AxisCare

Senior Security Engineer

AxisCare
Apply
25 days ago
Remote, WorldwideSenior

Responsibilities

  • Own and continuously improve AxisCare Engineering’s security program as an individual contributor.
  • Own the engineering side of SOC 2 Type II compliance, including control design, evidence collection, audit preparation, and remediation.
  • Chart the path toward HITRUST certification by mapping existing controls and building missing capabilities.
  • Threat-model the application and infrastructure and harden the PHP/React, AWS, Terraform, Docker, and MySQL/RDS stack.
  • Manage IAM policies, VPC design, secrets management, container security, and database access controls.
  • Own and improve security scanning, tune findings, reduce false positives, and drive developer remediation.
  • Assess and mitigate AI product risks such as prompt injection, data leakage, model output filtering, and abuse scenarios.
  • Create guardrails for AI-assisted development workflows.
  • Strengthen logging, alerting, detection, incident response playbooks, and penetration-test remediation.
  • Maintain clear security policies and train developers on secure practices.

Requirements

  • At least 5 years of experience in application security, infrastructure security, or security engineering at a SaaS company.
  • Hands-on experience with AWS security, including IAM, VPC, Security Groups, KMS, CloudTrail, and GuardDuty.
  • Experience owning or heavily contributing to the engineering side of SOC 2 Type II compliance.
  • Familiarity with Docker and Kubernetes container security and Terraform infrastructure-as-code.
  • Strong understanding of web application security fundamentals, including OWASP Top 10 and secure SDLC practices.
  • Experience securing AI/ML systems or LLM-powered products.
  • Concrete experience using AI to improve security work, such as automating compliance tasks, accelerating threat analysis, or building detection rules.
  • Ability to read application code and Terraform, explain vulnerability fixes, and work directly with developers.
  • Strong written communication skills for policies, incident reports, audit narratives, and engineering guidance.
  • Ability to work remotely from the Eastern, Central, or Mountain time zones.
  • Qualified to work in the United States or Canada.
  • Preferred: experience with HIPAA-compliant or HITRUST-certified environments; CISSP, OSCP, or AWS Security Specialty certification; penetration-testing or red-team experience.

Benefits

  • Fully remote role for candidates working from the Eastern, Central, or Mountain time zones.
  • Medical, dental, and vision insurance covered in full for the employee.
  • Company-provided laptop and other needed computer equipment.

Categories

AxisCare

About AxisCare

51-200 employees
Contact me