SmarterDx logo
SmarterDx

Improving clinical and financial outcomes with physician-validated AI for documentation and coding.

Staff Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

19 hours ago

Salary

$230K - $250K / year

Seniority

Lead

Bachelor Degree8 yrs expEnglishAWSCloudPythonTerraformTypeScriptGo

Job Description

Staff Security Engineer

SmarterDx

• Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product. • Publish the org's AI-security standard and drive its adoption by other engineering teams. • Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources, and the standards that keep detections high-signal as we grow. • Own incident-response readiness: the plan, the playbooks, and tested tabletops tied to the HIPAA breach-notification timeline, and help lead response when a real incident happens. • Lead complex security work across teams from start to finish, resolving ambiguity and coordinating with Platform, Engineering, and Compliance. • Act as the senior security resource across cloud security and security reviews, and the security expert other engineering teams seek out for guidance on high-stakes decisions. • Mentor teammates who are growing their security depth, set team standards for detection authoring and code review, and help raise our interview and hiring bar. • Build and grow security automation that gives a small team more reach, and contribute to the tooling the team runs on. • Take part in architecture reviews and threat modeling on our highest-risk designs, and communicate the resulting security architecture so the whole team can understand it and build on it.

Job Requirements

  • 8+ years in security and software engineering, with deep hands-on experience in AWS and cloud-native infrastructure, including working competence with containerized workloads (EKS) and infrastructure-as-code (Terraform).
  • A track record of leading complex security work across teams and making other engineers more effective.
  • Depth in AI and agentic security: securing LLM applications, agentic frameworks, and MCP, plus prompt-injection and agentic-access defenses.
  • Depth in threat detection engineering: designing, authoring, and tuning detections in a modern SIEM, and reasoning about coverage against real threats.
  • Incident-response experience, including building the plan and running the response.
  • The ability to write production code (Python, Go, or TypeScript) and build security tooling, not only configure products.
  • Strong writing and communication; you can publish a standard other teams adopt and explain a hard design to a non-security audience.
  • Working knowledge of SOC 2 and HIPAA, and the judgment to design controls that hold up without stalling delivery.
  • Experience mentoring and leveling up other engineers.

Benefits

  • Medical, Dental & Vision – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
  • Paid Parental Leave – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
  • Remote-First Team – Work from anywhere in the U.S.
  • Unlimited PTO & 10 Holidays – So you can relax and recharge.
  • 401(k) with Traditional & Roth Options – Tax-advantaged retirement savings through Fidelity with a 4% match.
  • Minimal Bureaucracy – A fast-moving, high-impact environment where you can focus on what matters.
  • Incredible Teammates! – Work alongside smart, supportive, and mission-driven colleagues.

Related Categories

Related Job Pages

More Security Engineer Jobs

CrowdStrike logo

Security Advisor I, Falcon Complete (Remote)

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Engineer19 hours ago
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on large scale distributed systems, processing almost 3 trillion events per day and this traffic is growing daily. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We're proud to work for a mission-driven company leveraging AI to transform the way we work. CrowdStrikers drive their careers through flexibility and autonomy while also being expected to contribute to a culture of responsible AI adoption, experimentation, and innovation. We use an AI-first mindset as a force multiplier to proactively and continuously accelerate execution, build expertise, uncover insights, and solve complex problems. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: The Falcon Complete Security Advisor works within a team of advisors focused on overall health and security posture of all Falcon Complete customers. The ideal candidate will demonstrate a combination of technical, security, and customer management skills aimed at guiding customers towards a successful and secure experience with Falcon Complete. Under the direction of leadership, this role will execute daily tasks to ensure Falcon Complete can achieve its mission to stop breaches. What You'll Do: - Assess customer’s Falcon environment and ensure alignment with Falcon Complete standards. - Provide Falcon Complete customers with recommendations that align to improved security. - Create and recommend remediation for components of CrowdStrike products that may lead to improved security posture. - Contact customers directly upon identification of misalignment with Falcon Complete standards. - Document, update, and resolve all customer related issues in accordance with established procedures and SLAs. - Develop and provide customers with service reports and stats as requested. - Partner with internal teams to ensure customer satisfaction. - Liaise with support team to help troubleshoot and coordinate efforts to resolve technical issues. What You'll Need: - 2+ years in Cybersecurity focused role. - Customer empathy and ability to guide customers towards desired outcome. - Excellent customer-facing communication skills including verbal and written. - Partner with CrowdStrike teams to troubleshoot and resolve customer issues. - Adept in Windows, Linux, and MAC operating systems. - Experience or demonstrated knowledge of threat detection and incident response. - Bachelor's degree in Technology and/or Cybersecurity or relevant experience. - Cybersecurity certifications from reputable organizations such as SANS, ISC2 or equivalent. - Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes. Bonus Points: - Incident Management and CSIRT operation - Change Management - Malicious Code: Detection and Response - Audit, Logging, and Monitoring Controls (SIEM, UEBA, MDR/XDR). - Intrusion Detection and Response - Experience working with complex, sophisticated clients - Strong analytical capabilities and a desire to learn new things - Able to work across multiple teams to resolve customer issues and requests - Demonstrated experience as a security advisor or consultant - Knowledge of the following frameworks: ISO 27001/2, NIST Cyber Security Framework, CIS Critical Security, PCI DSS, Cloud Controls Matrix and MITRE Att&ck a plus. #LI-RC2 #LI-Remote This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.Benefits of Working at CrowdStrike: - Market leader in compensation and equity awards - Comprehensive physical and mental wellness programs - Competitive vacation and holidays for recharge - Paid parental and adoption leaves - Professional development opportunities for all employees regardless of level or role - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections - Vibrant office culture with world class amenities - Great Place to Work Certified™ across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance. Find out more about your rights as an applicant. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to Work CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $85,000 - $120,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.For detailed information about the U.S. benefits package, please click here. Expected Close Date of Job Posting is:09-21-2026

United States
$85K - $120K / year
KBR, Inc. logo

Information System Security Officer – ISSO

KBR, Inc.

We deliver science, technology and engineering solutions to governments and companies around the world.

Security Engineer19 hours ago
Full TimeRemoteTeam 10,001+Since 1901H1B No Sponsor

• Provide support to the Test Resource Management Center’s (TRMC) All Domain Test Range (ADTR) • Assist with providing solutions to complex problems in a manner which meets both functional and security requirements • Ensure the team’s computing environment operational and in compliance with all TRMC directives and applicable RMF requirements • Collaborate with other distributed team members to discuss current system status and plan desired future enhancements • Develop, implement, and maintain security policies, procedures, and standards to safeguard organizational information systems • Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate potential threats • Administer Windows and Linux servers • Manage Active Directory • Oversee the virtualization of servers using VMware, Hyper-V, or similar technologies

Arizona + 3 moreAll locations: Arizona | Florida | Maryland | Virginia
$125K - $155K / year
Hitachi logo

Cybersecurity Professional

Hitachi

Hitachi Social Innovation is POWERING GOOD

Security Engineer19 hours ago
Full TimeRemoteTeam 10,001+Since 1910H1B Sponsor

• Conduct cybersecurity risk assessments for technology, business, and operational initiatives. • Analyze threats, vulnerabilities, and control effectiveness to determine residual risk. • Maintain and update cybersecurity risk registers. • Evaluate risks against approved risk appetite and risk tolerance thresholds. • Track risk mitigation and remediation activities through closure. • Support the operation of the Cybersecurity Risk and Control Framework (CRCF). • Challenge the completeness and accuracy of risk assessments and mitigation plans. • Monitor adherence to cybersecurity policies, standards, and control requirements. • Assist with exception and risk acceptance reviews. • Support cybersecurity governance forums and reporting activities. • Assist with internal and external cybersecurity audits. • Coordinate evidence collection and remediation tracking. • Assess compliance with internal cybersecurity standards and regulatory requirements. • Support control assessments and gap analyses. • Develop risk metrics, dashboards, and management reports. • Prepare materials for management and governance reviews. • Escalate significant cybersecurity risk exposures and emerging trends. • Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams. • Provide guidance on cybersecurity risk management processes and requirements. • Facilitate risk reviews and risk treatment discussions with stakeholders. • Promote cybersecurity awareness and risk-informed decision making.

Mexico

Security / Compliance Architect

NATIONMIND LLC

NationMind LLC is a technology consulting firm focused on Technical Engineering, software development, technicians, QA testing and services. We help clients build reliable, scalable applications with a strong emphasis on automation, performance, and quality. Our team works across industries, delivering solutions that drive innovation and operational efficiency.

Security Engineer20 hours ago

Role Description The Security / Compliance Architect is the primary security design authority for the engagement. This role is responsible for: - Defining the controlled data boundary. - Translating compliance and business requirements into enforceable controls. - Shaping the secure enclave design. - Ensuring the overall solution is defensible from a governance, audit, and risk-management standpoint. This is a client-facing onshore role requiring strong experience in data protection, compliance-aligned architecture, information protection controls, and regulated collaboration environments. Key Responsibilities - Lead the definition of the controlled data / CUI boundary, including in-scope users, repositories, workflows, endpoints, and approved handling paths. - Translate customer requirements into a target-state security architecture for a secure collaboration enclave. - Define the DLP and information protection strategy across collaboration, email, endpoint, and removable media channels. - Establish the control intent for classification, labeling, monitoring, restriction, blocking, exception handling, and audit evidence generation. - Drive alignment between business process requirements and security control design to ensure the solution is usable as well as compliant. - Lead design decisions related to: - Approved vs non-approved storage locations - Secure collaboration patterns - External sharing restrictions - Exception governance - Evidence and logging requirements - Review current-state data handling patterns and identify exposure points, control gaps, and architectural risks. - Produce client-facing security design artifacts, including boundary definitions, control strategies, architecture requirements, and decision packs. - Support design reviews, steering discussions, and executive readouts. - Work closely with the platform lead to ensure Microsoft control implementation aligns with security intent. - Support pilot validation by reviewing policy effectiveness, exception scenarios, usability impacts, and audit defensibility. - Provide oversight during deployment and handover to ensure the final state aligns with the approved security design. Qualifications - 8+ years in cybersecurity architecture, security consulting, or security engineering roles. - Strong experience in one or more of the following: - Data Loss Prevention - Information Protection / Data Classification - Secure collaboration architecture - Microsoft Purview / MIP / DLP - Compliance-driven security design - Experience defining and operationalizing controls for sensitive or regulated data. - Strong understanding of: - Secure data boundaries - Access control and least privilege concepts - Audit evidence requirements - Policy exception governance - Endpoint, email, and collaboration security controls - Experience working directly with business stakeholders, security leadership, and platform teams in regulated environments. - Strong workshop facilitation, requirements analysis, and executive communication skills. - Ability to convert ambiguous customer requirements into precise security architecture decisions. Requirements - This is a remote position.

United States
$62 - $65 / hour