As part of our RVO Health Security team, you will play a major part in strategic initiatives that improve our security posture and protect our sensitive data. You will work in a collaborative Agile environment, working closely with the business, IT, and engineering teams. You will apply your skills in a highly dynamic, innovative, cloud-native environment with a strong security-minded culture.
Where You'll BeLocation: Charlotte Metro Area (Fort Mill, SC) | HybridWe believe great collaboration happens when we're together, solving problems, learning from each other, and connecting as a team. That's why we're in our offices Tuesday through Thursday each week. You are welcome to work remotely Mondays and Fridays if you wish.
Office address: 1101 Red Ventures Dr Fort Mill, SC 29707
What You'll Do- Design, implement, and maintain security controls and architectures to protect the company's cloud infrastructure, applications, and data from cyber threats.
- Improve our cloud security posture and vulnerability management program - pull-request scanning, triage and tracking of findings to closure across engineering teams, and coverage and license optimization.
- Build and enforce software supply chain controls across the developer toolchain - package, dependency, and extension guardrails, with enforcement thresholds tuned to reduce noise rather than generate it.
- Extend security into CI/CD pipelines, including the emerging problem of governing AI-authored code at the pipeline chokepoint.
- Build automation, internal tooling, and integrations against our developer platform and security stack so that security controls are self-service rather than ticket-driven.
- Partner with Platform & Software Engineering teams to create visibility and awareness of security issues and work to prioritize their resolution in a collaborative way.
- Perform security assessments, including code reviews and application security testing, to identify and mitigate risk in new and changing systems.
- Participate in a weekly on-call rotation for managed detection and response escalations; investigate potential threats, respond to security incidents, and perform root cause analysis.
- Develop and maintain security standard operating procedures and policies in accordance with industry best practices and regulatory requirements (e.g., HIPAA, NIST CSF).
- Stay informed of the latest developments in tactics, techniques, and procedures related to application and infrastructure vulnerabilities - especially in the healthcare space - and adapt the strategy or tooling to address new threats.
What We're Looking ForRequired:
- Bachelor's degree in Computer Science, related field OR equivalent experience
- Minimum 4+ years of experience in application security, cloud security, or a related cybersecurity role.
- Solid understanding of cloud security principles, architectures, and services (AWS or Azure preferred).
- Hands-on experience with cloud security posture management or CNAPP tooling (e.g., Wiz, Orca, Prisma Cloud), and a track record of driving vulnerability findings to closure with engineering teams.
- Experience building security automation, tooling, and integrations, with working proficiency in at least one scripting or programming language.
- Working knowledge of secure coding practices.
- Knowledge of security frameworks, standards, and regulations (e.g., NIST CSF, HIPAA, MITRE ATT&CK).
- Strong problem-solving and analytical skills, with the ability to think critically and make sound decisions.
- Experience in incident response and recovery.
Preferred:
- Professional certifications (e.g., CISSP, CCSP, OSCP, GIAC).
- Expertise in AWS security controls, monitoring, and orchestration (SCPs, GuardDuty, Config, Macie, etc.)
- Working familiarity with Terraform, GitHub, and DevSecOps workflows - particularly securing GitHub Actions and other CI/CD pipelines.
- Experience securing AI- or LLM-assisted development workflows, or reviewing AI-generated code at scale.
- Experience with internal developer platforms or portals (e.g., Backstage).
- Experience working alongside an MDR or managed SOC provider.
Pursuant to various state Fair Pay Acts, below is a summary of compensation elements for this role at the company. The following benefits are provided by RVO Health, subject to eligibility requirements.- Starting Salary: $100,000 - $130,000*
*Note actual salary is based on geographic location, qualifications and experience - Health Insurance Coverage (medical, dental, and vision)
- Life Insurance
- Short and Long-Term Disability Insurance
- Flexible Spending Accounts
- Paid Time Off
- Holiday Pay
- 401(k) with match
- Employee Assistance Program
- Paid Parental Bonding Benefit Program
- Pharmacy Benefits
- Income Protection Plans
- Pet Services Plans
- Mental Health Support
- Wellness Coaching
- HSA- Health Savings Account
- Commuter Benefits
- Gym & Fitness Center Discount Program