Back to Jobs
Oshi Health
Development 21h ago

Senior Security Engineer

Oshi Health
United StatesUnited States
Full-time
$170,000 — $190,000 USD
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Python2h 41mFree Trial ✨
Start 10-Day Free Trial
DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
CybersecurityAI EngineerAWS

Want to know if you're a match for this job?

Calculate My Match Score

The Role

As Oshi Health’s first dedicated Senior Security Engineer, you will own the technical security of a fully remote, SaaS- and cloud-native healthcare platform — and you’ll do it as a hands-on builder, not a policy desk. Reporting to the Sr. Director, Security & IT, you will set the security architecture standards for our product and AWS environments, harden how we manage identity and secrets, and build security into our engineering and AI workflows from the start.

This is a uniquely forward-looking role. Oshi is transitioning to an agentic software development lifecycle in which AI agents help plan, build, review, and eventually deploy code against a data platform that touches regulated data. You will design the guardrails that make that transition safe: the security gates in the pipeline, the controls on agent-written code, and the lifecycle management for the non-human identities those agents use. You’ll partner closely with Product & Engineering to keep the path paved — moving fast with confidence rather than slow out of fear — and with the Sr. Director on HIPAA, SOC 2, and audit readiness. If you want a security role where the work is genuinely novel and your fingerprints are on the foundation, this is it.

What you’ll do

  • Own application and product security: threat modeling, secure design review, and secure code review, with a focus on the authorization and access-control flaw classes (IDOR, broken access control, exposed secrets, insecure upload) that matter most for a member-facing healthcare app and its APIs.
  • Make our existing tooling do real work: enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks, with branch protection and CODEOWNERS-enforced human review on security-sensitive paths.
  • Design and own the security architecture for our agentic SDLC — phase-gate criteria for each stage of the AI transition, deterministic out-of-band controls so that agent-written code is never its own security gate of record, and tested “clawback” procedures for when risk spikes.
  • Build and run non-human identity (NHI) and secrets management at scale: service accounts, scoped tokens, OAuth grants, and machine credentials — provisioning, rotation, least privilege, and decommissioning across our SaaS and AWS estate.
  • Secure our AWS environment: IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS and Terraform (and supporting services in coordination with our DevOps team).
  • Run security review of AI and third-party vendor integrations before they touch PHI — evaluating data flows, retention, and data-loss-prevention needs, and applying healthy skepticism to AI-native vendors’ security claims.
  • Stand up and tune detection and response: Leverage AI and build behavioral baselines and anomaly detection for identity, SaaS, AWS, and AI/agent usage logs.
  • Support HIPAA Security Rule technical safeguards in partnership with the Sr. Director — encryption at rest, audit controls and activity logging, vulnerability scanning, and asset inventory.
  • Own the vulnerability management and penetration-testing cadence: Own the relationship with an external pen tester, drive findings to closure, shrink time-to-remediation, and move recurring issues left into the development process.
  • Reduce attack surface through SaaS and identity rationalization, and write the security policies, standards, and runbooks the program needs as it matures.
  • Build automation (scripting, infrastructure-as-code) so that a small security function operates with outsized leverage.

Who you are

  • 6+ years in security engineering, with demonstrated depth in application/product security and cloud security (AWS). Experience in healthcare, fintech, or another regulated, data-sensitive environment is a strong plus.
  • Hands-on with secure SDLC tooling: SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply-chain / dependency security.
  • Strong in identity and access management: Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and the management of non-human identities and secrets (e.g., AWS Secrets Manager, or equivalents).
  • Familiarity with — or genuine drive to go deep on — securing AI/LLM and agentic systems: prompt injection, agent authorization and over-permissioning, NHI sprawl, and model/supply-chain risk. You don’t need to have done it for a decade; almost no one has. You do need to be the kind of engineer who runs toward a problem the industry hasn’t solved yet.
  • Comfortable being the sole security specialist on a small, cross-functional team — you prioritize ruthlessly by risk, you’re pragmatic about cost, and you can explain a tradeoff to both an engineer and a non-technical executive without changing the truth of it.
  • Working knowledge of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework. Experience operating a compliance-automation platform is a plus.
  • Proficient with scripting and automation (Python and at least one shell) to scale yourself.
  • A curious, builder’s mindset — you’d rather pave a safe path than post a “do not enter” sign, and you find the right technology to increase both security and velocity.
  • Bachelor’s degree in Computer Science or equivalent practical experience.

Certifications (nice to have, not required): one or more of OSCP, GIAC (e.g., GWAPT, GCSA, GCLD), AWS Certified Security – Specialty, CISSP, or Okta Certified Professional.

How would you rate this job post?

See what other professionals think about this role.

banner

Oshi Health (operating at oshihealth.com) is a virtual gastrointestinal health care platform engineered for whole-person digestive relief. Founded in 2018 by Sam Holliday, who serves as CEO, and headquartered in Not specified, Oshi Health does X instead of Y — providing life-changing digestive healthcare through virtual visits. Under the hood, a dedicated team of digestive health experts, including GI providers, registered dietitians, and gut-brain specialists, are available at your fingertips. This allows patients to find lasting digestive relief with integrated, on-demand gastrointestinal health care for IBD, IBS, and more. Backed by $113M in total funding across 3 funding rounds, including a recent $60 million Series C funding round.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More