An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Medplum is redefining healthcare with our open source, API-first EHR platform, trusted by leading digital health and life sciences companies.
As a Security Engineer, you will own vulnerability remediation, build security automation, and work across TypeScript apps and AWS to strengthen security architecture.
Join a fast-moving startup and collaborate with engineers and leadership to improve security posture across the platform and supporting compliance programs.
Security is a core part of the Medplum platform. We build open source healthcare infrastructure that stores and processes sensitive health information for healthcare organizations ranging from startups to large enterprises.
As a Security Engineer at Medplum, you will work across our application, cloud infrastructure, developer tooling, and security operations to identify vulnerabilities and make our systems more secure.
This is a hands-on engineering role. You might investigate a suspicious production event, review an authorization change, improve our vulnerability scanning, build security automation, analyze AWS logs, fix a security bug, or implement a new control required by one of our security and compliance programs.
You will work closely with Medplum's engineering team and company leadership on real-world security problems across a large and rapidly evolving healthcare platform.
Investigate vulnerabilities across the Medplum stack and work directly with engineers to remediate them.
Perform security reviews of new features and architecture changes, analyze authentication and authorization behavior, investigate dependency and infrastructure vulnerabilities, and help improve defensive controls throughout the platform.
Build tools that make Medplum easier to secure.
Improve vulnerability detection, dependency scanning, cloud security monitoring, audit logging, secrets management, security testing, and other automated controls. Look for opportunities to replace repetitive security and compliance work with software.
Participate in security incident response and forensic investigations.
Analyze application, infrastructure, database, and cloud logs; reconstruct relevant system activity; help determine impact; and work with the broader team to remediate issues and improve future detection.
Work across our TypeScript applications and AWS infrastructure to strengthen Medplum's security architecture.
Help improve authentication and authorization, multi-tenant isolation, network security, infrastructure configuration, secure development practices, and production monitoring.
Help maintain the technical controls behind Medplum's security and compliance programs, including SOC 2, HIPAA, HITRUST, and other healthcare requirements.
Work with engineers, auditors, and company leadership to gather evidence, address findings, and implement controls that improve both security and compliance.
Assist with technical security questions from customers and partners. Help investigate customer-reported issues, explain relevant parts of the Medplum architecture, and contribute to security documentation and technical responses.
Medplum is redefining healthcare with our open source, API-first electronic health record (EHR) platform, trusted by leading digital health and life sciences companies. Our mission is to catalyze change in the healthcare industry by improving the access, privacy, and utility of health data. At Medplum, we have a unique opportunity to impact the lives of patients, speed medical research, and contribute to the open source ecosystem.