Location: Hybrid 3 days (offices in NYC, Denver, CO and Charlotte, NC area)
Position SummaryReporting to the Director of Security Engineering, this Security Engineer role is a hands-on role responsible for securing Judi Health's cloud environments and the applications that run in them. This role sits at the intersection of cloud security and application security: hardening cloud infrastructure and infrastructure as code, building automation that enforces and evidences security controls, and partnering with software engineering teams to identify and remediate application-layer risk.
Judi Health operates a FedRAMP Moderate platform in addition to SOC 1, SOC 2, HITRUST, and HIPAA obligations. The engineer in this role will work inside that authorization boundary every day - maintaining continuous monitoring, contributing to continuous control validation and automated compliance evidence, and supporting change management and external assessments. This is a strong fit for an engineer who wants to build durable security capability in a regulated, cloud-native environment rather than operate tools in isolation.
Position Responsibilities:- Design, implement, and improve security controls across our cloud infrastructure, platform services, and supporting integrations, including identity and access management, network segmentation, logging, encryption, and key and secrets management.
- Harden infrastructure as code and cloud deployment pipelines, reviewing Terraform and CI/CD changes for security impact and building preventative guardrails rather than after-the-fact findings.
- Operate and tune cloud security tooling - CSPM/CNAPP, SIEM, vulnerability management, and endpoint and data protection platforms - and drive consolidation toward a unified, well-instrumented approach.
- Triage, prioritize, and drive remediation of cloud misconfigurations, vulnerabilities, and posture findings, working directly with platform, infrastructure, and engineering owners through to closure.
- Contribute to detection engineering and incident response, including alert development and tuning, investigation, threat hunting, containment support, and documentation of findings and root cause.
- Review application and service designs for authentication, authorization, input validation, data exposure, and secrets-handling risk, and participate in architecture and design reviews for new Judi capabilities.
- Assess code changes for security impact with enough fluency in Python and modern JavaScript frameworks to recognize unsafe patterns and propose practical fixes.
- Embed security into the software development lifecycle through dependency scanning, secrets detection, container image scanning, and enforcement of pipeline security gates.
- Contribute to secure coding guidance, developer-facing documentation, and practical enablement that helps engineering teams ship securely by default.
- Execute continuous monitoring activities including recurring infrastructure, database, web application, and container scanning, and maintain accurate, timely remediation tracking and POA&M entries.
- Build automation for security monitoring, evidence collection, control validation, and policy enforcement to support continuous compliance at scale.
- Author security impact analyses for changes affecting the authorization boundary, including affected components, impacted controls, risk, mitigations, and validation approach, and support the change control process.
- Translate FedRAMP, SOC 1, SOC 2, and HITRUST control requirements into practical, auditable technical implementations in partnership with the IT Audit and Compliance team.
Required Qualifications:- Three or more years of hands-on experience in security engineering, cloud security, application security, or a closely related discipline.
- Demonstrated experience securing production AWS environments, including identity and access management, network controls, logging and monitoring, encryption, and cloud-native security services.
- Working proficiency in at least one modern programming or scripting language, with a track record of automating security tasks rather than performing them manually.
- Practical experience with infrastructure as code, including reading and writing Terraform and assessing infrastructure changes for security impact.
- Experience with application security concepts and tooling, including the OWASP Top 10, API security risks, and SAST, DAST, or software composition analysis platforms.
- Experience with security operations disciplines such as SIEM, vulnerability management, detection and alerting, and incident investigation.
- Solid understanding of authentication and authorization patterns, least privilege, and secrets management, including OAuth2/OIDC and enterprise SSO.
- Ability to work independently, prioritize effectively, and drive remediation across teams without formal authority.
- Strong written communication skills, with the ability to produce documentation and evidence that withstands audit and assessor scrutiny.
(Optional) Preferred Qualifications:- Experience supporting a regulated or audited environment such as FedRAMP, FISMA, StateRAMP, or CMMC, including control implementation and evidence management.
- Familiarity with NIST SP 800-53 Rev 5 control families and FedRAMP continuous monitoring expectations.
- Experience with policy-as-code or automated compliance validation in cloud environments.
- Knowledge of container and orchestration security, including Kubernetes, ECS, or EKS.
- Experience in healthcare, health tech, or another highly regulated industry handling sensitive data.
- Industry certifications such as AWS Security Specialty, CCSP, CISSP, or similar.
- Familiarity with AI and ML security concepts, including model access, data protection, and secure adoption practices.
New York, NY Salary Range
$122,000-$152,500 USD
Denver, CO Salary Range
$111,600-$139,500 USD
Charlotte, NC Salary Range
$101,600-$127,000 USD
All employees are responsible for adherence to the Judi Health Code of Conduct including the reporting of non-compliance. This position description is designed to be flexible, allowing management the opportunity to assign or reassign duties and responsibilities as needed to best meet organizational goals.