Senior Security Engineer
$170k - $190kOshi Health
Job Description
Job Description
Senior Security Engineer
Are you a security engineer who wants to build a program from the foundation up — not inherit and babysit someone else's?
Do you thrive in a fast-paced, AI-native environment where security's job is to enable speed safely, not slow it down out of fear?
Are you energized by the idea that the systems you protect hold the most sensitive health data of real people trying to get their lives back from chronic GI conditions?
If so, you might be a perfect fit for our team of professionals dedicated to eliminating the impact of digestive health conditions through innovative GI care.
The RoleAs Oshi Health's first dedicated Senior Security Engineer, you will own the technical security of a fully remote, SaaS- and cloud-native healthcare platform — and you'll do it as a hands-on builder, not a policy desk. Reporting to the Sr. Director, Security & IT, you will set the security architecture standards for our product and AWS environments, harden how we manage identity and secrets, and build security into our engineering and AI workflows from the start.
This is a uniquely forward-looking role. Oshi is transitioning to an agentic software development lifecycle in which AI agents help plan, build, review, and eventually deploy code against a data platform that touches regulated data. You will design the guardrails that make that transition safe: the security gates in the pipeline, the controls on agent-written code, and the lifecycle management for the non-human identities those agents use. You'll partner closely with Product & Engineering to keep the path paved — moving fast with confidence rather than slow out of fear — and with the Sr. Director on HIPAA, SOC 2, and audit readiness. If you want a security role where the work is genuinely novel and your fingerprints are on the foundation, this is it.
What you'll do- Own application and product security: threat modeling, secure design review, and secure code review, with a focus on the authorization and access-control flaw classes (IDOR, broken access control, exposed secrets, insecure upload) that matter most for a member-facing healthcare app and its APIs.
- Make our existing tooling do real work: enforce and tune GitHub Advanced Security (CodeQL, secret scanning, push protection) as required status checks, with branch protection and CODEOWNERS-enforced human review on security-sensitive paths.
- Design and own the security architecture for our agentic SDLC — phase-gate criteria for each stage of the AI transition, deterministic out-of-band controls so that agent-written code is never its own security gate of record, and tested "clawback" procedures for when risk spikes.
- Build and run non-human identity (NHI) and secrets management at scale: service accounts, scoped tokens, OAuth grants, and machine credentials — provisioning, rotation, least privilege, and decommissioning across our SaaS and AWS estate.
- Secure our AWS environment: IAM/IC, network segmentation, logging, configuration baselines, encryption, and workload protection across S3, EKS and Terraform (and supporting services in coordination with our DevOps team)
- Run security review of AI and third-party vendor integrations before they touch PHI — evaluating data flows, retention, and data-loss-prevention needs, and applying healthy skepticism to AI-native vendors' security claims.
- Stand up and tune detection and response Leverage AI and build behavioral baselines and anomaly detection for identity, SaaS, AWS, and AI/agent usage logs.
- Support HIPAA Security Rule technical safeguards in partnership with the Sr. Director — encryption at rest, audit controls and activity logging, vulnerability scanning, and asset inventory.
- Own the vulnerability management and penetration-testing cadence: Own the relationship with an external pen tester, drive findings to closure, shrink time-to-remediation, and move recurring issues left into the development process.
- Reduce attack surface through SaaS and identity rationalization, and write the security policies, standards, and runbooks the program needs as it matures.
- Build automation (scripting, infrastructure-as-code) so that a small security function operates with outsized leverage.
- 6+ years in security engineering, with demonstrated depth in application/product security and cloud security (AWS). Experience in healthcare, fintech, or another regulated, data-sensitive environment is a strong plus.
- Hands-on with secure SDLC tooling: SAST/DAST, GitHub Advanced Security / CodeQL, secret scanning, and software supply-chain / dependency security.
- Strong in identity and access management: Okta, OAuth/OIDC, SAML, phishing-resistant MFA, and the management of non-human identities and secrets (e.g., AWS Secrets Manager, or equivalents).
- Familiarity with — or genuine drive to go deep on — securing AI/LLM and agentic systems: prompt injection, agent authorization and over-permissioning, NHI sprawl, and model/supply-chain risk. You don't need to have done it for a decade; almost no one has. You do need to be the kind of engineer who runs toward a problem the industry hasn't solved yet.
- Comfortable being the sole security specialist on a small, cross-functional team — you prioritize ruthlessly by risk, you're pragmatic about cost, and you can explain a tradeoff to both an engineer and a non-technical executive without changing the truth of it.
- Working knowledge of the HIPAA Security Rule, SOC 2, and the NIST Cybersecurity Framework. Experience operating a compliance-automation platform is a plus.
- Proficient with scripting and automation (Python and at least one shell) to scale yourself.
- A curious, builder's mindset — you'd rather pave a safe path than post a "do not enter" sign, and you find the right technology to increase both security and velocity.
- Bachelor's degree in Computer Science or equivalent practical experience.
Certifications (nice to have, not required): one or more of OSCP, GIAC (e.g., GWAPT, GCSA, GCLD), AWS Certified Security – Specialty, CISSP, or Okta Certified Professional.
We make healthcare more equitable and accessible:
- Mission-driven organization focused on innovative digestive care.
- Thrive on diversity with monthly DEIB discussions and activities.
- Virtual-first culture: Work from home anywhere in the U.S.
- Live our core values: Own the outcome, Do the right thing, Be direct & open, Learn & improve, Team, Thrive on diversity.
We take care of our people:
- Competitive compensation and meaningful equity.
- Employer-sponsored medical, dental, and vision plans.
- Access to a "Life Concierge" through Overalls, because we know life happens.
- Tailored professional development opportunities to help you grow.
We rest, recharge, and re-energize:
- Flexible paid time off — take what you need, when you need it.
- 13 paid company holidays to power down.
- Team events, such as virtual cooking classes, games, and more.
- Recognition of professional and personal accomplishments.
Oshi Health's Core Values:
- Own the Outcome
- Do the Right Thing
- Be Direct & Open
- Learn & Improve
- TEAM - Together Everyone Achieves More
- Thrive on Diversity
If you're ready to lead Oshi Health's security and IT operations and help revolutionize healthcare technology, we'd love to hear from you!
Oshi Health is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
Compensation Range
$170,000—$190,000 USD
Note: This job description serves as a general overview and may be subject to change based on organizational needs and requirements.
Oshi Health is an equal opportunity employer that is committed to creating a diverse work environment. To do that, we champion a workplace where each and every person is treated with dignity and respect and is valued for their unique perspective and contributions.
Oshi Health's policy is to maintain a working environment that encourages mutual respect, promotes harmonious and congenial relationships between employees, and is free from all forms of discrimination and harassment of any employee (or applicant for employment or service provider) by anyone, including supervisors, co-workers, vendors, or clients. Harassment and discrimination in any manner or form is expressly prohibited. There is no tolerance for discrimination or unequal treatment of any kind on the basis of race, color, religion, creed, gender, sex, sexual orientation, gender identity or expression, pregnancy, sexual and reproductive health decisions, national origin, age, disability, genetic information, marital status or civil partnership/union status, familial status, military or veteran status, predisposition or carrier status, domestic violence victim status, alienage or citizenship status, unemployment status, sexual violence or stalking victim status, caregiver status, or any other characteristic protected by law.This practice applies to all terms, conditions and privileges of employment including, but not limited to, recruitment, selection, promotion, demotion, transfer, layoff, rehire, termination of employment, development and training, compensation, benefits and retirement.
For more information, visit us at
Oshi Health will never contact job candidates via text message or any other messaging platform including WhatsApp, Signal, and Telegram. All official correspondence will occur through email. We will never ask you to share bank account information, cash a check from us, or purchase software or equipment as part of your interview or hiring process. If you have concerns, please reach out to View email address on ziprecruiter.com, and we'll confirm whether you're engaging with one of our Oshi teammates!
$128.9k - $180k
...passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.WHAT YOU'LL DOAs a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and...SeniorWork at officeLocal area$130k - $145k
...BasePosted: 2026-08-20Company: Addison GroupCONFIDENTIAL SEARCH - Senior Network Security EngineerLocation: Chicago - OnsitePay: $130 - $145K Base... ...401(k)Confidential search for a Senior Network Security Engineer for a highly respected Chicago organization undergoing a...Senior$130k - $150k
How you'll make an impact: As the Senior Security Engineer, you will work as a team member on the Security team you will be ensuring Strata has the correct security measures in place and provide continuous improvement opportunities to extend our capabilities and security...SeniorWork experience placement$160k - $205k
...work with some of the best information security professionals in the world in challenging... ...Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of... ...and experience by mentoring junior engineers, and assist with monitoring and response...SeniorFull timeWork at officeRemote workShift workDay shift$200k - $225k
...re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative on JLL's Falcon team, owning the product's security...SeniorFull timeLocal areaImmediate startRemote work$92k - $120k
...Click here to access. Time Type:Full timeRemote Type:Job Family Group:Information TechnologyJob Description Summary: The Senior IT Security Engineer is responsible for planning, deploying, administering, and maintaining security platforms and technologies to protect the...SeniorFull timeWork at officeWork from homeFlexible hours2 days per week$149k - $235k
...spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security...SeniorWork at officeLocal area$112k - $209k
...and your search for important and impactful work lead to the same place.The global law firm of K&L Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior Security Engineer develops, automates, and enhances security capabilities for cloud, on-premises...SeniorFull timeTemporary workWork experience placementLocal areaRemote work$134k - $205k
...grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.We’re looking for a Senior Corporate Security Engineer to help secure the systems, identities, devices, and collaboration platforms that power how Gong employees work every...SeniorRemote workWork from homeFlexible hours$140k - $160k
...Leading Financial Service Client is looking to hire a strong Security Engineer who can lead Red team exercises against a hybrid environment... ...Windows and Linux system hardening concepts and techniques. Seniority level Mid-Senior level Employment type Full-time Job...SeniorFull time$80k - $92k
...Senior Network Security EngineerNPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento... ...are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The...SeniorLocal areaRemote work$174.8k - $236.5k
...Senior Security Engineer Chicago, US Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a...SeniorWorldwide$50 - $70 per hour
...Senior Network Security EngineerWe are seeking a Senior Network Security Engineer with deep expertise in Cisco Identity Services Engine (ISE) and identity-driven network segmentation to support and enhance a modern enterprise security architecture. This role will focus...SeniorHourly payLive inRemote work- ...resume submitted outside of an active job posting will not be considered for employment.What You'll Do:Join our dynamic Security Engineering team as a Senior Associate and make a significant impact on our organization's cybersecurity posture. In this role, you'll manage...SeniorFull timeRemote work2 days per week
- A leading technology firm is seeking a Remote Sr. Microsoft Security Consultant for a contract position lasting 6-8 months. This role requires strong technical expertise in integrating Microsoft Security tools, deep knowledge of Microsoft security technologies like Entra...SeniorRemote jobContract work
- ...workflow automation with Moveworks’ Reasoning Engine and natural language capabilities, we... ...RoleDo you care deeply about secure access at scale? Making sure the right people... ...security is an enabler, not a blocker. As a Senior Identity & Access Management Engineer, you...SeniorWork at officeRemote workFlexible hours
- Chicago, Illinois100% RemoteFull Time$140k - $160kA consulting company is looking to bring on a hands on a Senior Application Security Engineer to work with clients on new development. You'll perform code reviews, conduct SAST/DAST/SCA scans, identify vulnerabilities in...SeniorFull time
$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative...SeniorWork experience placementLocal areaVisa sponsorship$131k - $169k
...culture that is recognized with Great Place To Work® certification and on Fortune magazine's Best Small Workplaces™ List. Senior Security Engineer Our Engineering Standards at Karbon: Balance Speed and Quality Engineers are expected to balance delivery speed...SeniorWork at officeWork from homeFlexible hoursDay shift- SAGE Integration is looking for a Senior Systems Engineer in Chicago to develop solutions and support our sales & operations teams. The ideal candidate will have over 10 years in security technologies, excellent problem-solving skills, and knowledge of AutoCAD and IP surveillance...Senior
- ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web...SeniorFull time
- Bank of America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense AI Security Senior Engineer to drive the integration of advanced AI technologies into our cyber defense ecosystem. This senior individual‑contributor role focuses on technical innovation...SeniorShift workDay shift
$116.1k - $158.2k
...subscription design, governance, and onboarding standardsEstablish engineering standards for identity, networking, monitoring, resiliency,... ...with architecture, infrastructure, networking, and security teams to deliver scalable cloud solutionsEnable and integrate...SeniorFull timeContract workLocal areaFlexible hours- Bank of America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense AI Security Senior Engineer to drive the integration of advanced AI technologies into our cyber defense ecosystem. This senior role focuses on technical innovation and SME leadership...Senior
$112.5k - $150k
Senior Security Operations & Incident Response Engineer Salary: $112,500-$150,000 The Engineer - Security Operations and Incident Response will be a critical function responsible for the transformation of the organization's Security Operations and Incident Response program...Senior$114.5k - $194.7k
...partners, we serve the world’s most sophisticated clients using leading technology and exceptional service. Title: Senior Associate, Cloud Security Engineer Role descriptionThe Senior Associate Cloud Security Engineer plays a crucial role in ensuring the security,...SeniorFull timeH1bWorldwideFlexible hours- Northern Trust Corp. seeks a Senior Lead Cyber Security Engineer to design, implement, and manage enterprise data protection controls across cloud and on‑prem environments. You will drive SecuPi DAM, Purview DLP, labeling, monitoring, and encryption, while advancing data...Senior
$70 - $90 per hour
DescriptionWe are seeking a skilled and motivated Container Security Engineer to strengthen our cybersecurity posture across containerized environments. This role focuses on the identification, analysis, and mitigation of vulnerabilities and misconfigurations in container...SeniorContract workTemporary workWork experience placement- Ahold Delhaize USA is seeking a Sr. Network Security Engineer to lead architecture, deployment, and operations of enterprise security across data centers, cloud environments, retail locations, and offices. You will drive zero-trust initiatives, manage firewalls and cloud...SeniorRemote work
- Ahold Delhaize USA is seeking a Sr. Network Security Engineer to lead the engineering, delivery, and operations of our network security platforms with a focus on zero trust and next-generation firewalls across data centers, cloud, and retail locations. You will drive the...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer. Be the first to apply!
- security engineering manager Chicago, IL
- application security engineer Chicago, IL
- sr information security engineer Chicago, IL
- sr security engineer Chicago, IL
- entry level security engineer Chicago, IL
- senior application security engineer Chicago, IL
- principal security engineer Chicago, IL
- physical security engineer Chicago, IL
- lead security engineer Chicago, IL
- security engineer Chicago, IL


