
Senior Security Engineer
Sequencing5 months ago
Remote, United StatesSenior
Responsibilities
- Lead security testing for web applications, APIs, AWS and OCI cloud environments, Kubernetes, and on-premises servers.
- Build security into CI/CD pipelines through code and application scanning and improved secrets management.
- Secure genomic data pipelines and protect PHI and PII in accordance with HIPAA requirements.
- Set up security monitoring, alerting, incident response, playbooks, runbooks, logging, and SIEM capabilities.
- Lead technical work for HIPAA, SOC 2, and ISO 27001 readiness and future audits.
- Translate security findings into prioritized remediation tasks and partner with engineering, DevOps, bioinformatics, and data teams.
- Contribute to threat modeling, secure design, architecture and infrastructure decisions, vendor assessments, and security documentation.
- Support performance and security assessments, security awareness efforts, and eCommerce and checkout security.
- Collaborate across functions and time zones to plan, prioritize, and communicate security work and trade-offs.
Requirements
- 8+ years of experience in security engineering, DevSecOps, or infrastructure security roles.
- Strong hands-on penetration testing and vulnerability discovery experience using manual methods and tools.
- Deep experience securing AWS, OCI, Kubernetes, bare-metal systems, and on-premises server environments.
- Experience integrating and tuning security tools in CI/CD, including Semgrep, CodeQL, OWASP ZAP, or Burp Suite.
- Experience with SIEM or log aggregation, real-time detection, and monitoring.
- Familiarity with HIPAA, SOC 2, and protection of PHI and PII in regulated or highly sensitive environments.
- Experience with eCommerce and checkout security, including payment flows, cart and order APIs, fraud, skimming attacks, and checkout abuse.
- Clear written and verbal communication and the ability to influence technical teams without formal authority.
- Ability to work independently in a remote, fast-moving startup with limited existing security processes.
- OSCP, OSCE, or equivalent certifications are preferred; vulnerability research, responsible disclosure, or red team operations experience is a strong plus.
Benefits
- Remote role with a global team and collaboration across time zones.
- Opportunity to establish security practices and directly influence company operations, architecture, and customer trust.