ComPsych Corporation

Senior Cloud Security Engineer

ComPsych Corporation$150K — $200K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field; security certifications like CISSP are a plus.
  • 6 to 9 years of hands-on security engineering experience, particularly with cloud security.
  • Experience using AI tools for security engineering, including analysis and automation.
  • Senior-level knowledge across multiple security areas: network, application, cloud, and AI security.
  • Proficient in building controls as code, including policy and infrastructure as code, with real production experience.
  • Depth in AWS and Azure security practices, especially surrounding IAM, encryption, and container security.
  • Expertise in data protection and privacy for health data, familiar with data residency regulations.

Responsibilities

  • Secure the cloud with a focus on posture management, identity management, and least privilege access.
  • Integrate application security into CI/CD pipelines to ensure safe product delivery.
  • Design network security architecture incorporating zero trust principles and automated solutions.
  • Lead data protection initiatives, including classification, encryption, and handling PHI and ePHI.
  • Implement AI security measures, including controls for data protection and misuse concerns.
  • Oversee detection, response, and vulnerability management across systems and initiate timely remediation actions.
  • Promote and maintain security baselines and compliance standards, fostering a culture of security among engineers.

Benefits

  • Full benefits package including Paid Time Off (PTO).
  • Medical, dental, and vision coverage.
  • 401(k) with company match.
  • Robust Employee Assistance Program (EAP).
  • Wellness program and additional perks.
Full Job Description
About the Role

This is a fully remote role.  ComPsych is modernizing how it secures the business as it migrates to the cloud and builds AI into its products, and the Senior Cloud Security Engineer is accountable for raising the bar across every security domain, network, application, cloud, data, and AI. The role covers the full security lifecycle, from designing controls, policy as code, and guardrails to directing AI assisted build and validation work, through owning detection, response, and vulnerability management, while keeping human judgment on what ships and how the team responds. Because ComPsych’s platform carries behavioral health data for millions of members, this engineer helps ensure that security and privacy scale with the business rather than slowing it down.  Candidates with different levels of experience and strong equivalent experience are encouraged to apply.

 

What You'll Do
  • Secure the cloud, by design and in code. Own cloud security posture management across configuration, workloads, and entitlements (CSPM, CWPP, and CIEM); identity and access management and least privilege, including federation and single sign on, secrets management, privileged access, and workload and non human identities; network segmentation; container security; encryption and key management; and guardrails delivered as policy as code across our cloud environments (AWS primary, Azure), so the secure path is the default for every team.
  • Build application security into the pipeline. Shift security left in CI/CD with static, dynamic, and dependency and software supply chain scanning, threat modeling, secrets management, and secure by design reviews, so product teams ship safely by default.
  • Engineer network security for a cloud first estate. Design segmentation and zero trust access, firewalls and web application firewalls, and traffic inspection across cloud and hybrid networks, automated and observable rather than manually maintained.
  • Protect the data and engineer privacy in. Lead data classification, encryption and tokenization, key management, and data loss prevention, with privacy by design for PHI and ePHI and awareness of data residency and cross border handling across our domestic and international footprint.
  • Secure the AI systems we build. Design guardrails, data protection, and abuse and misuse controls for AI, machine learning, and generative AI, addressing risks like prompt injection, model and data poisoning, and sensitive data leakage, and build the monitoring to catch them.
  • Own detection, response, and vulnerability management. Tune SIEM and cloud native detections, drive event correlation and incident response, run vulnerability scanning and coordinate penetration testing, and turn findings into fixes with real remediation timelines.
  • Advance information security and make secure the easy default. Maintain security baselines and configuration compliance, and the controls, logging, and audit evidence that keep us compliant, coaching engineers across teams rather than gatekeeping.
  • Perform other duties as assigned
What We're Looking For
  • Education: Bachelor’s degree in Computer Science or a related field; security certifications such as CISSP or a cloud security specialty are a plus.
  • 6 to 9 years of security engineering experience with hands on cloud experience, as a guideline rather than a hard requirement.
  • Agentic AI tools are your primary surface for security engineering, analysis, detection, and automation, and you apply hard judgment to what they produce, not an occasional assist.
  • Senior level breadth across network security, application security, cloud security, information security, and the emerging discipline of AI security, with real depth in several of them.
  • You build controls as code, including policy as code, infrastructure as code, automation, and detections, and you have operated them in production, including carrying on call and incident load.
  • Cloud security depth in AWS (primary) and Azure: identity and access management and least privilege, identity federation and single sign on, secrets management, privileged access, and workload and non human identities; network security; container security including image scanning and runtime protection; key management and encryption; and cloud security posture management across configuration, workloads, and entitlements (CSPM, CWPP, and CIEM).
  • Data protection and privacy engineering: data classification, encryption, tokenization, and key management, data loss prevention, and privacy by design for regulated health data, with data residency awareness across domestic and international operations.
  • Application and product security depth: secure software development lifecycle, threat modeling, static, dynamic, and software composition analysis, secrets and software supply chain security, and API security.
  • Detection, response, and vulnerability management depth: SIEM and cloud native detection, log and event correlation, vulnerability scanning and management, and coordinating penetration testing and remediation to closure.
  • AI security awareness and a point of view: securing AI and generative AI systems against risks like prompt injection, data and model poisoning, and data leakage, with familiarity with references like the OWASP Top 10 for LLM Applications and MITRE ATLAS a plus.
  • You build to the frameworks we operate under, domestic and international: HIPAA, HITRUST, SOC 2, NIST, ISO 27001, ISO 42001, and GDPR.
  • Self-starter with ability to multi-task and work autonomously
  • Excellent organizational and project management skills

Effective interpersonal and communication skills

Compensation and Benefits
  • Full benefits package, including Paid Time Off (PTO), medical, dental, vision, 401(k) with match, robust EAP, wellness program, and much more
  • The salary range for this position is $150,000 - $200,000 (USD). The base salary range represents the anticipated low end and high end of the range for this position. The actual compensation will be influenced by a wide range of factors including, but not limited to previous experience, education, pay market/geography, and scheduled hours. 

 

About ComPsych Corporation

ComPsych Corporation is a provider of employee assistance programs (EAP), corporate wellness, and crisis management services. The company was founded in 1984 by Dr. Richard A. Chaifetz. ComPsych provides services to more than 33,000 organizations covering more than 89 million individuals throughout the United States and over 160 countries. The company has been recognized as one of the largest privately held companies in Chicago and one of the largest EAP providers in the world.
Learn more about ComPsych Corporation
Size
500 employees
Industry
Founded
1984

Similar Jobs

More Jobs at ComPsych Corporation

More Information Technology Jobs

Find similar Senior Cloud Security Engineer jobs: