Verified today
Security and Compliance Engineer
About the role
Seeking a hands‑on Security and Compliance Engineer to secure applications, infrastructure, and compliance programs in a healthcare setting. The role blends security engineering, DevSecOps, and risk management, focusing on cloud, AI, and data security. Responsibilities include penetration testing, CI/CD security integration, CSPM deployment, compliance leadership (HIPAA, SOC 2, HITRUST), email and bot protection, AI system security, data protection, threat modeling, incident response, and audit support. Candidates should bring 4‑6 years of experience, strong technical skills, and excellent communication.
What you’ll do
- Conduct web/mobile penetration testing, vulnerability scanning, and remediation.
- Integrate DevSecOps practices into CI/CD pipelines using Snyk, Terraform, container scanners.
- Deploy and monitor CSPM tools like Wiz to secure cloud configurations.
- Enforce secure IaC provisioning with DevOps collaboration.
- Lead HIPAA, SOC 2, HITRUST compliance initiatives via Drata.
- Design email gateway and bot protection solutions (Barracuda, WatchGuard).
- Secure AI/chatbot systems against prompt injection and data leakage.
- Promote data security best practices: encryption, DLP, classification.
- Perform threat modeling, secure code reviews, and architecture reviews.
- Manage incident detection, response, root‑cause analysis, logging, monitoring.
- Maintain security documentation and support audits and third‑party assessments.
What you’ll bring
- 4-6 years experience in security engineering, compliance, and DevSecOps.
- Proficient in web/mobile application security, OWASP, SAST/DAST, Burp Suite.
- Hands‑on with DevSecOps tools: Snyk, Terraform, container security scanners.
- Deep knowledge of HIPAA, SOC 2, HITRUST and healthcare compliance.
- Cloud security expertise on Microsoft Azure and CSPM tools like Wiz.
- Experience with compliance automation platforms such as Drata.
- Skilled in email gateway security (Barracuda) and bot protection (WatchGuard).
- Understanding of AI/chatbot security risks and mitigation.
- Strong data security practices: encryption, DLP, classification.
- Scripting in Python or Bash; excellent communication and documentation.
Nice to have
- OSCP, CEH, CCSK, CISSP, HCISPP certifications.
- Familiarity with KnowBe4, Intune, Azure AD for identity security.
- Knowledge of Zero Trust, RBAC, EDR strategies.
- Prior work in health‑tech, SaaS, or AI‑focused organizations.