资深安全工程师
Staff Security Engineer
SmarterDx 正在改变医疗系统使用临床 AI 的方式,以实现患者护理的全部价值。由医生-数据科学家打造,并基于经过临床验证的电子健康记录(EHR)数据进行训练,我们的临床 AI 平台能够解读每个患者故事背后的细微差别,并为收入周期团队提供临床合理的建议——帮助医院追回应得的收入,提高质量指标,减少拒付,并简化收入周期运营。作为 SmarterDx 的一员,你将参与构建让每个人都能更准确、可持续和高效地获得医疗的技术。了解更多请访问 [smarterdx.com/careers](http://smarterdx.com/careers)。
**职位**
SmarterDx 安全工程的职责范围广泛:包括 AI、云和企业安全,以及公司内部新设计和代码的审查。我们是一个小团队,每位工程师都负责一个领域。该职位是我们团队在两个需要深度发展的领域中的高级技术核心:AI 安全和威胁检测与响应。
在 AI 安全方面,你将负责 SmarterDx 如何安全地采用 AI 和代理工具。这包括对代理访问我们云和数据的防护措施、产品中 AI 和 ML 工作负载的安全性,以及其它工程团队遵循的标准,使得大多数 AI 采用无需安全工程师在场即可进行。在检测方面,你将负责我们的检测平台(Panther)、我们的检测策略和覆盖范围,以及随着团队成长保持高信号检测的标准。作为团队中最资深的安全工程师,你还将跨云和代码安全审查提供支持,并指导仍在建立安全深度的同事。
_**该职位为美国境内远程办公**_
**你将负责的工作**
- 负责我们对 AI 和代理安全的方法:代理访问云和数据的防护措施,以及产品中 AI 和 ML 工作负载的安全性。
- 发布组织的 AI 安全标准并推动其他工程团队的采用。
- 负责我们的检测平台(Panther):覆盖云、容器和 SaaS 日志源的检测策略和覆盖范围,以及保持检测高信号的标准。
- 负责事件响应准备:计划、操作手册和与 HIPAA 漏洞通知时间线相关的测试演练,在真实事件发生时协助主导响应。
- 领导跨团队的复杂安全工作,从头到尾解决模糊点并协调平台、工程和其他团队。
查看英文原文
SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at [smarterdx.com/careers](http://smarterdx.com/careers).
**Role**
SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. We are a small team, and each engineer owns a domain. This role is our senior technical anchor for the two areas where we most need depth as the team grows: AI security and threat detection and response.
On the AI security side, you will own how SmarterDx adopts AI and agentic tooling safely. That includes the guardrails for agentic access to our cloud and data, the security of the AI and ML workloads in our product, and the standards other engineering teams follow so that most AI adoption can happen without a security engineer in the room. On the detection side, you will own our detection platform (Panther), our detection strategy and coverage, and our incident response readiness. As the most senior security IC on the team, you will also be a resource across cloud and code security reviews, and you will mentor teammates who are still building their security depth.
_**This role is fully remote within the US**_
**What You’ll Do**
- Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product.
- Publish the org's AI-security standard and drive its adoption by other engineering teams.
- Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources, and the standards that keep detections high-signal as we grow.
- Own incident-response readiness: the plan, the playbooks, and tested tabletops tied to the HIPAA breach-notification timeline, and help lead response when a real incident happens.
- Lead complex security work across teams from start to finish, resolving ambiguity and coordinating with Platform, Engineering, and Compliance.
- Act as the senior security resource across cloud security and security reviews, and the security expert other engineering teams seek out for guidance on high-stakes decisions.
- Mentor teammates who are growing their security depth, set team standards for detection authoring and code review, and help raise our interview and hiring bar.
- Build and grow security automation that gives a small team more reach, and contribute to the tooling the team runs on.
- Take part in architecture reviews and threat modeling on our highest-risk designs, and communicate the resulting security architecture so the whole team can understand it and build on it.
**What You Bring**
- 8+ years in security and software engineering, with deep hands-on experience in AWS and cloud-native infrastructure, including working competence with containerized workloads (EKS) and infrastructure-as-code (Terraform).
- A track record of leading complex security work across teams and making other engineers more effective.
- Depth in AI and agentic security: securing LLM applications, agentic frameworks, and MCP, plus prompt-injection and agentic-access defenses.
- Depth in threat detection engineering: designing, authoring, and tuning detections in a modern SIEM, and reasoning about coverage against real threats.
- Incident-response experience, including building the plan and running the response.
- The ability to write production code (Python, Go, or TypeScript) and build security tooling, not only configure products.
- Strong writing and communication; you can publish a standard other teams adopt and explain a hard design to a non-security audience.
- Working knowledge of SOC 2 and HIPAA, and the judgment to design controls that hold up without stalling delivery.
- Experience mentoring and leveling up other engineers.
**Nice To Haves**
- Recognized AI-security work: published standards or research, contributions to AI-security tooling, or red-teaming of AI/LLM systems.
- Startup experience, especially in health tech or another regulated, data-sensitive environment.
- Deeper specialization in container security (Kubernetes/EKS, Helm) or in infrastructure-as-code and policy-as-code, beyond working competence.
- Experience consolidating or retiring a security platform with a measurable cost or coverage result.
**Our Tech Stack**
- Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
- Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
- Languages: Go, Python, TypeScript
- AI and automation: Claude, MCP, and agentic tooling used across engineering
#### **Compensation**
_$230k to 250k base salary_
_#LI-Remote_
_#LI-DNP_
#### Benefits
- **Medical, Dental & Vision** – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
- **Paid Parental Leave** – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
- **Remote-First Team** – Work from anywhere in the U.S.
- **Unlimited PTO & 11 Holidays** – So you can relax and recharge.
- **401(k) with Traditional & Roth Options**– Tax-advantaged retirement savings through Fidelity with a 4% match.
- **Minimal Bureaucracy** – A fast-moving, high-impact environment where you can focus on what matters.
- **Incredible Teammates!** – Work alongside smart, supportive, and mission-driven colleagues.