Staff Security Engineer

Far Coder

Northern (KY)

Hybrid

USD 190,000 - 200,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

100% remote first culture (US-based)
Stock options
Medical/Dental/Vision benefits on Day
Unlimited Flexible Time Off
R^Charge sabbatical program

Job summary

Redox is hiring a Staff Security Engineer for a 100% remote role based in the United States. You will own cloud security posture, drive secure development practices, and harden environments across a large health-tech platform.

You will lead container security efforts, application threat modeling, and compliance mapping to HITRUST and SOC 2 while collaborating with Platform Engineering to embed security into the SDLC and CI/CD pipelines.

Qualifications

  • 8+ years in security engineering with Staff-level impact.
  • Deep technical proficiency in Kubernetes security including network policy and container hardening.
  • Expertise in threat modeling for Applications built with Node.js, TypeScript, Python or Go.
  • Proven track record in securing SDLC & CI/CD with GitHub Actions, ensuring artifact validity.
  • Experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets (AWS Secrets Manager/Vault).
  • Experience translating HITRUST and SOC 2 into practical technical controls.
  • Strong written communication to influence roadmaps in a remote, async culture.
  • Familiarity with AI tools, prompt engineering, and automation using AI.

Responsibilities

  • Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening.
  • Manage vulnerability lifecycles and prioritize remediation based on production exposure.
  • Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards.
  • Translate HITRUST and SOC 2 frameworks into actionable technical configurations.
  • Evaluate and secure infrastructure-as-code across environments.
  • Execute incident response duties including forensic investigations and blameless post-mortems.
  • Elevate security standards through design reviews, mentoring, and collaboration.
  • Oversee bug bounty triage and engagement with external researchers.

Skills

Kubernetes security
Network policy orchestration
Admission control Kyverno
Container hardening
Node.js/TypeScript/Python/Go
Secure SDLC & CI/CD
Terraform
AWS Secrets Manager/Vault
Vulnerability management
HITRUST & SOC 2 compliance
AI tools & prompt engineering

Tools

Terraform
GitHub Actions
Kubernetes
Docker
ArgoCD

Job description

Redoxengine is hiring a remote candidate for Staff Security Engineer. This is a full time position. Work location: USA, UK, Europe. The role typically involves technologies such as TypeScript, Node.js, Kubernetes, Terraform, CI/CD, Rails. Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.

Opportunity & Impact

We are seeking a Staff Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands‑on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact. You will function as a partner to our Engineering teams, embedding security into the SDLC by default. Whether it is container security, Kubernetes hardening, or architecture design, you will have the autonomy to define our standards and ensure the secure path is always the easy path for every engineer on the team. As a core member of a small, senior team, your technical decisions will scale across our entire network, directly impacting how we protect data for every customer we serve. We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership.

Engineering Culture & How We Work

Transparency, Ownership & Autonomy We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Staff Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes. We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too - when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern. We own the systems we maintain, not just the new features on the roadmap. You'll have latitude to identify and drive platform work - defining scope, consulting on priority, and seeing it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.

Job Responsibilities

Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening. Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics. Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity. Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls. Evaluate and secure infrastructure-as-code across all environments. Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses. Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship. Oversee bug bounty triage and maintain professional engagement with external security researchers.

Required Skills & Experience

8+ years in security engineering with a track record of Staff-level impact through system architecture, leadership of strategic initiatives, and technical mentorship. Deep technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols. Expertise in threat modeling for Applications built using Node.js, TypeScript, Python or Go. Proven track record institutionalizing secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity. Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms. End-to-end accountability for vulnerability management lifecycles, encompassing everything from initial triage to final production remediation. Ability to operationalize compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows. Exceptional written communication skills with the ability to influence technical roadmaps within a remote, asynchronous organizational culture. Proficiency in AI tools and techniques, including prompt engineering and hands‑on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.

Our stack

AWS, Docker, EKS Crowdstrike, Jamf, Okta, GuardDuty, Sumologic Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane Github Actions, Terraform, Helm, ArgoCD and Atlantis Postgres, Redis, Kafka.

Nice to have in your background

Experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions. Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources. Hands‑on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment. Go, Node.js, or TypeScript - we're a TypeScript shop and it helps to be comfortable there VPN administration or enterprise network security experience Dependency management tooling (Renovate, Dependabot).

Compensation

$190,000 - $200,000 a year Compensation: The base salary range for this position is expected to be between $190,000 - $200,000 per year. *The base salary range is subject to change and may be modified in the future. The actual offer may vary depending on multiple factors unique to each candidate, including but not limited to the level of job-related knowledge, skills, qualifications, education/certification, and interview assessment. Please note that the compensation details listed above reflect the base salary only. Redox offers a total rewards package that includes stock options and employee benefits for full-time employees.

Benefits & Perks
  • 100% remote first culture (must be based in the US)
  • Unlimited Flexible Time Off
  • 15+ Observed Holidays
  • Rest & R^Charge days (guaranteed a 3-day weekend each month)
  • R^Charge (6 weeks paid sabbatical + stipend)
  • 401k match 50% for up to 8% on Day 1
  • Medical/Dental/Vision Benefits on Day 1
  • HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program
  • Paid Parental Leave (16 weeks)
  • Productivity Stipend & Wellness Fund
  • Redox Issued MacBook
  • Virtual and/or in-person Team & Company Events
  • Stock Options
  • Employee Referral Bonus Program
About Redox

Take a look here: https://youtu.be/4OjENXR6UXA

Other Stuff About Us

Redox is an EEO company. We fully support the diversity of our team. As part of our ongoing work to build more diverse teams at Redox, you will be asked to complete a voluntary EEO survey when applying. This survey is anonymous, we cannot link your application record with your survey responses. We request that you complete this voluntary survey as we run monthly reports for each team which provides data for diversity in terms of gender and ethnic background in our Applicants and our Hired Redoxers. We take this data very seriously and appreciate your willingness and time to complete this step in the process. Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S.

Skills required for this role include TypeScript, Node.js, Kubernetes, and related tools for day-to-day development.

Senior.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Redox, Inc. • Northern (KY)

Hybrid
USD 190,000 - 200,000
100% remote first culture (US)
Medical/Dental/Vision Benefits on Day
401k match 50% for up to 8%
+1
Sr. Technical Account Executive (TAE)
Sr. Technical Account Executive (TAE)

HealthX Ventures • United States

Remote
USD 115,000 - 130,000
Unlimited Flexible Time Off
15+ Observed Holidays
401k match on Day 1
+4
Senior Digital Marketing Manager at Redox
Senior Digital Marketing Manager at Redox

Feedinkoo • United States

Remote
USD 134,000 - 159,000
Unlimited Flexible Time Off
401k match
Medical/Dental/Vision Benefits
+2
Staff Cloud Security Engineer: Kubernetes & SDLC
Staff Cloud Security Engineer: Kubernetes & SDLC

Redox, Inc. • Northern (KY)

Hybrid
USD 190,000 - 200,000
100% remote first culture (US)
Medical/Dental/Vision Benefits on Day
401k match 50% for up to 8%
+1
Senior Integration Coordinator
Senior Integration Coordinator

Redox • United States

Remote
USD 89,000 - 100,000
Unlimited Flexible Time Off
15+ Observed Holidays
Stock Options
+3
Remote Staff Security Engineer: Kubernetes & Cloud Defense
Remote Staff Security Engineer: Kubernetes & Cloud Defense

Far Coder • Northern (KY)

Hybrid
USD 190,000 - 200,000
100% remote first culture (US-based)
Stock options
Medical/Dental/Vision benefits on Day
+2
IT Security Engineer
IT Security Engineer

Redwood Logistics • Chicago (IL)

Remote
USD 115,000 - 130,000
Paid time off
Medical, dental, vision plans
Employee referral bonus program
Application Security & Red Team - Lead Engineer, Information Security
Application Security & Red Team - Lead Engineer, Information Security

RXO, Inc. • Charlotte (NC)

On-site
USD 90,000 - 150,000
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Cloud Systems Engineer
Cloud Systems Engineer

Far Coder • Northern (KY)

Hybrid
USD 160,000 - 190,000