This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced Security Engineer to join our Platform Team. This team is at the core of our infrastructure, responsible for managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications. The Platform Team’s responsibilities span a wide range of areas, including: The AWS infrastructure that our engineering teams rely on; Management of our GitHub organization and IT operations; Supporting compliance efforts to ensure alignment with industry standards (SOC, HIPAA, HITRUST). As a Security Engineer, you will play an active role in how we set up our AWS infrastructure, software development lifecycle, and endpoint security. Your contributions will help ensure our engineering teams build applications in a way where it is easy to demonstrate alignment with regulatory and compliance requirements.
Job Responsibility:
Develop playbooks and address security-related tasks in our AWS serverless environments
Drive improvements in our broader security posture, including application security, endpoint security, access management / just-in-time access, email and web gateways, browser security, and data loss prevention
Collaborate with product engineering teams to raise the bar for security, supporting CI/CD pipelines, dependency management, and secure application design reviews
Help secure and improve our AWS organization using infrastructure as code (CDK), enforcing security controls, and ensuring strong tenant isolation
Continuously assess vulnerabilities and perform regular risk assessments
Requirements:
4+ years of experience in engineering, working as a security engineer or in security-adjacent roles
Familiarity with compliance frameworks such as SOC, HIPAA, and/or HITRUST
4+ years working with AWS services, including compliance and governance services like AWS Organizations, AWS CloudTrail, AWS Config, Security Hub, and GuardDuty
Proficiency in TypeScript
Ability to prioritize your work based on the needs of the business and the customers
High bandwidth
thoughtful attention to many areas simultaneously
Ability to context switch throughout the course of the day or week as priorities shift
Philosophical alignment with the Stedi Standards and the Unwritten laws of engineering