Staff Security Engineer
$190k - $200kRedox
Staff Security Engineer
Redox is on a mission to accelerate healthcare's transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.
We are seeking a Staff Security Engineer to take ownership of cloud-native and application security across the Redox platform. This is a high-impact, hands-on IC role where you will move beyond identifying risks to actively hardening our environment, performing code reviews, and translating complex control gaps into engineering proposals that drive production impact.
You will function as a partner to our Engineering teams, embedding security into the SDLC by default. Whether it is container security, Kubernetes hardening, or architecture design, you will have the autonomy to define our standards and ensure the secure path is always the easy path for every engineer on the team.
As a core member of a small, senior team, your technical decisions will scale across our entire network, directly impacting how we protect data for every customer we serve.
We're a fully remote team within the U.S. that operates with radical transparency and a strong bias toward ownership.
Transparency, Ownership & Autonomy: We make room for everyone to be heard, regardless of level. We work openly, normalize not knowing things, and treat "learning out loud" as a feature, not a liability. You'll be expected to bring your real perspective, push back when you see something wrong, and commit fully once a decision is made. As a Staff Engineer, you help cultivate our culture: you model the behavior, you embrace questions, you acknowledge mistakes. We default to public Slack channels over DMs, post Zoom summaries back in writing, and work async whenever possible. We'd rather expose incomplete thinking in public to get better feedback than protect it in private. That applies to security work too - when you identify a risk or propose a control, you bring it to the table with a recommendation, not just a concern. We own the systems we maintain, not just the new features on the roadmap. You'll have latitude to identify and drive platform work - defining scope, consulting on priority, and seeing it through from design to operationalization. We measure ourselves by the value we deliver, not the process we follow.
Job Responsibilities:
- Own Cloud Security Posture Management including Kubernetes and Container security strategies, admission control, network policies, image integrity, and environment hardening.
- Manage comprehensive vulnerability lifecycles, prioritizing remediation based on actual production exposure rather than simplistic finding metrics.
- Collaborate with Platform Engineering to institutionalize secure SDLC and CI/CD safeguards, focusing on artifact validity and pipeline integrity.
- Convert HITRUST and SOC 2 compliance frameworks into actionable technical configurations and operational controls.
- Evaluate and secure infrastructure-as-code across all environments.
- Execute incident response duties, encompassing forensic investigation and the facilitation of blameless post-mortem analyses.
- Elevate security standards within Engineering through rigorous design reviews, collaborative pairing, and technical mentorship.
- Oversee bug bounty triage and maintain professional engagement with external security researchers.
Required Skills & Experience:
- 8+ years in security engineering with a track record of Staff-level impact through system architecture, leadership of strategic initiatives, and technical mentorship.
- Deep technical proficiency in Kubernetes security, specifically network policy orchestration, admission control (Kyverno), and container hardening protocols.
- Expertise in threat modeling for Applications built using Node.js, TypeScript, Python or Go.
- Proven track record institutionalizing secure SDLC practices and CI/CD safeguards using GitHub Actions, ensuring artifact validity and pipeline integrity.
- Direct experience hardening Infrastructure-as-Code (Terraform) and managing enterprise secrets via AWS Secrets Manager, Vault, or similar platforms.
- End-to-end accountability for vulnerability management lifecycles, encompassing everything from initial triage to final production remediation.
- Ability to operationalize compliance frameworks like HITRUST and SOC 2 into pragmatic technical controls that align with engineering workflows.
- Exceptional written communication skills with the ability to influence technical roadmaps within a remote, asynchronous organizational culture.
- Proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to automate workflows using AI.
Our Stack - You'll Be Hands-On With These:
- AWS, Docker, EKS
- Crowdstrike, Jamf, Okta, GuardDuty, Sumologic
- Kyverno, Karpenter, KEDA, VPA, Velero, Crossplane
- Github Actions, Terraform, Helm, ArgoCD and Atlantis
- Postgres, Redis, Kafka
Nice To Have In Your Background:
- Experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
- Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
- Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.
- Go, Node.js, or TypeScript - we're a TypeScript shop and it helps to be comfortable there
- VPN administration or enterprise network security experience
- Dependency management tooling (Renovate, Dependabot)
Compensation: The base salary range for this position is expected to be between $190,000 - $200,000 per year. The actual offer may vary depending on multiple factors unique to each candidate, including but not limited to the level of job-related knowledge, skills, qualifications, education/certification, and interview assessment. Please note that the compensation details listed above reflect the base salary only. Redox offers a total rewards package that includes stock options and employee benefits for full-time employees. Our total rewards package includes the following:
- 100% remote first culture (must be based in the US)
- Unlimited Flexible Time Off
- 15+ Observed Holidays
- Rest & R^Charge days (guaranteed a 3-day weekend each month)
- R^Charge (6 weeks paid sabbatical + stipend)
- 401k match 50% for up to 8% on Day 1
- Medical/Dental/Vision Benefits on Day 1
- HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program
- Paid Parental Leave (16 weeks)
- Productivity Stipend & Wellness Fund
- Redox Issued MacBook
- Virtual and/or in-person Team & Company Events
- Stock Options
- Employee Referral Bonus Program
- ...and colleagues. Those stories are part of what makes this such a special place to work.Job OverviewMacy’s is seeking a Staff Information Security Engineer to join its Cloud Security team. This position plays a pivotal role in designing, implementing, and operating secure...SuggestedWork experience placementFlexible hoursShift work
$232k - $290k
...see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and...SuggestedFull timeWork at officeLocal area$210k - $260k
...journey toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for aStaff Security Engineer, Application Security to help scale and mature our security program. You'll own key security domains and initiatives end-to-end...SuggestedWork at officeRemote workWorldwideMonday to FridayFlexible hours$210k - $234.1k
...few technology companies ever operate at.Security at Compass International HoldingsThe... ...estates in the industry. We are hands-on engineers who build security as a service: secure-... ...Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to...SuggestedMinimum wageWork experience placementFlexible hours- ...impossible at record breaking speeds.About You and The Role Product security at Zipline protects systems that directly affect safety,... ...infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a...SuggestedLocal area
$145k - $155k
...for Applicants:At Bixal, we want to ensure a transparent and secure application process for all candidates. Official communication... ...FedRAMP-authorized systems continuously compliant while enabling engineering velocity.This role offers you a unique opportunity to make a...Temporary workLocal areaRemote workFlexible hoursWeekend work$245.92k - $286.9k
Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create...Full timeWork experience placementWork at officeFlexible hours- ...every step of the way. Join us to invest in yourself, your career, and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection and anomaly detection program. You will own the detection...Remote work
$169k - $199k
...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission... ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications...Work at officeShift work3 days per week- Job Description:The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-level...Work at officeLocal area
- Austin, TXTechnology - Security /RemoteThe Staff Security Engineer will be responsible for designing, implementing, and maintaining security identity services that support our business. You will understand data and automation are important ingredients to our mission and...Temporary workRemote workFlexible hours
$165k - $200k
Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is a family technology company on a mission to help families... ...out of bed every morning.Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This individual will be responsible...Full timeWork at officeLocal areaRemote workWork from homeDay shift$232k - $310k
...see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security practitioners, operating at the intersection of application...Full timeWork at officeLocal area- ...from. Our success will be built on amazing colleagues, working together.Job OverviewThe Staff, Vulnerability Engineer is a specialist in Penetration Testing and Information Security Vulnerability Management. This hands-on role involves conducting penetration tests and vulnerability...Work at office
- ...over activity. We don’t just ship features; we solve hard problems to help creatives do their best work.As our first Principal Security Engineer, you will own the security posture for the entire organization—from the cloud to the colo, and from the training cluster to...Full timeWork at officeRelocation
$175k - $270k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...how we operate, not treated as a blocker.Your roleAs a Staff Corporate Security Engineer, you will be a critical part...Temporary workLocal areaWorldwide- ...reduce data exposure risks, improve data governance, and enable secure collaboration both inside and outside the company.... ...environments.Strong technical foundation in Computer Science, Computer Engineering, or equivalent experience, with deep knowledge of networking,...Full timeLocal areaImmediate start
- P-1528As a Staff Security Assurance Engineer within the Security Assurance Team, you will help lead high-visibility security compliance implementation initiatives. Reporting directly to the Senior Director, you will serve as a strategic catalyst for these programs, ensuring...WorldwideRelocation
$210k - $255k
...with us at Crusoe.About This RoleCrusoe is building the world’s favorite AI-first cloud infrastructure. We are seeking a Staff Corporate Security Engineer to act as the principal architect for our corporate security posture.In this role, you will move beyond tactical tool...Temporary work$134k - $184.8k
Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of... ...and Intelligence (TDI) organization is the engine that powers Okta's global workforce,... ...our employees to do their best work.The Staff Security Engineer OpportunityWe are seeking...Local areaWorldwideFlexible hoursShift work$156k - $255k
...information every day and we take their security seriously. Our core value of putting our... ...services. Our mission is to leverage security engineering, advanced risk analytics, and automation... ...standards. About the RoleAs a Staff Security Engineer focused on Third-Party...For contractorsWork experience placementWork at officeFlexible hours$198k - $273k
...CAInformation Technology and Applications - Enterprise Security /Full-time /HybridZoox's Network Security team... ...of the company — from corporate offices to engineering labs and product/mission environments. As a Senior or Staff Network Security Engineer, you will design,...Full timeTemporary workRemote workRelocation package$168.56k - $231.77k
We’re looking for a Staff Security Engineer to join Procore’s Security Engineering team as a foundational technical leader. In this role, you won’t just be implementing security controls—you will be designing the next generation of autonomous defense. Your mission is to...Full timeContract workWork at officeLocal areaShift work$169k - $199k
...Expectations are high, and so are the rewards. About the TeamThe Security Operations (SecOps) team at Robinhood proactively... ...standard across the cybersecurity industry!About the RoleAs a Staff Security Engineer (IC6) on the Detection & Response team, you will drive our...Work at officeFlexible hoursShift work3 days per week$207k - $280k
...never stop working to find new, innovative ways to make that possible.Job OverviewWhat we expect10+ years of experience in Security Engineering building, operating and architecting a combination home grown and vendor solutions. Strong understanding of Computer Engineering...Worldwide$212k - $265k
...ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Staff Security Engineer within the Secure Digital Asset Operations (SDAO) function, you will collaborate with leadership and cross-functional...Full timeWork at officeLocal area- This is a hybrid role (3 days in office / 2 days remote).About your team:We seek a motivated Incident Responder to join our Security Operations team. You will assist in monitoring, detecting, analyzing, and responding to security events and incidents. This role is ideal...Work at officeRemote work
$212k - $265k
...our promise to customers sending money globally, providing secure, simple, and reliable ways to manage their money, ensuring... ...program backbone connecting the pillars.We're looking for a Staff Security Engineer to join Detection & Response as a senior individual contributor...Full timeWork at officeWorldwideFlexible hours3 days per week$170k - $278k
Lehi, UtahResearch and Development - Security /Full-Time /HybridSince 2003, Entrata has evolved from a visionary, student-led startup... ...Minimum Qualifications10+ years of experience in corporate security engineering or information security roles.Direct hands-on experience with...Full timeLocal areaRemote workWorldwideFlexible hours$188k - $275k
...7, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave’s Vulnerability Management program. You will design and implement scalable...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer. Be the first to apply!
- project engineer assistant project manager United States
- senior staff systems engineer United States
- information technology administrative assistant United States
- staff data engineer United States
- staff devops engineer United States
- staff process engineer United States
- assistant chief engineer United States
- assistant engineer United States
- information technology support assistant United States
- assistant electrical engineer United States
