Hiring.Camp

Sr. Information Security Engineer

Reveleer

·

Yesterday

Salary
$140k – $160k/yr
Location
US
Workplace
Remote
Type
Full-time
Department
Engineering
Experience
5+ years
Education
Master
Source
Breezy HR

Description

Sr. Information Security Engineer

Hybrid/Remote

About Reveleer

Reveleer delivers a unified platform spanning risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations navigating the complexity of value-based care. Trusted by 80+ customer organizations nationwide, the platform integrates data, analytics, and intelligent workflow automation into one governed system designed to support traceable documentation across diagnoses, quality measures, and submissions. With regulatory expertise and transparent, human-in-the-loop AI at its core, Reveleer supports organizations working to advance care quality, strengthen documentation integrity, and sustain the operational readiness needed to navigate audits with confidence.

Position Summary

  • The Senior Information Security Engineer plays a key role in safeguarding Reveleer's cloud-based healthcare SaaS platforms, AI/ML systems, infrastructure, and customer data. This position designs, implements, and manages enterprise-grade security solutions aligned to HIPAA, HITRUST, SOC 2, NIST 800-53, and NIST AI RMF. Because Reveleer's platform relies heavily on AI and large language models to process clinical data, this role carries direct responsibility for securing AI pipelines, models, and the PHI that flows through them. The ideal candidate is a hands-on technologist with depth in cloud security, AI/LLM security, application security, DevSecOps, identity, and security automation.

Cloud and Infrastructure Security

  • Design and maintain secure architectures across AWS, Azure, and GCP, with emphasis on infrastructure-as-code security (Terraform, CloudFormation) and policy-as-code enforcement (OPA, Sentinel, AWS SCPs).
  • Implement guardrails using AWS Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls.
  • Operate CSPM/CNAPP tooling (e.g., Wiz, Prisma Cloud, Orca) to detect misconfigurations, toxic combinations, and exposed PHI data stores.
  • Secure containerized and serverless workloads across EKS/ECS and Lambda, including image scanning, admission control, runtime protection, and least-privilege task roles.
  • Enforce network segmentation, TLS/encryption standards, and centralized key and secrets management (AWS KMS, Secrets Manager, HashiCorp Vault).

AI and Machine Learning Security

  • Partner with Data Science and AI Engineering to secure model development, training, fine-tuning, inference, and RAG pipelines that handle PHI and PII.
  • Apply the OWASP Top 10 for LLM Applications and MITRE ATLAS to threat model AI features, addressing prompt injection, insecure output handling, training data poisoning, model and data exfiltration, and excessive agency in agentic workflows.
  • Implement AI gateway, guardrail, and content-filtering controls (e.g., Bedrock Guardrails, Azure AI Content Safety, LLM firewalls) along with input/output validation, rate limiting, and prompt and completion logging for audit.
  • Govern third-party and foundation model usage: vendor security review, data residency and retention terms, zero-retention and no-training contractual controls, and BAA coverage for any AI service touching PHI.
  • Establish controls against shadow AI, including discovery of unsanctioned generative AI tools, DLP policies for AI endpoints, and enterprise-approved alternatives.
  • Secure the ML supply chain: model and artifact provenance, signed models, dependency scanning for ML libraries, notebook and MLOps platform hardening (SageMaker, Databricks, MLflow).
  • Contribute to AI governance alongside Compliance and Legal, mapping controls to NIST AI RMF, ISO/IEC 42001, HITRUST AI assurance criteria, and emerging state and federal AI regulation.

Application and SaaS Security

  • Embed security into CI/CD pipelines with SAST, DAST, SCA, secrets scanning, and IaC scanning (Snyk, StackHawk, Semgrep, etc).
  • Perform threat modeling, secure design reviews, and code reviews for microservices, APIs, and AI-enabled features.
  • Secure API and machine-to-machine authorization patterns (OAuth 2.0, OIDC, mTLS, scoped service tokens) across internal and partner integrations.
  • Manage software supply chain risk through SBOM generation, dependency governance, and artifact signing.
  • Drive penetration testing, bug bounty intake, and remediation validation; track findings to closure with Engineering.
  • Ensure PHI and PII protection across SaaS platforms through data classification, tokenization, de-identification, and DLP.

Endpoint and Identity Security

  • Manage and tune EDR/XDR platforms (Palo Alto Cortex XDR, Microsoft Defender for Endpoint), including detection engineering and response automation.
  • Implement identity security through Microsoft Entra ID, Conditional Access, PIM, and risk-based authentication; advance phishing-resistant MFA and password less adoption.
  • Govern non-human identities, service principals, workload identities, and AI agent credentials with least privilege and short-lived tokens.
  • Support Intune and MDM compliance baselines for Windows, macOS, iOS, and Android; apply CIS Benchmarks and configuration drift monitoring.
  • Operate SaaS security posture management (SSPM) for third-party app integrations and OAuth grant risk.

Security Operations and Incident Response

  • Monitor and triage alerts, investigate incidents, and coordinate response with the SOC and MDR partners.
  • Build and maintain detection content in the SIEM, including detection-as-code, log pipeline coverage, and MITRE ATT&CK mapping.
  • Develop incident response runbooks, playbooks, and forensic procedures, including scenarios specific to AI systems such as model misuse, data leakage through prompts, and compromised AI integrations.
  • Automate response and enrichment through SOAR workflows, Python, and PowerShell.
  • Participate in tabletop exercises, purple team activity, and post-incident reviews.

Governance, Risk, and Compliance

  • Support audits and evidence collection for HIPAA, HITRUST, SOC 2 Type 2, NIST 800-53, and customer security assessments; leverage compliance automation platforms.
  • Maintain asset and AI system inventories, risk registers, and remediation tracking with clear SLAs.
  • Conduct vendor and third-party risk reviews, with added scrutiny for AI subprocessors and data flows.
  • Partner with Compliance to keep technical controls, policies, and standards in alignment.
  • Contribute to security awareness and training, including secure and responsible AI use guidance for employees and engineers.

Qualifications

Required:

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
  • 5+ years of experience in security engineering or related technical security roles.
  • Strong knowledge of cloud-native security (AWS, Azure, GCP) and modern SaaS architectures.
  • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
  • Familiarity with HIPAA, HITRUST, NIST, and SOC 2 requirements.
  • Experience securing containerized and serverless workloads (e.g., EKS, Lambda).

Preferred:

  • Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or GIAC (GSEC, GCIA, GCIH).
  • Experience with Terraform, Ansible, or CloudFormation for infrastructure-as-code security.
  • Experience in DevSecOps pipelines and tools (e.g., Jenkins, Bitbucket).
  • Strong scripting skills (Python, PowerShell, or Bash).

Key Competencies

  • Analytical and detail-oriented with strong problem-solving skills.
  • Ability to balance business needs with risk mitigation.
  • Excellent communication skills, able to translate complex technical topics for non-technical stakeholders.
  • Collaborative team player with a proactive approach to continuous improvement.

WHAT YOU’LL RECEIVE:

• Competitive salary 

• Medical, Dental and Vision benefits 

• 401k match

• Generous PTO plan 

 Our compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.

Reveleer E-Verifies all new hires.

Reveleer is an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, disability status or genetic information, in compliance with applicable federal, state and local law.

Skills

PythonAWSAzureGCPTerraformAnsibleJenkinsCI/CDMachine LearningDatabricksData ScienceiOSAndroidPenetration TestingSIEMSOCOAuthMicroservicesComplianceSOC 2

Similar Jobs

30

Cyber Security Engineer - Information Systems Security Engineer (ISSE) - Senior Principal

Modern Technology Solutions Inc·Dayton, OH

Today

Sr. Manager, Information Security

Strayer·Remote, US·Remote

1d ago

Information Systems Security Officer - Senior

Modern Technology Solutions Inc·Colorado Springs, CO·Onsite

1d ago

Senior Information Security Consultant

Keystone Solutions·Bruxelles

1d ago

Senior Information Security Architect

Verisign·Reston, Virginia·Hybrid

1d ago

[IT Delivery Center] Senior Information Security Analyst

Eurofins Scientific·Ho Chi Minh City, Ho Chi Minh·Hybrid

1d ago

Information Security Analyst Senior

AMERICAN SYSTEMS·Colorado Springs, CO

2d ago

Senior Information System Security Officer (ISSO) - Forest, MS (Sponsor Clearance)

RTX·US-MS-FOREST-425 ~ 19859 Hwy 80 ~ BLDG 425, US·Onsite

2d ago

Sr. Information Security Analyst

Point32Health·Canton MA Office, US

2d ago

Senior Information Security Specialist

Cibc·Toronto-141 Bay, 16th Floor·Remote, Hybrid, Onsite

2d ago

Senior Information Security & Compliance Business Partner

Fullsteam·US-GA-Remote, US·Remote

2d ago

Senior Manager Information Security

Tabby·Remote, Serbia·Remote

2d ago

Information Security Analyst-Senior (RMF)

Caci·BMA FORT BRAGG NC, US·Onsite

5d ago

Sr. Manager, Cyber Security - Information Security Office Consultant

Capitalone·Plano, TX

5d ago

Information Systems Security Officer, Senior (TS Clearance w/SCI eligibility)

AMERICAN SYSTEMS·Jacksonville, FL

5d ago

(USA) Senior Systems and Infrastructure Engineer, Information Security

Walmart·Bentonville Global Tech AR BENTONVILLE Home Office, US

5d ago

Senior Director - Information Security

Qlarant·Remote, DC +2·Remote

5d ago

Senior Information Security Engineer - Product & Customer Organization

IFS·Colombo, Western Province

5d ago

SR Information Security Engineer - IS-Mod

Mayo Clinic·Rochester, MN

5d ago

Information System Security Officer, Senior

WOOD Consulting Services·Annapolis Junction, MD

6d ago

Senior Information Systems Security Manager (ISSM)

KBR Careers·Washington, 110 Luke Ave SW

6d ago

Sr Information Security Specialist (US)

Td·13024 Ballantyne Corporate Place, Charlotte +1·Onsite

6d ago

Senior Information System Security Officer (ISSO) - Tewksbury, MA

RTX·US-MA-TEWKSBURY-TB3 ~ 50 Apple Hill Dr ~ CONCORD BLDG, Tewksbury Tb3 300 Concord·Onsite

6d ago

Information Security Senior Manager

Bdouk·London - Baker Street, UK

6d ago

Senior Information Security Systems Officer

Corvus Consulting·Lakehurst, NJ

6d ago

Information Security Specialist (Senior-Level)

" Link Solutions, Inc."·Orlando, FL

6d ago

Information Systems Security Manager Senior

Modern Technology Solutions Inc·Wright-Patterson AFB, OH

6d ago

Senior Information Security Engineer

IFS·Colombo, Western Province

6d ago

Information System Security Officer - Senior

Pae·US-VA-Warrenton1-Classified, US·Onsite

1w ago

Senior Manager, Information Security

D Matrix·Santa Clara·Hybrid

1w ago
Remote Sr. Information Security Engineer at Reveleer • $140k – $160k/yr | Hiring.Camp