25 days ago
Remote, WorldwideSenior
Responsibilities
- Own and continuously improve AxisCare Engineering’s security program as an individual contributor.
- Own the engineering side of SOC 2 Type II compliance, including control design, evidence collection, audit preparation, and remediation.
- Chart the path toward HITRUST certification by mapping existing controls and building missing capabilities.
- Threat-model the application and infrastructure and harden the PHP/React, AWS, Terraform, Docker, and MySQL/RDS stack.
- Manage IAM policies, VPC design, secrets management, container security, and database access controls.
- Own and improve security scanning, tune findings, reduce false positives, and drive developer remediation.
- Assess and mitigate AI product risks such as prompt injection, data leakage, model output filtering, and abuse scenarios.
- Create guardrails for AI-assisted development workflows.
- Strengthen logging, alerting, detection, incident response playbooks, and penetration-test remediation.
- Maintain clear security policies and train developers on secure practices.
Requirements
- At least 5 years of experience in application security, infrastructure security, or security engineering at a SaaS company.
- Hands-on experience with AWS security, including IAM, VPC, Security Groups, KMS, CloudTrail, and GuardDuty.
- Experience owning or heavily contributing to the engineering side of SOC 2 Type II compliance.
- Familiarity with Docker and Kubernetes container security and Terraform infrastructure-as-code.
- Strong understanding of web application security fundamentals, including OWASP Top 10 and secure SDLC practices.
- Experience securing AI/ML systems or LLM-powered products.
- Concrete experience using AI to improve security work, such as automating compliance tasks, accelerating threat analysis, or building detection rules.
- Ability to read application code and Terraform, explain vulnerability fixes, and work directly with developers.
- Strong written communication skills for policies, incident reports, audit narratives, and engineering guidance.
- Ability to work remotely from the Eastern, Central, or Mountain time zones.
- Qualified to work in the United States or Canada.
- Preferred: experience with HIPAA-compliant or HITRUST-certified environments; CISSP, OSCP, or AWS Security Specialty certification; penetration-testing or red-team experience.
Benefits
- Fully remote role for candidates working from the Eastern, Central, or Mountain time zones.
- Medical, dental, and vision insurance covered in full for the employee.
- Company-provided laptop and other needed computer equipment.
