SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Redox is a healthcare interoperability platform that connects 12,000+ systems and organizations to enable secure, real-time healthcare data exchange. The company processes over 1.2 billion messages monthly and serves health tech vendors, providers, payers, EHRs, and life sciences customers.
As a Senior Security Engineer, you will own critical security functions across Redox's cloud infrastructure and development lifecycle. Your responsibilities include:
• Cloud Security Posture Management: Lead Kubernetes and container security practices, including admission control, network policies, image integrity, and environment hardening.
• Vulnerability Management: Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic metrics.
• Secure SDLC & CI/CD: Collaborate with Platform Engineering to implement and maintain secure development practices, focusing on artifact validity and pipeline integrity using GitHub Actions.
• Compliance & Controls: Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
• Infrastructure Security: Evaluate and secure infrastructure-as-code across all environments, particularly Terraform.
• Incident Response: Execute incident response duties, including forensic investigation and facilitation of blameless post-mortem analyses.
• Mentorship & Design: Contribute to security standards through design reviews, collaborative pairing, and peer mentorship.
• Bug Bounty & Research: Support bug bounty triage and maintain professional engagement with external security researchers.
You'll work hands-on with AWS, Docker, EKS, Kyverno, GitHub Actions, Terraform, and a modern cloud-native stack. The role is fully remote within the continental US and emphasizes asynchronous collaboration.
REQUIREMENTS:
• 5+ years in security engineering with hands-on delivery across system hardening, security projects, and peer mentorship
• Strong technical proficiency in Kubernetes security (network policies, Kyverno admission control, container hardening)
• Experience with threat modeling for applications built in Node.js, TypeScript, Python, or Go
• Hands-on experience with secure SDLC and CI/CD safeguards using GitHub Actions
• Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets (AWS Secrets Manager, Vault, or similar)
• Solid experience across the vulnerability management lifecycle from triage to production remediation
• Ability to apply compliance frameworks (HITRUST, SOC 2) into pragmatic technical controls aligned with engineering workflows
• Strong written communication skills and ability to work effectively in remote, asynchronous environments
• Proficiency in AI tools and techniques, including prompt engineering and hands-on experience with multiple LLM platforms, with demonstrated ability to automate workflows using AI
NICE TO HAVE:
• Experience securing autonomous agentic loops and tool-calling frameworks; understanding of Indirect Prompt Injection and Human-in-the-Loop guardrails
• Technical familiarity with securing Model Context Protocol (MCP) regarding context isolation, sandboxing, and identity propagation
• Hands-on application of NIST AI RMF and OWASP Top 10 for LLMs in production
• Proficiency in Go, Node.js, or TypeScript
• VPN administration or enterprise network security experience
• Dependency management tooling (Renovate, Dependabot)