Redox

Redox

Redox is a top integration platform enabling seamless interoperability between healthcare software and EHRs, accelerating implementations, reducing costs, and empowering healthcare innovators to bring cutting-edge solutions to market efficiently.

Internet Software & Services
51-250
$95M raised

Description

  • Own cloud security posture management across Kubernetes and container environments, including admission control, network policies, image integrity, and hardening.
  • Manage the vulnerability lifecycle from triage through production remediation, prioritizing based on real production exposure.
  • Partner with Platform Engineering to embed secure SDLC and CI/CD safeguards into build and release workflows.
  • Translate HITRUST and SOC 2 requirements into technical controls and operational configurations.
  • Evaluate and secure infrastructure-as-code across all environments.
  • Support incident response, including forensic investigation and blameless post-mortems.
  • Lead security design reviews, pair with engineers, and provide technical mentorship to raise security standards.
  • Triage bug bounty findings and work with external security researchers.

Requirements

  • 8+ years of security engineering experience with staff-level impact through architecture, strategic initiatives, and mentorship.
  • Deep experience with Kubernetes security, including network policy orchestration, Kyverno admission control, and container hardening.
  • Experience threat modeling applications built with Node.js, TypeScript, Python, or Go.
  • Proven experience implementing secure SDLC practices and CI/CD safeguards using GitHub Actions.
  • Experience hardening Infrastructure-as-Code with Terraform and managing secrets with AWS Secrets Manager, Vault, or similar tools.
  • End-to-end ownership of vulnerability management lifecycles from triage to remediation.
  • Ability to operationalize compliance frameworks such as HITRUST and SOC 2 into practical technical controls.
  • Strong written communication skills and the ability to influence roadmaps in a remote, asynchronous environment.
  • Experience with AI tools and techniques, including prompt engineering and workflow automation using multiple LLM platforms.
  • Nice to have: experience securing autonomous agentic loops and tool-calling frameworks, including indirect prompt injection defenses and human-in-the-loop guardrails.
  • Nice to have: experience securing the Model Context Protocol (MCP), including context isolation, sandboxing, and identity propagation.
  • Nice to have: hands-on application of the NIST AI RMF and OWASP Top 10 for LLMs in production.
  • Nice to have: familiarity with Go, Node.js, or TypeScript; the team is a TypeScript shop.
  • Nice to have: VPN administration or enterprise network security experience.
  • Nice to have: experience with dependency management tooling such as Renovate or Dependabot.

Benefits

  • Fully remote role within the U.S.
  • Work in a culture that emphasizes transparency, ownership, and autonomy.
  • Opportunity to shape security standards and have broad production impact.
  • Eligibility requires residence and work in the continental U.S.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Detection Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring a Senior Detection Engineer to help build and operate detection engineering for its global cyber defense function across DoorDash, Deliveroo, and Wolt.

Go Python SIEM Snowflake SQL
1 hour, 8 minutes ago

Senior Information Security Engineer

KPA 251-1K Professional Services

KPA is hiring a Senior Information Security Engineer to own and improve its technical security platforms, cloud and identity security, and incident response efforts across a modern enterprise environment.

AWS AWS SES Azure CI/CD CrowdStrike DevSecOps Kubernetes Linux Network Security Penetration Testing PowerShell Python REST API SendGrid
1 hour, 23 minutes ago

IAM Architect - Saviynt

IDMWORKS 51-250 Professional Services

IDMWORKS is hiring an IAM Architect - Saviynt to design and deliver identity and access management solutions that strengthen security and support access control across enterprise environments.

Active Directory Cybersecurity OAuth SAML
1 hour, 23 minutes ago

Quantum Computing/Cryptography Engineer (R-00219)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is hiring a quantum security professional to assess, modernize, and implement post-quantum cryptography solutions for enterprise and government-scale systems.

C++ Encryption Java Python TLS
1 hour, 38 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers