Empowering Providers. State by State.
Infrastructure and Security Engineer
Location
United States
Posted
106 days ago
Salary
0
Seniority
Senior
Job Description
Infrastructure and Security Engineer
Statewise
• Own AWS Infrastructure Architecture & Security • Architect and maintain AWS infrastructure across compute, networking, databases, caching, storage, and serverless services • Design for scalability, elasticity, and cost efficiency • Own VPC architecture, subnet segmentation, routing, and security boundaries • Design and enforce IAM policies, least-privilege access, and secrets management • Strengthen encryption standards (at rest and in transit) and key management • Design and improve monitoring, alerting, and observability across the stack • Move from reactive alerts to proactive system health signals • Define uptime expectations, SLAs, and capacity planning • Create and maintain incident response runbooks and disaster recovery plans • Regularly test and validate backup and recovery procedures • Strengthen AWS security services usage including GuardDuty, WAF, CloudTrail, Config, and Security Hub • Own vulnerability scanning, patch management, and remediation tracking • Support audits, security assessments, and penetration test remediation • Drive toward steady-state audit readiness, not scramble-based compliance • Improve and maintain Azure DevOps build and release pipelines • Implement low-blast-radius release strategies • Enforce security gates within deployment workflows • Improve rollback confidence and deployment predictability • Collaborate on infrastructure needs for new services and features • Drive infrastructure-as-code practices where they create leverage • Influence architectural decisions related to scalability, cost, and security • Raise operational awareness and security discipline across the team
Job Requirements
- 5+ years of infrastructure, DevOps, or cloud engineering experience
- Deep hands-on experience with AWS (EC2, RDS, VPC, S3, Lambda, IAM)
- Strong understanding of AWS security services and IAM best practices
- Experience designing scalable, elastic production systems
- Experience maturing and hardening HIPAA-compliant environments
- Strong networking fundamentals: VPCs, subnets, routing, DNS, load balancing
- Experience with monitoring and observability tools (CloudWatch, Datadog, or similar)
- Hands-on experience with CI/CD pipelines (Azure DevOps preferred)
- Familiarity with Infrastructure-as-Code (Terraform, CloudFormation, or CDK)
- Experience in healthcare or regulated software environments strongly preferred
- Must be located in and authorized to work in the United States.
Benefits
- Remote-first role (Nashville or Fort Worth proximity is a plus, not a requirement)
- Competitive salary based on experience
- Medical insurance with employer contribution
- HSA with employer contribution
- Dental insurance available (employee-paid)
- 401(k) with employer match
- Flexible PTO with an expectation that people actually take time off
- Paid parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Plan and engineer the integration of a wide variety of cybersecurity and IT tools into Wraithwatch’s core artificial intelligence engine. • Ensure AI engine has access to common data models and function execution models across disparate sets of IT and security tools. • Provide cybersecurity subject matter expertise, oversight, and optimization into autonomous reasoning and analysis performed by Wraithwatch system. • Own Wraithwatch’s internal corporate cybersecurity posture across our company endpoints, cloud systems, build pipelines, and AI subsystems.
Director, Privacy & Security, Legal
SentinelOneSecure your enterprise with the autonomous cybersecurity platform. Endpoint. Cloud. Identity. XDR. Now.
• Develop and execute a global legal strategy for privacy and data security that aligns with SentinelOne’s rapid growth and product innovation. • Work cross-functionally across the organization, supporting the Commercial team on the privacy aspects of both inbound and outbound work while collaborating closely with the Legal Product team. • Provide expert guidance on a wide range of privacy, security, and compliance matters, ensuring that legal requirements are integrated seamlessly into our technical operations. • Lead the legal side of incident management and response, providing strategic advice and legal guidance on all types of incidents to ensure the company navigates complex security events with precision and speed.
__Own The Role:__112Cyber (formerly SP6 Cyber Risk & Compliance) is looking for a Compliance SME wanting to take the next step in their career! In this role, you will assist organizations in solidifying and strengthening their security posture while also conducting assessments for those pursuing certification. Joining our Compliance team, you will see your impact across the company as you take ownership over customer projects and advising our platform team on the different compliance rules. From there, you will be supporting Defense Industrial Base (DiB) companies to ensure they are CMMC and/or NIST 800-171 compliant. You will accomplish this through providing pre-audit readiness and GAP assessments, plans of action and milestones (POA&M) support, Compliance as a Service (CaaS), and official C3PAO assessments. __**How You’ll Drive Success:**____Advisory Services__ - Leading cybersecurity gap assessments aligned with NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC). - Supporting the day-to-day activities of engagements for external clients, as a contributing member of 112Cyber’s customer-facing Cyber Risk & Compliance practice. - Assist external customers in their FedRAMP, DFARS 7012, CMMC, and NIST 800-171 compliance initiatives. - Applying cyber compliance / risk management knowledge, control principles and technical knowledge across cyber risk and compliance engagements. - Consulting with end clients to gather requirements and understand our clients' key business and security challenges. Working with team members to advise on practical and cost-effective solutions to help mitigate our clients’ cybersecurity risks and challenges. - In depth knowledge of relevant security regulatory compliance requirements and translating those into business processes and security controls to enhance and support client’s compliance and audit capabilities. - Articulating and defending IT controls testing approach and performing test of design and operating effectiveness. - Develop and deliver training to internal teams and customers. - Establishing and maintaining effective working relationships with colleagues, existing clients, and prospective client organizations. - Supporting the ASCERA product team and advising them on NIST continuous monitoring software. __C3PAO Assessments__ - Conducting formal assessments of organizations’ cybersecurity practices using the CMMC assessment process (CAP). - Collaborate with client organizations to plan assessments, develop assessment schedules, and ensure readiness - Assess the effectiveness of security practices and ensure they align with the CMMC practices and processes. - Interview key personnel within the organization to understand how cybersecurity practices are implemented and maintained. - Evaluate sufficiency and adequacy of evidence to verify implementation. - Maintain an objective and unbiased stance during the assessment process, ensuring that conclusions are based on facts and evidence. - Ensure that all documentation is properly prepared for submission to eMASS if the organization is seeking certification.
Senior Software Engineer – OpenShift Infrastructure, Security Compliance
Red HatThe leading provider of enterprise open source solutions.
• Develop tooling to generate and automate regulatory benchmark guidance • AI driven tooling (MCP servers/toolsets) that integrates with IDEs (Claude Code/Cursor) • Understanding Compliance Operator resources, like CustomRules and Profiles • Implementing checks using multiple scanning technologies, like OpenSCAP and CEL expressions • Developing and maintaining operators that improve OpenShift security posture • Contribute to industry benchmark regulatory bodies where applicable (CIS)




