Senior Security Engineer

Full-time
Remote
$170,000-200,000/yr
San Francisco, CA; Chicago, IL; Boston, MA; New York, NY; Austin, TX; Miami, FL
No visa sponsorship

Benefits

Equity / Stock Options
Other

Job description

We are looking for a Senior Security Engineer with 5+ years of experience to be the first dedicated security hire at a high-growth digital health company. You'll own the technical security of a fully remote, cloud-native healthcare platform – acting as a hands-on builder, not a policy desk. You will set security architecture standards for our product and AWS environments, harden identity and secrets management, and design the guardrails for our transition to an agentic SDLC where AI agents help plan, build, and deploy code against regulated data. This is a uniquely forward-looking role where your fingerprints will be on the foundation.

What you will be doing

  • Owning application and product security – threat modeling, secure design review, and secure code review focused on authorization and access-control flaw classes for a member-facing healthcare app and its APIs

  • Designing and owning the security architecture for an agentic SDLC – building phase-gate criteria, deterministic out-of-band controls for agent-written code, and lifecycle management for non-human identities

  • Securing the AWS environment – IAM, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS, and Terraform

  • Building and running non-human identity and secrets management at scale – service accounts, scoped tokens, OAuth grants, and machine credentials with provisioning, rotation, and least privilege

  • Enforcing and tuning GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks and building automation so a small security function operates with outsized leverage

Requirements

  • 6+ years of experience in security engineering,​ with depth in AppSec and AWS cloud security

Work experience

  • Application/product security AND AWS cloud security in a regulated industry (e.​​g.​​,​​ healthtech,​​ fintech,​ insurtech) that is either:​​ a VC-​​​​​backed OR <​500-​person startup that has significantly scaled;​ only open to big tech (FAANG or better) if paired with top-​20 CS program
  • Working knowledge of HIPAA,​ SOC 2,​ and NIST CSF

Education

  • Top-​20 CS program (non-​negotiable if coming form big tech)
  • Security certification (OSCP,​ GIAC,​ CISSP)

Hard skills

  • Hands-​on expertise with secure SDLC tooling (SAST/DAST,​ GitHub Advanced Security)
  • Proficient in Python and shell scripting for automation
  • Strong in IAM:​ Okta,​ OAuth/OIDC,​ SAML,​ NHI management

Traits to avoid

  • Only large,​ slow-​moving enterprise experience
  • Contractors or consultants

Visa sponsorship details

  • Not open to any visas (e.g. US. citizen, green card holders)

More information

Minimum education level

Bachelor's

Experience level

Senior (5-7 years)

Job skills

secure SDLC tooling

SAST

DAST

GitHub Advanced Security

IAM

Okta

OAuth

OIDC

SAML

NHI Ma

HIPAA

NIST CSF

SOC 2

AWS

Application Security

Product Security

Python (Programming Language)

Cloud Security

Certifications

CISSP

GIAC

OSCP

Languages

English

Company overview

company-logo
Silpa Companies

IT Services and IT Consulting·1-10 employees

Silpa Companies is the parent of two mission driven brands: Silpa Recruiting (https://silparecruiting.com) and Silpa Consulting (https://silpaconsulting.com). Our purpose is simple but bold; to build stronger businesses by elevating the people and platforms that power them. Through Silpa Recruiting, we connect high performing talent with organizations that value impact, culture, and growth. And with Silpa Consulting, we guide companies through critical moments of transformation; integrating cloud, cybersecurity, and data strategies that scale. We’re not just consultants or recruiters. We’re long term partners in resilience; helping our clients attract the right people, embrace the right technologies, and stay future ready in a world that doesn’t sit still.