Senior Security Engineer
Oshihealth · Remote
About this role
**Senior Security Engineer** *Are you a security engineer who wants to build a program from the foundation up - not inherit and babysit someone else's?* *Do you thrive in a fast-paced, AI-native environment where security's job is to enable speed safely, not slow it down out of fear?* *Are you energized by the idea that the systems you protect hold the most sensitive health data of real people trying to get their lives back from chronic GI conditions?* If so, you might be a perfect fit for our team of professionals dedicated to eliminating the impact of digestive health conditions through innovative GI care. **The Role** As Oshi Health's first dedicated Senior Security Engineer, you will own the technical security of a fully remote, SaaS- and cloud-native healthcare platform. Reporting to the Sr. Director, Security & IT, you will set the security architecture standards for our product and AWS environments, harden how we manage identity and secrets, and build security into our engineering and AI workflows from the start. This is a uniquely forward-looking role. You will design the guardrails for an agentic software development lifecycle in which AI agents help plan, build, review, and deploy code against a data platform that touches regulated data. You'll partner closely with Product & Engineering to keep the path paved—moving fast with confidence rather than slow out of fear—and with the Sr. Director on HIPAA, SOC 2, and audit readiness. **What you'll do** • **Own application and product security:** threat modeling, secure design review, and secure code review, with a focus on authorization and access-control flaws (IDOR, broken access control, exposed secrets, insecure upload) • **Make our existing tooling do real work:** enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks • **Design and own the security architecture for our agentic SDLC** - phase-gate criteria, deterministic out-of-band controls, and tested clawback procedures • **Build and run non-human identity (NHI) and secrets management at scale:** service accounts, scoped tokens, OAuth grants, and machine credentials • **Secure our AWS environment:** IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection • **Run security review of AI and third-party vendor integrations** before they touch PHI • **Stand up and tune detection and response** leveraging AI and behavioral baselines • **Support HIPAA Security Rule technical safeguards** in partnership with the Sr. Director • **Own the vulnerability management and penetration-testing cadence** • **Reduce attack surface** through SaaS and identity rationalization • **Build automation** so that a small security function operates with outsized leverage **Who you are** • **6+ years in security engineering** with demonstrated depth in application/product security and cloud security (AWS). Healthcare, fintech, or regulated environment experience is a strong plus • **Hands-on with secure SDLC tooling:** SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply-chain security • **Strong in identity and access management:** Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and non-human identity/secrets management • **Familiarity with - or genuine drive to go deep on - securing AI/LLM and agentic systems:** prompt injection, agent authorization, NHI sprawl, and model/supply-chain risk • **Comfortable being th
Listing freshness
CronJobs last confirmed this listing 16h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.