Hipp
Senior Security Engineer
Remote, United States · Remote · Posted today
Opens jobs.ashbyhq.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- Remote
- Source
- Ashby (employer's hiring system)
Skills mentioned
Cloud Security, SOC 2, Threat Modeling, Incident Response, SaaS, AWS, Azure, GCP
About the role
About Hipp
Hipp is an AI-native healthcare platform built to modernize operations for non-hospital healthcare providers. We partner closely with ambulatory healthcare organizations to streamline clinical workflows, billing, scheduling, patient engagement, and revenue cycle operations.
Our platform handles sensitive healthcare and operational data across a growing set of intelligent products. Security, privacy, reliability, and customer trust are fundamental to what we build—not separate functions applied after the fact.
Role Overview
We’re looking for a Senior Security Engineer to lead and strengthen security across Hipp’s product, cloud infrastructure, software-development lifecycle, and internal operations.
You will be a hands-on technical leader responsible for identifying risk, designing pragmatic controls, improving detection and response, and helping engineering teams ship secure systems quickly. You will work closely with engineering, IT, product, compliance, and company leadership to evolve Hipp’s security posture as the platform and customer base grow.
This role is ideal for someone who can move fluently between application security, cloud security, incident response, compliance readiness, and security architecture. You should be comfortable setting direction while also implementing controls, reviewing systems, investigating alerts, and helping teams resolve concrete security problems.
What You’ll Do
• Own and evolve Hipp’s product and infrastructure security program
• Partner with engineering teams to embed security into system design, implementation, deployment, and operations
• Conduct architecture reviews, threat modeling, code reviews, and targeted security assessments
• Strengthen cloud security across identity and access management, network controls, secrets, encryption, logging, and workload configuration
• Build and improve vulnerability-management processes across applications, dependencies, containers, infrastructure, and endpoints
• Develop security monitoring, alerting, investigation, and incident-response capabilities
• Lead incident-response preparation, including playbooks, tabletop exercises, evidence collection, and post-incident improvement
• Improve authentication, authorization, tenant isolation, privileged-access, and least-privilege controls
• Partner with engineering to secure AI-agent tools, model integrations, retrieval systems, and access to sensitive data
• Assess AI-specific threats such as prompt injection, excessive agency, insecure tool use, sensitive-data disclosure, and untrusted retrieved content
• Support HIPAA and SOC 2 compliance through technically sound, sustainable controls and evidence
• Help respond to customer security reviews, questionnaires, and technical diligence
• Evaluate vendors and integrations for security and privacy risk
• Establish security standards, documentation, and engineering guidance that teams can apply without unnecessary friction
• Track security posture and risk through meaningful metrics
• Mentor engineers and build a strong security culture across the company
What We’re Looking For
• Significant experience securing production SaaS, cloud, or data-intensive applications
• Strong knowledge of application security, cloud security, identity, network security, encryption, secrets management, and secure software development
• Experience with at least one major cloud platform such as AWS, GCP, or Azure
• Experience identifying and remediating common web, API, authentication, and authorization vulnerabilities
• Hands-on experience with threat modeling, vulnerability management, security testing, monitoring, or incident response
• Ability to review architecture and code, reason about realistic attack paths, and recommend practical mitigations
• Experience working with engineering teams to implement security controls without unnecessarily slowing product development
• Strong understanding of logging, detection, investigation, and response
• Sound judgment when prioritizing security risks in a fast-moving environment
• Clear written and verbal communication with both technical and non-technical audiences
• High ownership and comfort building systems and processes from an early stage
Nice to Have
• Experience securing healthcare technology or systems handling protected health information
• Familiarity with HIPAA, SOC 2, HITRUST, NIST, or similar frameworks
• Experience with infrastructure as code, container security, CI/CD security, and software-supply-chain controls
• Experience with penetration testing, bug bounty programs, or adversarial security reviews
• Familiarity with modern AI and agent security risks
• Experience securing multi-tenant SaaS architectures
• Experience with endpoint security, device management, SSO, and internal corporate security
• Relevant security certifications are welcome but not required
• Experience as an early security hire at a startup
Why Join Hipp
• Own security at a company where trust directly affects healthcare providers and patients
• Shape security architecture and practices while the platform and team are still growing
• Work closely with engineers, founders, product leaders, and customers
• Address emerging security challenges created by AI-native healthcare workflows
• Build durable systems rather than perform compliance theater
• Have direct influence over Hipp’s product, infrastructure, and security culture
Job ID ab-hipp-886a4429-e863-436e-8071-d7ea07e382e8 · Original posting ↗
Similar jobs
Cybersecurity EngineerNewABACUSRemote, United States · Remote
Cloud Security EngineerNewPatch My PCRemote, United States · Remote · US$110,000–145,000 / year
Sr Product Security EngineerNewBeyondTrustToronto, Ontario · Remote
Security EngineerNewBastionRemote, United States · Remote · US$180,000–250,000 / year
Security EngineerNewPatreonRemote, United States · Remote · US$170,000–255,500 / year