Opala logo
Opala

Connecting data flow across healthcare so that every patient's experience is optimized.

Senior Platform Security Engineer

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 11-50H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

72 days ago

Salary

$163K - $192K / year

Seniority

Senior

Job Description

Senior Platform Security Engineer

Opala

Opala develops healthcare products that tackle the most complex data challenges faced by payers and providers. As a startup originating from a major healthcare plan in the Northwest, we combine deep health-tech expertise with top-tier data and software engineering talent to create products that our customers find meaningful and valuable. These data products empower payers and their partners to find timely insights and take action to intervene in areas like value-based care analytics, interoperability compliance, and real-time streaming of clinical data. In this remote position, we're seeking an experienced Senior Platform Security Engineer to join our team. Here, you will play a critical role in securing our cloud infrastructure and embedding strong security practices across our engineering squads. You’ll bridge platform engineering and security, building paved-road guardrails that make it easy for developers to ship securely in a healthcare data environment. You'll also both "lead by doing" (designing and implementing IaC guardrails, CI/CD security checks, and software supply chain protections) AND "lead by influence" (mentoring engineers and partnering with our Security and Compliance team). Responsibilities: - Monitor and secure our Azure + AWS environments, responding to incidents and remediating vulnerabilities. - Design and implement Infrastructure as Code guardrails (Terraform, Bash, Azure CLI, AWS CLI, Jinja, CloudInit). - Embed security checks into CI/CD pipelines (GitHub Actions). - Build and manage secrets management, identity solutions, and key rotation. - Partner with squads to ensure product features are secure and compliant by design. - Investigate security breaches and document root cause and remediation steps. - Integrate logging/monitoring with SOC/MDR vendor to ensure strong detection and response. - Perform SAST/DAST testing and strengthen software supply chain security. - Develop and implement an immutable infrastructure strategy. - Build and execute a red team and blue team strategy to continually test defenses. - Research security enhancements and make recommendations to leadership. - Stay current on IT and security standards, advising the company on emerging risks. Minimum Qualifications: - Bachelor’s degree in computer science or related field (or equivalent experience). - 6+ years in platform engineering, DevSecOps, or cloud security roles, with at least 4 in a senior capacity. - 2+ years mentoring and developing junior team members. - Experience with security in both AWS and Azure. - Experience with IaC tools and automation (Terraform, Bash, Azure CLI, AWS CLI, Jinja, CloudInit). - Experience with SAST/DAST and securing the software supply chain. - Experience with OpenAPI/Swagger JSON specifications and API security. - Familiarity with SOC 2 controls and know how to enforce them in cloud systems. - Familiarity with HIPAA controls and know how to enforce them in cloud systems. - Strong Bash scripting skills for automation. - Ability to collaborate closely with developers and product squads while setting security best practices. Preferred Qualifications: - 2+ years of vendor management experience.Security certifications (AWS Security Specialty, AZ500, CISSP, etc.). - Experience using or administering compliance automation tools (Drata or similar GRC platforms). - Experience with HITRUST controls and how to enforce them in cloud systems. - Exposure to enterprise architecture frameworks such as TOGAF. - Experience in regulated industries (healthcare, fintech, etc.). - Experience leading or coordinating red/blue team exercises. - Experience with other scripting languages: PowerShell, python Benefits: - The Seattle base salary range for this full-time position is $163k-$192k. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. - Benefits include medical, dental, vision, life and AD&D insurance, EAP, short-term and long-term disability, 16 days PTO, 8 paid holidays, fully paid holiday closure, parental and family medical leave, 401k, stock options and annual bonuses and salary increases based on merit. Diversity and Inclusivity Statement: - At Opala, we believe that diversity and inclusivity are critical to our success. We encourage and value diverse perspectives and experiences, and we believe that they are essential for driving innovation and creating products that meet the needs of our diverse customer base.  Opala is an equal opportunity employer and makes employment decisions on the basis of merit. We are committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, veteran status, disability status, pregnancy, parental status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.

Job Requirements

  • Bachelor’s degree in computer science or related field (or equivalent experience).
  • 6+ years in platform engineering, DevSecOps, or cloud security roles, with at least 4 in a senior capacity.
  • 2+ years mentoring and developing junior team members.
  • Experience with security in both AWS and Azure.
  • Experience with IaC tools and automation (Terraform, Bash, Azure CLI, AWS CLI, Jinja, CloudInit).
  • Experience with SAST/DAST and securing the software supply chain.
  • Experience with OpenAPI/Swagger JSON specifications and API security.
  • Familiarity with SOC 2 controls and know how to enforce them in cloud systems.
  • Familiarity with HIPAA controls and know how to enforce them in cloud systems.
  • Strong Bash scripting skills for automation.
  • Ability to collaborate closely with developers and product squads while setting security best practices.
  • Preferred Qualifications
  • 2+ years of vendor management experience.
  • Security certifications (AWS Security Specialty, AZ500, CISSP, etc.).
  • Experience using or administering compliance automation tools (Drata or similar GRC platforms).
  • Experience with HITRUST controls and how to enforce them in cloud systems.
  • Exposure to enterprise architecture frameworks such as TOGAF.
  • Experience in regulated industries (healthcare, fintech, etc.).
  • Experience leading or coordinating red/blue team exercises.
  • Experience with other scripting languages: PowerShell, python.

Benefits

  • The Seattle base salary range for this full-time position is $163k-$192k. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.
  • Benefits include medical, dental, vision, life and AD&D insurance, EAP, short-term and long-term disability, 16 days PTO, 8 paid holidays, fully paid holiday closure, parental and family medical leave, 401k, stock options and annual bonuses and salary increases based on merit.

Related Categories

Related Job Pages

More Security Engineer Jobs

Leidos logo

AI Infrastructure – Security Intern

Leidos

Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.

InternshipRemoteTeam 10,001+Since 1969H1B Sponsor

• Gain hands-on experience at the intersection of cloud security, AI platform engineering, and federal compliance. • Work alongside experienced engineers, data scientists, and cybersecurity professionals to support the design, deployment, and hardening of AI infrastructure. • Directly support high-priority strategic AI initiatives, giving exposure to real-world challenges in operationalizing AI at enterprise scale.

United States
$48.1K - $87.0K / year
Job Closed
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Secure AI / ML platforms and workloads • Lead security architecture and threat modeling for AI/ML systems, including LLMs, RAG pipelines, agents, and AI-powered applications. • Design and implement security controls as code (services, libraries, infrastructure-as-code, policy-as-code) for AI/ML platforms and workloads. • Lead and help setup the basic infrastructure needed to safely rollout AI - MCPs, LLMs, pipelines, Test harness for AI (ie: harmbench), intake automation. • Partner with data science and MLOps teams to harden: Data ingestion and labeling, Training and fine-tuning pipelines, Model registries and deployment workflows, Inference APIs, agents, and integrations. • Define and champion secure reference architectures and patterns for common AI use cases and focus on composable architecture. • Design, implement, and continuously improve the intake, triage, and review process for AI/ML and generative AI use cases across the organization. • Build and automate self-service workflows (e.g., request forms, risk questionnaires, routing, approvals) that balance speed of delivery with security, privacy, and compliance with a focus on risk scoring and scorecards. • Define risk-based criteria for AI use case approval, including data sensitivity, model and vendor selection, integration patterns, and control requirements; this will involve in re-mapping the complete end to end lifecycle. • Review proposed AI solutions from concept through deployment, providing clear, actionable guidance to product and engineering teams. • Maintain visibility into the AI use case portfolio and risk posture, and provide regular reporting to leadership and governance bodies. • Establish and maintain monitoring and detection for AI-specific threats, such as: Prompt injection and jailbreak attempts, Data exfiltration and sensitive data exposure, Misuse or abuse of AI tools and agents, Anomalous model or pipeline behavior.

United States
$180K - $190K / year
Job Closed
Hitachi logo

Cybersecurity Compliance Project Manager

Hitachi

Hitachi Social Innovation is POWERING GOOD

Full TimeRemoteTeam 10,001+Since 1910H1B Sponsor

• Run the CFIUS Cybersecurity Compliance Program and maintain alignment with the National Security Agreement • Coordinate effectively with CFIUS Monitoring Agencies to support reporting and oversight expectations • Translate U.S. cybersecurity regulatory requirements—including Covered Information Protection Plans (CIPP), DFARS, and NIST SP 800‑171—into practical processes across the organization • Manage U.S. compliance activities connected to CFIUS, NIST SP 800‑171/172, CMMC 2.0, related federal Executive Orders, and other federal oversight obligations • Support mandatory reporting needs and maintain readiness for internal and external audits • Work with legal, technical, and business teams to maintain a proactive cybersecurity compliance posture • Support assessments and audits related to ISO 27001, ISMS, and application‑level reviews tied to CFIUS obligations • Drive improvements in compliance tooling and workflows, including work in ServiceNow IRM, OneTrust, and SharePoint migration efforts • Responsible to ensure compliance with applicable external and internal regulations, procedures, and guidelines.

United States
Job Closed
Full TimeRemoteTeam 10,001+Since 2015H1B Sponsor

• Responsible for sales of storage products and solutions in assigned territory, industry or accounts. • Uses advanced storage expertise to seek out new opportunities for customer value by expanding and enhancing existing opportunities. • Creates and drives the storage sales pipeline. • Captures leads outside of specialization and uses closed-loop lead management to ensure assignment and follow-up by others. • Collaborates with the account pursuit teams to leverage their solutions expertise for business development. • Build sales readiness and reduces client learning curve through effective knowledge transfer in storage. • Contributes to development of quota objectives and future direction for storage product lines. • Directs and coordinates supporting sales activities related to pipeline hygiene through account managers, Presales, channel partners and other relevant stakeholders. • Effectively uses internal sales tools to maintain a healthy pipeline and the account plan in a timely fashion. • Collaborates across the HPE teams to deliver a consistent approach to developing business, including account planning for end to end solutions. • Assesses solution feasibility from a technical and business perspective to determine "qualify-in"/"qualify-out" status. • Negotiates and drives profitable deals to ensure successful closure and a high win rate. • Drives sales of the storage portfolio, using strong leadership and initiative to successfully prospect, negotiate and close deals. • Establishes a professional and consultative relationship with the client by achieving an advanced understanding of the unique business needs of the client within the industry. • Works with clients up to and including the C-level for mid-to-large accounts. • Leverages advanced knowledge of competitors and industry trends to strategically position the company's products and services. • Focuses on and works with the channel to forge relationships, provide enablement of key technologies, and co-sell to end-users. • Effectively leads, evangelizes, and helps to coordinate Storage marketing campaigns (digital /new techniques) to ensure a successful launch and maintenance of the campaign momentum, in alignment with the account strategy. • Acts as a trusted storage solutions consultant for the slated accounts/region. • Reinforces and articulates HPE's strategy and portfolio to partners and champions to uncover new business opportunities and contacts, including new logos when appropriate. • Effectively uses references to craft a story that makes complex technologies seem simple and understandable for the customers • Actively generates customer interest and anticipates customer's buying trends. • Links business and financial benefits with technology offerings. • Illustrates the ROI & TCO advantages of HPE offerings for the customer's business. • Cultivates and maintains positive relationships with customers to ensure account retention and growth, to position the company as the preferred vendor to meet business needs. • Supports deal closure in partnership with relevant internal stakeholders including account managers and channel partners.

District Of Columbia + 2 moreAll locations: District Of Columbia | Maryland | Virginia
$194.5K - $456.5K / year
Job Closed