Security Engineer - Detection & Cloud Security Operations
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.
Role
SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. This role is our hands-on owner of detection engineering and security operations. You will turn our detection platform into real coverage: writing and tuning detections in Panther, keeping alerts high-signal, running the SIEM as it grows, and being on point when an alert turns into an investigation. You will also handle the day-to-day work of cloud security operations and help run incident response.
You will work closely with our Staff Security Engineer, who sets detection and AI-security strategy. Your job is to make that strategy real in production and keep it sharp. There is room to grow into deeper detection engineering, cloud security, and security automation, on a team that invests in leveling people up.
This role is fully remote within the US
What You’ll Do
- Write, tune, and maintain detections in our SIEM (Panther) across cloud, container, and SaaS log sources, keeping coverage broad and alerts high-signal.
- Run the SIEM day to day: onboard log sources, manage detection quality, and reduce false positives so real signals stand out.
- Triage and investigate security alerts from raw log to conclusion, and help execute our incident-response playbooks.
- Run cloud security operations in AWS: investigate GuardDuty and Wiz findings, tighten configurations, and close cloud misconfigurations.
- Own and improve GitHub organization security controls as code.
- Partner on network and infrastructure security: help onboard network telemetry, support egress monitoring, and provide backup depth alongside our infrastructure security engineer.
- Help build and extend the team's security-automation tooling.
- Write runbooks so detection and response are repeatable rather than tribal knowledge.
- Contribute to security design reviews and RFCs, and give substantive security feedback on pull requests.
- Support the Vulnerability Management program with triage and exploitability assessment as volume requires.
What You Bring
- 4+ years in security engineering, with solid hands-on experience in AWS and cloud-native infrastructure.
- Direct experience writing and tuning detections in a modern SIEM (Panther or similar) and reasoning about detection coverage.
- Experience investigating security alerts from raw log to a defensible conclusion.
- The ability to design and deliver medium-complexity security work independently.
- Code fluency in Python or TypeScript to automate your work.
- Familiarity with cloud logging and observability (CloudTrail, VPC Flow Logs) and AWS security services (GuardDuty, AWS Config).
- Solid AWS network security fundamentals (VPC, security groups, egress controls) and Terraform, enough to partner on and back up our network and infrastructure security work.
- Clear writing; you leave behind runbooks and tickets others can follow.
- Design detections and operational tooling for maintainability, so the work stays reliable and easy for the team to extend.
- An ownership mindset: you close loops rather than drop them.
Nice To Haves
- Startup experience, especially in health tech or another regulated, data-sensitive environment.
- Incident-response experience, or a strong interest in growing into it.
- Network security depth beyond fundamentals (VPC design, segmentation, Transit Gateway, firewall/egress architecture).
- Kubernetes (EKS) and container security exposure.
- Interest in AI and agentic security and in building security automation.
Our Tech Stack
- Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
- Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
- Languages: Python, TypeScript, Go
- AI and automation: Claude, MCP, and agentic tooling used across engineering
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at SmarterDx
Explore Top Companies in this Space
Lucida AI
EdTech / AI Language Coaching / Speech-to-Speech Tech / B2B Enterprise SaaS
Crop
AI Image Processing
Hanna Interpreting Services
Language Services
Stripe
Payment Processing
SmarterDx
View Company ProfileSmarterDx (operating at smarterdx.com) is a clinical AI platform engineered for hospitals to analyze patient records and capture the value of care delivered. Founded in 2020 by Drs. Michael Gao and Joshua Geleris and headquartered in New York, NY, SmarterDx brings clinical AI to the revenue cycle, starting where old systems break down: clinical complexity. Under the hood, SmarterDx uses AI to analyze patient records and support accurate capture of care value. This allows hospitals to review 100% of patient charts for 100% accuracy, achieve 100% revenue, and bolster hospital revenue integrity and quality. Backed by $50 million in Series B funding led by Transformation Capital.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
