Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Opportunity & Impact
We are seeking a Staff Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands-on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact.
You will function as a partner to our Engineering teams, embedding security into the SDLC by default. Whether it is container security, Kubernetes hardening, or architecture design, you will have the autonomy to define our standards and ensure the secure path is always the easy path for every engineer on the team.
As a core member of a small, senior team, your technical decisions will scale across our entire network, directly impacting how we protect data for every customer we serve.
We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership.
Our Engineering Culture & How We Work
Transparency, Ownership & Autonomy
We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Staff Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes.
We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too - when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern.
We own the systems we maintain, not just the new features on the roadmap. You'll have latitude to identify and drive platform work - defining scope, consulting on priority, and seeing it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.
Job Responsibilities:
Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening.
Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.
Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
Evaluate and secure infrastructure-as-code across all environments.
Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship.
Oversee bug bounty triage and maintain professional engagement with external security researchers.
Required Skills & Experience:
8+ years in security engineering with a track record of Staff-level impact through system architecture, leadership of strategic initiatives, and technical mentorship.
Deep technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.
Expertise in threat modeling for Applications built using Node.js, TypeScript, Python or Go.
Proven track record institutionalizing secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.
Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.
End-to-end accountability for vulnerability management lifecycles, encompassing everything from initial triage to final production remediation.
Ability to operationalize compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.
Exceptional written communication skills with the ability to influence technical roadmaps within a remote, asynchronous organizational culture.
Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.
Our stack - you'll be hands-on with these:
AWS, Docker, EKS
Crowdstrike, Jamf, Okta, GuardDuty, Sumologic
Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane
Github Actions, Terraform, Helm, ArgoCD and Atlantis
Postgres, Redis, Kafka
Nice to have in your background:
Experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.
Go, Node.js, or TypeScript - we're a TypeScript shop and it helps to be comfortable there
VPN administration or enterprise network security experience
Dependency management tooling (Renovate, Dependabot)
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Redox
Explore Top Companies in this Space
Stedi
Programmable Healthcare Clearinghouse & APIs / EDI Infrastructure & Developer Tools / HealthTech Revenue Cycle Management (RCM) / Enterprise B2B SaaS
SteadyMD
HealthTech / Telehealth / B2B Healthcare
Nuna
HealthTech / Healthcare Data Infrastructure / Value-Based Care Platforms / B2B Enterprise SaaS
Mira Mace
HealthTech & Patient Advocacy / AI Care Navigation SaaS / Insurance Integration & Care Coordination / B2B2C Healthcare Services
Redox
View Company ProfileRedox (operating under redoxengine.com) is the premier, enterprise-grade healthcare interoperability pioneer, cloud-native data normalization network, and clinical API architect engineered to operate as the definitive, single-source integration layer for healthcare providers, payers, life science institutions, and digital health applications globally. The company completely eliminates the severe systemic friction of modern medical software deploymentsโwhere software developers and health systems lose months of engineering velocity to custom EHR vendor configurations, brittle HL7/FHIR mapping pipelines, complex VPN setups, and fragmented health data exchange standardsโby deploying a unified, high-concurrency cloud API platform. Moving far beyond traditional, passive point-to-point interface engines or slow middleware registries, Redox natively unifies bi-directional Electronic Health Record (EHR) integration compatibility with over 55 distinct clinical vendors, in-flight protocol translation (converting HL7, X12, CDA, and custom JSON into standardized FHIR models), automated workflow orchestration, and enterprise-grade cloud developer hubs into a single high-availability data infrastructure. Trusted by over 12,000 connected healthcare organizations and processing billions of patient records annually, the platform empowers scaling digital health solutions to accelerate clinical product launches, achieve absolute data integrity, and minimize hospital integration timelines with production-hardened precision. Under the hood, its sophisticated technical coreโbacked by over $100 million in growth funding from elite venture institutions like Adams Street Partners, Battery Ventures, and .406 Venturesโnatively orchestrates advanced cross-domain routing loops, Zero Trust security controls, and preferred data ingestion linkages alongside major hyper-scalers including AWS, Databricks, and Google Cloud. What sets Redox apart is its uncompromising dedication to replacing ancient healthcare data silos with modern, developer-first API momentum; by bridging the gap between performance-intensive legacy infrastructure and real-time application capabilities, the firm remains the definitive, category-defining cornerstone of global health-tech connectivity and automated clinical insight delivery.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
