Skip to main content
Oshi Health

Senior Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Startup
$170k–$190k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

As Oshi Health’s first dedicated Senior Security Engineer, you will own the technical security of a fully remote, SaaS- and cloud-native healthcare platform — and you’ll do it as a hands-on builder, not a policy desk. Reporting to the Sr.

Core skills

AWSidentity and access managementAI/LLM security

Required skills

IAM/ICS3EKSTerraformCodeQLsecret scanningpush protectionOktaOAuth/OIDCSAMLAWS Secrets ManagerPythonshell scriptingHIPAA Security RuleSOC 2NIST Cybersecurity Framework

Optional skills

OSCPGIAC (e.g., GWAPT, GCSA, GCLD)AWS Certified Security – SpecialtyCISSPOkta Certified Professionalcompliance-automation platform

Required languages

English

What you'll do

  • Own application and product security: threat modeling, secure design review, and secure code review.
  • Enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks.
  • Design and own the security architecture for our agentic SDLC.
  • Build and run non-human identity (NHI) and secrets management at scale.
  • Secure our AWS environment: IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS and Terraform.

What they require

  • 6+ years in security engineering, with demonstrated depth in application/product security and cloud security (AWS).
  • Hands-on with secure SDLC tooling: SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply-chain / dependency security.
  • Strong in identity and access management: Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and the management of non-human identities and secrets (e.g., AWS Secrets Manager, or equivalents).
  • Familiarity with — or genuine drive to go deep on — securing AI/LLM and agentic systems: prompt injection, agent authorization and over-permissioning, NHI sprawl, and model/supply-chain risk.
  • Working knowledge of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework.

Benefits

  • Competitive compensation and meaningful equity.
  • Employer-sponsored medical, dental, and vision plans.
  • Access to a “Life Concierge” through Overalls, because we know life happens.
  • Tailored professional development opportunities to help you grow.
  • Flexible paid time off — take what you need, when you need it.

Healthcare company providing digestive health care

HealthcareStartup
$170k–$190k/yr