- Location
- Remote
- Workplace
- Remote
- Employment
- Full time
- Level
- Senior
- Posted
- 2 weeks ago
About this role
Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.
Opportunity & Impact
We are seeking a Senior Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands-on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact.
You will function as a partner to our Engineering teams, embedding security into the SDLC through hands-on work across container security, Kubernetes hardening, and architecture reviews. You'll follow and reinforce our established security standards, helping make the secure path the easy path for the engineers you work with day to day.
As part of a small, senior security team, your day to day work will directly strengthen how we protect data for our customers, with impact concentrated in the systems and teams you own.
We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership.
Our Engineering Culture & How We Work
Transparency, Ownership & Autonomy
We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Senior Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes.
We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too, when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern.
We own the systems we maintain, not just the new features on the roadmap. You'll have room to identify platform security work, propose scope, consult on priority, and see it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.
Job Responsibilities:
Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.
Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.
Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
Evaluate and secure infrastructure-as-code across all environments.
Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers.
Support bug bounty triage and maintain professional engagement with external security researchers.
Required Skills & Experience:
5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship.
Strong technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.
Experience with threat modeling for applications built using Node.js, TypeScript, Python or Go.
Hands-on experience supporting secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.
Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.
Solid experience across the vulnerability management lifecycle, from initial triage to production remediation.
Ability to apply compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.
Strong written communication skills, with the ability to clearly document decisions and collaborate effectively within a remote, asynchronous organizational culture.
Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.
Our stack - you'll be hands-on with these:
AWS, Docker, EKS
Crowdstrike, Jamf, Okta, GuardDuty, Sumologic
Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane
Github Actions, Terraform, Helm, ArgoCD and Atlantis
Postgres, Redis, Kafka
Nice to have in your background:
Experience securing autonomous agentic loops and tool-calling frameworks. Understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
Technical familiarity with securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.
Go, Node.js, or TypeScript (we're a TypeScript shop and it helps to be comfortable there).
VPN administration or enterprise network security experience.
Dependency management tooling (Renovate, Dependabot).
About Redox - Take a look here: https://youtu.be/4OjENXR6UXA What We Do Healthcare organizations and technology vendors connect to Redox once, then authorize what data they send to and receive from partners through a centralized hub. Redox's cloud-based platform is vendor and standards-agnostic and enables the secure and efficient exchange of healthcare data. This approach eradicates the need for point-to-point integrations and accelerates the discovery, adoption, and distribution of patient and provider-facing technology solutions. With hundreds of healthcare organizations and technology vendors exchanging data today, Redox represents the largest interoperable network in healthcare. Learn how you can leverage the Redox platform at www.redoxengine.com. Other Stuff About Us Redox is an EEO company. We fully support the diversity of our team. As part of our ongoing work to build more diverse teams at Redox, you will be asked to complete a voluntary EEO survey when applying. This survey is anonymous, we cannot link your application record with your survey responses. We request that you complete this voluntary survey as we run monthly reports for each team which provides data for diversity in terms of gender and ethnic background in our Applicants and our Hired Redoxers. We take this data very seriously and appreciate your willingness and time to complete this step in the process. Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S. Thank you for your interest in Redox! #LI-TA1
As published by Redox. Applications are handled on their site.
Skills this posting mentions
About Redox
Redox helps providers, payers, health tech vendors, EHRs, and Life Sciences power better care with real-time data exchange. Our interoperability platform helps our customers to send, receive, process, and act on massive volumes of diverse healthcare data instantly. Today, more than 12,000 connected healthcare organizations use our technology to exchange data across the broadest range of systems, applications, and use cases in the industry. For more information, visit www.redoxengine.com.
All 12 openings at RedoxOne click, then it is written
Apply to Redox with a resume written for this role.
Queue Senior Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Redox’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Redox
See all- Last week
- 2 weeks ago
- 2 weeks ago
- 2 weeks ago
- 2 weeks ago
- 2 weeks ago
Similar roles elsewhere
See morePut this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Redox publishes. Refolk is not the employer and does not handle their hiring. Applications go to Redox directly.