SmarterDx
Staff Security Engineer
Remote (United States) · Staff+
Sponsorship not specified$230k-$250kDetected 14 hours ago
TypeScriptPythonGoCode ReviewGitPostgreSQLAWSKubernetesTerraformHelmMachine LearningLLMsCybersecuritySIEMDetection EngineeringIncident ResponseComplianceHIPAAEHR/EMRPatient CareResearchCommunicationMentoring
About the role
- SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered.
Responsibilities
- Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product.
- Publish the org's AI-security standard and drive its adoption by other engineering teams.
- Own incident-response readiness: the plan, the playbooks, and tested tabletops tied to the HIPAA breach-notification timeline, and help lead response when a real incident happens.
- Lead complex security work across teams from start to finish, resolving ambiguity and coordinating with Platform, Engineering, and Compliance.
- Build and grow security automation that gives a small team more reach, and contribute to the tooling the team runs on.
- Take part in architecture reviews and threat modeling on our highest-risk designs, and communicate the resulting security architecture so the whole team can understand it and build on it.
Requirements
- 8+ years in security and software engineering, with deep hands-on experience in AWS and cloud-native infrastructure, including working competence with containerized workloads (EKS) and infrastructure-as-code (Terraform).
- A track record of leading complex security work across teams and making other engineers more effective.
- Experience mentoring and leveling up other engineers.
- Depth in threat detection engineering: designing, authoring, and tuning detections in a modern SIEM, and reasoning about coverage against real threats.
- Incident-response experience, including building the plan and running the response.
- The ability to write production code (Python, Go, or TypeScript) and build security tooling, not only configure products.
- Strong writing and communication
- you can publish a standard other teams adopt and explain a hard design to a non-security audience.
- Working knowledge of SOC 2 and HIPAA, and the judgment to design controls that hold up without stalling delivery.
- Nice To Haves
- Recognized AI-security work: published standards or research, contributions to AI-security tooling, or red-teaming of AI/LLM systems.
- Startup experience, especially in health tech or another regulated, data-sensitive environment.
- Deeper specialization in container security (Kubernetes/EKS, Helm) or in infrastructure-as-code and policy-as-code, beyond working competence.
Nice to have
- This role is our senior technical anchor for the two areas where we most need depth as the team grows: AI security and threat detection and response.
- securing LLM applications, agentic frameworks, and MCP, plus prompt-injection and agentic-access defenses.
- Depth in AI and agentic security: securing LLM applications, agentic frameworks, and MCP, plus prompt-injection and agentic-access defenses.
Skills
- AWS, Kubernetes (EKS), Terraform, Postgres
Compensation
- $230k to 250k base salary
Benefits
- Medical, Dental & Vision - Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
- Paid Parental Leave -
- Unlimited PTO & 10 Holidays - So you can relax and recharge.
- 401(k) with Traditional & Roth Options - Tax-advantaged retirement savings through Fidelity with a 4% match.
- As a Smartian, you'll help build technology that makes healthcare more accurate, sustainable, and effective for everyone.
- Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources, and the standards that keep detections high-signal as we grow.
Apply directly at SmarterDx →Create a free account for alerts like thisView SmarterDx immigration profile
This listing is sourced directly from SmarterDx's careers page and normalized into a canonical job model.