waypointjobs

Med-Metrix

Senior Cloud Security Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Job Purpose The Senior Cloud Security Engineer will design, implement, and maintain security controls across our multi-cloud environment, with a particular emphasis on securing AI/ML workloads and leveraging AI-driven security tooling. The Senior Cloud Security Engineer will serve as a technical leader, partnering with engineering, application development, and DevOps teams to embed security into every stage of the cloud and AI development lifecycle.

Duties & Responsibilities

Design and implement secure cloud architecture across AWS and Azure, including identity, network security, encryption, and key management

Implement cloud-native logging, monitoring, and threat detection to improve visibility and incident response

Build Infrastructure-as-Code (Terraform, CloudFormation, Bicep), Policy-as-Code, and automated compliance controls

Implement and enhance Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), and CNAPP capabilities

Conduct threat modeling, security architecture reviews, and risk assessments for cloud services and applications

Design and secure AI/ML environments, including MLOps pipelines, model security, inference endpoints, and AI governance

Assess and mitigate AI-specific threats, including prompt injection, model poisoning, adversarial attacks, and data leakage

Partner with engineering and data science teams to implement secure-by-design and privacy-preserving controls for regulated data

Develop automated detections, SOAR playbooks, and AI-driven threat hunting capabilities

Lead technical response to cloud and AI security incidents, including forensic analysis and remediation

Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements

Support technical readiness, evidence collection, and remediation activities for security audits and compliance assessments

Develop and maintain cloud security standards, technical guidance, and AI governance documentation

Support enterprise risk management and vendor security assessments

Integrate security throughout the DevSecOps lifecycle, including application, container, and secrets management

Develop security metrics, communicate technical risks to stakeholders, and recommend continuous security improvements

Mentor junior engineers and champion security best practices across engineering teams

Other duties as assigned

Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards

Understand and comply with Information Security and HIPAA policies and procedures at all times

Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties

Qualifications

High school diploma or equivalent required

6+ years of experience in information security, with at least 4 years focused on cloud security engineering

Deep hands-on expertise in both AWS and Microsoft Azure, including native security services (e.g., AWS GuardDuty, Security Hub, IAM Identity Center; Microsoft Defender for Cloud, Sentinel, Entra ID)

Strong knowledge of IAM, zero trust architecture, network security, encryption, and secrets management in cloud environments

Practical experience securing AI/ML systems or LLM-based applications, or demonstrable working knowledge of AI security frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF)

Proficiency in at least one scripting/programming language (Python preferred) and infrastructure-as-code tooling

Experience with container and orchestration security (Docker, Kubernetes, EKS/AKS)

Solid understanding of DevSecOps practices and CI/CD security integration

Hands-on experience supporting compliance programs such as HIPAA, HITRUST CSF, PCI DSS, and SOC 2 in cloud environments, including audit evidence and control implementation

Proficiency in Microsoft Office Suite

Strong interpersonal skills, ability to communicate well at all levels of the organization

Strong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses

High level of integrity and dependability with a strong sense of urgency and results oriented

Excellent written and verbal communication skills required

Preferred Qualifications

Experience with Google Cloud Platform (GCP) in addition to AWS and Azure

Experience deploying or securing MLOps platforms (SageMaker, Vertex AI, Azure ML, Databricks, Kubeflow)

Familiarity with AI-driven security platforms and building custom detections using ML techniques

Relevant certifications such as CISSP, CCSP, HCISPP, CCSFP (HITRUST), AWS Security Specialty, Azure Security Engineer (AZ-500), GCP Professional Cloud Security Engineer, or GIAC certifications

Prior experience in healthcare, health tech, or revenue cycle management environments handling PHI at scale

Experience with red teaming or adversarial testing of AI systems

Knowledge of data privacy regulations as they apply to AI training data and model outputs, particularly de-identification standards under HIPAA (Safe Harbor and Expert Determination)

Contributions to security communities, open-source tooling, or published research

Working Conditions

Travel may be required for training, conferences, etc.

Must possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes

Physical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear

Mental Demands: The employee must be able to follow directions, collaborate with others, and handle stress

Work Environment: The noise level in the work environment is usually minimal

Med-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job