远程工作雷达

高级安全工程师

Senior Security Engineer

AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Redox
薪资$165,000 - $190,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

Redox 正致力于通过有用的数据加速医疗行业的转型。Redox Engine 是一个灵活的互操作性平台,连接并推动实时医疗数据交换。只需一次连接,数据就可以在不断扩展的 12,000+ 系统和组织网络中进行编排,包括 100+ 电子健康记录系统(EHR)。Redox 每月处理超过 12 亿条消息,服务我们的医疗科技供应商、提供者、支付方、EHR 和生命科学客户。

职位职责:
负责云安全态势管理,包括 Kubernetes 和容器安全实践、准入控制、网络策略、镜像完整性以及环境加固。

管理全面的漏洞生命周期,根据实际生产暴露情况而非简单的发现指标来优先修复漏洞。

与平台工程团队合作,支持安全的 SDLC 和 CI/CD 保障措施,重点关注工件有效性和流水线完整性。

将 HITRUST 和 SOC 2 合规框架转化为可执行的技术配置和操作控制。

评估并保护所有环境中的基础设施即代码(IaC)。

执行事件响应职责,包括取证调查和推动无责复盘分析。

通过设计评审、协作配对和对同事的指导,为工程团队的安全标准做出贡献。

支持漏洞赏金的分类,并与外部安全研究人员保持专业互动。

所需技能与经验:
5 年以上安全工程经验,有在系统加固、安全工程项目和同行指导方面的实际交付记录。

在 Kubernetes 安全方面有较强的技术能力,特别是网络策略编排、准入控制(Kyverno)和容器加固协议。

有使用 Node.js、TypeScript、Python 或 Go 构建的应用程序进行威胁建模的经验。

有使用 GitHub Actions 支持安全的 SDLC 实践和 CI/CD 保障措施的实际经验,确保工件有效性和流水线完整性。

直接有加固基础设施即代码(Terraform)的经验,并通过 AWS Secrets Manager、Vault 或类似平台管理企业密钥。

在漏洞管理生命周期中有扎实的经验,从初步分类到生产修复。

能够将 HITRUST 和 SOC 2 等合规框架应用为符合工程需求的实用技术控制措施。

查看英文原文

Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.

Job Responsibilities:
Own Cloud Security Posture Management including Kubernetes and Container security practices, admission control, network policies, image integrity, and environment hardening.

Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.

Collaborate with Platform Engineering to support secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.

Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.

Evaluate and secure infrastructure-as-code across all environments.

Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.

Contribute to security standards within Engineering through design reviews, collaborative pairing, and mentorship of peers.

Support bug bounty triage and maintain professional engagement with external security researchers.

Required Skills & Experience:
5+ years in security engineering with a track record of hands-on delivery across system hardening, security engineering projects, and peer mentorship.

Strong technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.

Experience with threat modeling for applications built using Node.js, TypeScript, Python or Go.

Hands-on experience supporting secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.

Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.

Solid experience across the vulnerability management lifecycle, from initial triage to production remediation.

Ability to apply compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.

Strong written communication skills, with the ability to clearly document decisions and collaborate effectively within a remote, asynchronous organizational culture.

Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.

Our stack - you'll be hands-on with these:
AWS, Docker, EKS

Crowdstrike, Jamf, Okta, GuardDuty, Sumologic

Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane

Github Actions, Terraform, Helm, ArgoCD and Atlantis

Postgres, Redis, Kafka

Nice to have in your background:
Experience securing autonomous agentic loops and tool-calling frameworks. Understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.

Technical familiarity with securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.

Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.

Go, Node.js, or TypeScript (we're a TypeScript shop and it helps to be comfortable there).

VPN administration or enterprise network security experience.

Dependency management tooling (Renovate, Dependabot).

About Redox - Take a look here: https://youtu.be/4OjENXR6UXA
 
What We Do
Healthcare organizations and technology vendors connect to Redox once, then authorize what data they send to and receive from partners through a centralized hub. Redox's cloud-based platform is vendor and standards-agnostic and enables the secure and efficient exchange of healthcare data.
 
This approach eradicates the need for point-to-point integrations and accelerates the discovery, adoption, and distribution of patient and provider-facing technology solutions. With hundreds of healthcare organizations and technology vendors exchanging data today, Redox represents the largest interoperable network in healthcare. Learn how you can leverage the Redox platform at www.redoxengine.com.
 
Other Stuff About Us
Redox is an EEO company. We fully support the diversity of our team. As part of our ongoing work to build more diverse teams at Redox, you will be asked to complete a voluntary EEO survey when applying. This survey is anonymous, we cannot link your application record with your survey responses. We request that you complete this voluntary survey as we run monthly reports for each team which provides data for diversity in terms of gender and ethnic background in our Applicants and our Hired Redoxers. We take this data very seriously and appreciate your willingness and time to complete this step in the process.
 
Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S.
 
Thank you for your interest in Redox!
 
#LI-TA1

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级定价经理

RedoxUnited States$155,000 - $180,000/年Full Time今天
市场运营职能支持限定地区(需当地身份)

企业客户成功总监

RedoxUnited States$170,000 - $195,000/年permanent昨天
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

客户成功总监

RedoxUnited States$185,000 - $205,000/年permanent4 天前
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

助理生产支持工程师,一级

RedoxUnited States$70,000 - $80,000/年permanent4 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位