Skip to content

Open nowPosted 16 hours ago

Sr. Information Security Engineer

Reveleer23 open roles

Where
United States, Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Information Security EngineerReveleer · United States, Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Reveleer's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Reveleer postings stay open a median of 4 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 16 hours ago

Reveleer median: 4 days open

The posting

Sr. Information Security Engineer

Hybrid/Remote

About Reveleer

Reveleer delivers a unified platform spanning risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations navigating the complexity of value-based care. Trusted by 80+ customer organizations nationwide, the platform integrates data, analytics, and intelligent workflow automation into one governed system designed to support traceable documentation across diagnoses, quality measures, and submissions. With regulatory expertise and transparent, human-in-the-loop AI at its core, Reveleer supports organizations working to advance care quality, strengthen documentation integrity, and sustain the operational readiness needed to navigate audits with confidence.

Position Summary

  • The Senior Information Security Engineer plays a key role in safeguarding Reveleer's cloud-based healthcare SaaS platforms, AI/ML systems, infrastructure, and customer data. This position designs, implements, and manages enterprise-grade security solutions aligned to HIPAA, HITRUST, SOC 2, NIST 800-53, and NIST AI RMF. Because Reveleer's platform relies heavily on AI and large language models to process clinical data, this role carries direct responsibility for securing AI pipelines, models, and the PHI that flows through them. The ideal candidate is a hands-on technologist with depth in cloud security, AI/LLM security, application security, DevSecOps, identity, and security automation.

Cloud and Infrastructure Security

  • Design and maintain secure architectures across AWS, Azure, and GCP, with emphasis on infrastructure-as-code security (Terraform, CloudFormation) and policy-as-code enforcement (OPA, Sentinel, AWS SCPs).
  • Implement guardrails using AWS Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls.
  • Operate CSPM/CNAPP tooling (e.g., Wiz, Prisma Cloud, Orca) to detect misconfigurations, toxic combinations, and exposed PHI data stores.
  • Secure containerized and serverless workloads across EKS/ECS and Lambda, including image scanning, admission control, runtime protection, and least-privilege task roles.
  • Enforce network segmentation, TLS/encryption standards, and centralized key and secrets management (AWS KMS, Secrets Manager, HashiCorp Vault).

AI and Machine Learning Security

  • Partner with Data Science and AI Engineering to secure model development, training, fine-tuning, inference, and RAG pipelines that handle PHI and PII.
  • Apply the OWASP Top 10 for LLM Applications and MITRE ATLAS to threat model AI features, addressing prompt injection, insecure output handling, training data poisoning, model and data exfiltration, and excessive agency in agentic workflows.
  • Implement AI gateway, guardrail, and content-filtering controls (e.g., Bedrock Guardrails, Azure AI Content Safety, LLM firewalls) along with input/output validation, rate limiting, and prompt and completion logging for audit.
  • Govern third-party and foundation model usage: vendor security review, data residency and retention terms, zero-retention and no-training contractual controls, and BAA coverage for any AI service touching PHI.
  • Establish controls against shadow AI, including discovery of unsanctioned generative AI tools, DLP policies for AI endpoints, and enterprise-approved alternatives.
  • Secure the ML supply chain: model and artifact provenance, signed models, dependency scanning for ML libraries, notebook and MLOps platform hardening (SageMaker, Databricks, MLflow).
  • Contribute to AI governance alongside Compliance and Legal, mapping controls to NIST AI RMF, ISO/IEC 42001, HITRUST AI assurance criteria, and emerging state and federal AI regulation.

Application and SaaS Security

  • Embed security into CI/CD pipelines with SAST, DAST, SCA, secrets scanning, and IaC scanning (Snyk, StackHawk, Semgrep, etc).
  • Perform threat modeling, secure design reviews, and code reviews for microservices, APIs, and AI-enabled features.
  • Secure API and machine-to-machine authorization patterns (OAuth 2.0, OIDC, mTLS, scoped service tokens) across internal and partner integrations.
  • Manage software supply chain risk through SBOM generation, dependency governance, and artifact signing.
  • Drive penetration testing, bug bounty intake, and remediation validation; track findings to closure with Engineering.
  • Ensure PHI and PII protection across SaaS platforms through data classification, tokenization, de-identification, and DLP.

Endpoint and Identity Security

  • Manage and tune EDR/XDR platforms (Palo Alto Cortex XDR, Microsoft Defender for Endpoint), including detection engineering and response automation.
  • Implement identity security through Microsoft Entra ID, Conditional Access, PIM, and risk-based authentication; advance phishing-resistant MFA and password less adoption.
  • Govern non-human identities, service principals, workload identities, and AI agent credentials with least privilege and short-lived tokens.
  • Support Intune and MDM compliance baselines for Windows, macOS, iOS, and Android; apply CIS Benchmarks and configuration drift monitoring.
  • Operate SaaS security posture management (SSPM) for third-party app integrations and OAuth grant risk.

Security Operations and Incident Response

  • Monitor and triage alerts, investigate incidents, and coordinate response with the SOC and MDR partners.
  • Build and maintain detection content in the SIEM, including detection-as-code, log pipeline coverage, and MITRE ATT&CK mapping.
  • Develop incident response runbooks, playbooks, and forensic procedures, including scenarios specific to AI systems such as model misuse, data leakage through prompts, and compromised AI integrations.
  • Automate response and enrichment through SOAR workflows, Python, and PowerShell.
  • Participate in tabletop exercises, purple team activity, and post-incident reviews.

Governance, Risk, and Compliance

  • Support audits and evidence collection for HIPAA, HITRUST, SOC 2 Type 2, NIST 800-53, and customer security assessments; leverage compliance automation platforms.
  • Maintain asset and AI system inventories, risk registers, and remediation tracking with clear SLAs.
  • Conduct vendor and third-party risk reviews, with added scrutiny for AI subprocessors and data flows.
  • Partner with Compliance to keep technical controls, policies, and standards in alignment.
  • Contribute to security awareness and training, including secure and responsible AI use guidance for employees and engineers.

Qualifications

Required:

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
  • 5+ years of experience in security engineering or related technical security roles.
  • Strong knowledge of cloud-native security (AWS, Azure, GCP) and modern SaaS architectures.
  • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
  • Familiarity with HIPAA, HITRUST, NIST, and SOC 2 requirements.
  • Experience securing containerized and serverless workloads (e.g., EKS, Lambda).

Preferred:

  • Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or GIAC (GSEC, GCIA, GCIH).
  • Experience with Terraform, Ansible, or CloudFormation for infrastructure-as-code security.
  • Experience in DevSecOps pipelines and tools (e.g., Jenkins, Bitbucket).
  • Strong scripting skills (Python, PowerShell, or Bash).

Key Competencies

  • Analytical and detail-oriented with strong problem-solving skills.
  • Ability to balance business needs with risk mitigation.
  • Excellent communication skills, able to translate complex technical topics for non-technical stakeholders.
  • Collaborative team player with a proactive approach to continuous improvement.

WHAT YOU’LL RECEIVE:

• Competitive salary

• Medical, Dental and Vision benefits

• 401k match

• Generous PTO plan

Our compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.

Reveleer E-Verifies all new hires.

Reveleer is an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, disability status or genetic information, in compliance with applicable federal, state and local law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Reveleer's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Reveleer's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Reveleer's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.