Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
AnswersNow

Staff Cloud Security Engineer

AnswersNow

. Architect, secure, and continuously harden the AWS environment, including IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, Config, and WAF .

Posted 10/8/2026full-timeRemote • United StatesLead💰 $151,000 - $178,500 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in AWS security, including IAM, VPC, and KMS, while ensuring compliance with SOC 2 and HIPAA regulations. Proficient in implementing Infrastructure-as-Code security and managing AI/ML security frameworks.

Highest-signal resume keywords
AWS Security ExpertiseSOC 2 ComplianceHIPAA ComplianceInfrastructure-as-Code SecurityIncident Response Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
AWS IAMAWS VPCAWS KMSPostgreSQL SecurityAPI SecurityInfrastructure-as-Code (Pulumi, CloudFormation, CDK)AI SecurityOWASP LLM Top 10Vulnerability ManagementPenetration Testing
Soft Skills
Excellent CommunicationMentoringCollaboration
Tools & Technologies
VantaDrataSecureframeWebRTCSIEM
Certifications & Qualifications
AWS Security SpecialtyCISSPCCSPOSCP
Industry Keywords
SOC 2 Type ISOC 2 Type IIHIPAA Security RulePHIPIIHITRUSTISO 27001NIST

Tech Stack

Tools & technologies
AWSCloudPostgresSDLC

About the role

Key responsibilities & impact
  • Architect, secure, and continuously harden the AWS environment, including IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, Config, and WAF
  • Secure serverless and data layers including Lambda, S3, and PostgreSQL/RDS/Aurora through encryption, least-privilege access, network isolation, backup integrity, and audit logging
  • Implement Infrastructure-as-Code security guardrails and policy-as-code
  • Own secrets management, key management, and certificate lifecycle
  • Manage and harden Amazon EKS infrastructure, including cluster security, network policies, and container runtime security
  • Secure APIs and application stack, including authentication/authorization, session management, rate limiting, input validation, and OWASP Top 10/API Top 10 risks
  • Embed security into the SDLC through threat modeling, secure design reviews, SAST/DAST, dependency and container scanning, and CI/CD pipeline security
  • Secure the proprietary real-time video platform, including WebRTC/media transport, session access controls, recording storage, and encryption
  • Run vulnerability management and penetration testing, including vendor selection, scoping, and remediation tracking
  • Establish company-wide AI usage policies and governance frameworks
  • Architect and secure in-product AI/ML capabilities against OWASP LLM Top 10 vulnerabilities
  • Implement privacy guardrails for PHI/PII in model training, fine-tuning, and prompt contexts
  • Define model security controls and secure artifacts, endpoints, dependencies, and access controls
  • Build monitoring, telemetry, and audit logging across AI/ML workflows
  • Own SOC 2 Type I and Type II readiness, control design, evidence collection, auditor management, and ongoing compliance
  • Own HIPAA Security Rule compliance, including risk assessments, policies, BAAs, breach notification procedures, and audit readiness
  • Tune Vanta integrations, automate evidence collection, and drive remediation
  • Maintain security policies, risk register, and vendor risk management program
  • Support customer and payer security questionnaires and due diligence
  • Manage endpoint security with outsourced IT, including MDM, disk encryption, EDR, patching, hardening baselines, and device compliance
  • Own identity and access management, including SSO, MFA, RBAC, joiner/mover/leaver processes, and periodic access reviews
  • Run security awareness and HIPAA training programs with People Ops
  • Build logging, monitoring, alerting, and SIEM capabilities
  • Develop and test the incident response plan, run tabletop exercises, and lead incident response
  • Partner with engineering on disaster recovery, backup, and business continuity planning
  • Define the security roadmap and communicate risk to the CTO and executive team
  • Mentor engineers and build a security-conscious culture, including a security champions model
  • Build the business case for tools, vendors, and future security headcount

Requirements

What you’ll need
  • 8+ years in security engineering, with significant hands-on experience securing production cloud environments, ideally AWS-heavy
  • Deep AWS security expertise (IAM, networking, encryption/KMS, logging and detection services, serverless security)
  • Experience securing PostgreSQL and other data stores containing regulated or sensitive data
  • Strong application and API security background, with ability to review code and architecture and work effectively with developers
  • Direct experience owning or leading a SOC 2 audit (Type I and/or Type II) and HIPAA compliance, ideally in healthcare or health-tech handling PHI
  • Experience with Infrastructure-as-Code (Pulumi, CloudFormation, or CDK) and CI/CD security
  • Experience with AI security, LLM application security, and OWASP LLM Top 10 vulnerabilities
  • Strong incident response experience
  • Excellent communication with engineers, executives, auditors, and customers
  • Experience with compliance automation platforms such as Vanta, Drata, or Secureframe (nice to have)
  • Experience securing real-time communication or video platforms (WebRTC) (nice to have)
  • Familiarity with HITRUST, ISO 27001, or NIST frameworks (nice to have)
  • Experience at a startup or scale-up where you built a security program from scratch (nice to have)
  • Relevant certifications such as AWS Security Specialty, CISSP, CCSP, OSCP, or similar (nice to have)
  • Experience with pediatric or behavioral health data and privacy considerations for minors' information (nice to have)
  • Legally authorized to work in the United States

Benefits

Comp & perks
  • Equity options in a high-growth, venture-backed company
  • Comprehensive medical, dental, and vision
  • Generous PTO
  • Remote-first flexibility