SECTION I · THE BRIEF
Brief #65920Updated 06 OCT 2026REMOTEBreezySOFTWARE COMPANIES
Employbl Company Profile

Sr. Information Security Engineer

Reveleer empowers managed care organizations nationwide to take control of their Risk Adjustment and Quality Improvement initiatives.

Location
Remote
Company size
100–200
Posted
Yesterday
Via
Breezy
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Sr. Information Security Engineer

Reveleer· United StatesView company profile


Job title
Sr. Information Security Engineer
Job location
United States
Job description

Sr. Information Security Engineer

Hybrid/Remote

About Reveleer

Reveleer delivers a unified platform spanning risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations navigating the complexity of value-based care. Trusted by 80+ customer organizations nationwide, the platform integrates data, analytics, and intelligent workflow automation into one governed system designed to support traceable documentation across diagnoses, quality measures, and submissions. With regulatory expertise and transparent, human-in-the-loop AI at its core, Reveleer supports organizations working to advance care quality, strengthen documentation integrity, and sustain the operational readiness needed to navigate audits with confidence.

Position Summary

  • The Senior Information Security Engineer plays a key role in safeguarding Reveleer's cloud-based healthcare SaaS platforms, AI/ML systems, infrastructure, and customer data. This position designs, implements, and manages enterprise-grade security solutions aligned to HIPAA, HITRUST, SOC 2, NIST 800-53, and NIST AI RMF. Because Reveleer's platform relies heavily on AI and large language models to process clinical data, this role carries direct responsibility for securing AI pipelines, models, and the PHI that flows through them. The ideal candidate is a hands-on technologist with depth in cloud security, AI/LLM security, application security, DevSecOps, identity, and security automation.

Cloud and Infrastructure Security

  • Design and maintain secure architectures across AWS, Azure, and GCP, with emphasis on infrastructure-as-code security (Terraform, CloudFormation) and policy-as-code enforcement (OPA, Sentinel, AWS SCPs).
  • Implement guardrails using AWS Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls.
  • Operate CSPM/CNAPP tooling (e.g., Wiz, Prisma Cloud, Orca) to detect misconfigurations, toxic combinations, and exposed PHI data stores.
  • Secure containerized and serverless workloads across EKS/ECS and Lambda, including image scanning, admission control, runtime protection, and least-privilege task roles.
  • Enforce network segmentation, TLS/encryption standards, and centralized key and secrets management (AWS KMS, Secrets Manager, HashiCorp Vault).

AI and Machine Learning Security

  • Partner with Data Science and AI Engineering to secure model development, training, fine-tuning, inference, and RAG pipelines that handle PHI and PII.
  • Apply the OWASP Top 10 for LLM Applications and MITRE ATLAS to threat model AI features, addressing prompt injection, insecure output handling, training data poisoning, model and data exfiltration, and excessive agency in agentic workflows.
  • Implement AI gateway, guardrail, and content-filtering controls (e.g., Bedrock Guardrails, Azure AI Content Safety, LLM firewalls) along with input/output validation, rate limiting, and prompt and completion logging for audit.
  • Govern third-party and foundation model usage: vendor security review, data residency and retention terms, zero-retention and no-training contractual controls, and BAA coverage for any AI service touching PHI.
  • Establish controls against shadow AI, including discovery of unsanctioned generative AI tools, DLP policies for AI endpoints, and enterprise-approved alternatives.
  • Secure the ML supply chain: model and artifact provenance, signed models, dependency scanning for ML libraries, notebook and MLOps platform hardening (SageMaker, Databricks, MLflow).
  • Contribute to AI governance alongside Compliance and Legal, mapping controls to NIST AI RMF, ISO/IEC 42001, HITRUST AI assurance criteria, and emerging state and federal AI regulation.

Application and SaaS Security

  • Embed security into CI/CD pipelines with SAST, DAST, SCA, secrets scanning, and IaC scanning (Snyk, StackHawk, Semgrep, etc).
  • Perform threat modeling, secure design reviews, and code reviews for microservices, APIs, and AI-enabled features.
  • Secure API and machine-to-machine authorization patterns (OAuth 2.0, OIDC, mTLS, scoped service tokens) across internal and partner integrations.
  • Manage software supply chain risk through SBOM generation, dependency governance, and artifact signing.
  • Drive penetration testing, bug bounty intake, and remediation validation; track findings to closure with Engineering.
  • Ensure PHI and PII protection across SaaS platforms through data classification, tokenization, de-identification, and DLP.

Endpoint and Identity Security

  • Manage and tune EDR/XDR platforms (Palo Alto Cortex XDR, Microsoft Defender for Endpoint), including detection engineering and response automation.
  • Implement identity security through Microsoft Entra ID, Conditional Access, PIM, and risk-based authentication; advance phishing-resistant MFA and password less adoption.
  • Govern non-human identities, service principals, workload identities, and AI agent credentials with least privilege and short-lived tokens.
  • Support Intune and MDM compliance baselines for Windows, macOS, iOS, and Android; apply CIS Benchmarks and configuration drift monitoring.
  • Operate SaaS security posture management (SSPM) for third-party app integrations and OAuth grant risk.

Security Operations and Incident Response

  • Monitor and triage alerts, investigate incidents, and coordinate response with the SOC and MDR partners.
  • Build and maintain detection content in the SIEM, including detection-as-code, log pipeline coverage, and MITRE ATT&CK mapping.
  • Develop incident response runbooks, playbooks, and forensic procedures, including scenarios specific to AI systems such as model misuse, data leakage through prompts, and compromised AI integrations.
  • Automate response and enrichment through SOAR workflows, Python, and PowerShell.
  • Participate in tabletop exercises, purple team activity, and post-incident reviews.

Governance, Risk, and Compliance

  • Support audits and evidence collection for HIPAA, HITRUST, SOC 2 Type 2, NIST 800-53, and customer security assessments; leverage compliance automation platforms.
  • Maintain asset and AI system inventories, risk registers, and remediation tracking with clear SLAs.
  • Conduct vendor and third-party risk reviews, with added scrutiny for AI subprocessors and data flows.
  • Partner with Compliance to keep technical controls, policies, and standards in alignment.
  • Contribute to security awareness and training, including secure and responsible AI use guidance for employees and engineers.

Qualifications

Required:

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
  • 5+ years of experience in security engineering or related technical security roles.
  • Strong knowledge of cloud-native security (AWS, Azure, GCP) and modern SaaS architectures.
  • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
  • Familiarity with HIPAA, HITRUST, NIST, and SOC 2 requirements.
  • Experience securing containerized and serverless workloads (e.g., EKS, Lambda).

Preferred:

  • Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or GIAC (GSEC, GCIA, GCIH).
  • Experience with Terraform, Ansible, or CloudFormation for infrastructure-as-code security.
  • Experience in DevSecOps pipelines and tools (e.g., Jenkins, Bitbucket).
  • Strong scripting skills (Python, PowerShell, or Bash).

Key Competencies

  • Analytical and detail-oriented with strong problem-solving skills.
  • Ability to balance business needs with risk mitigation.
  • Excellent communication skills, able to translate complex technical topics for non-technical stakeholders.
  • Collaborative team player with a proactive approach to continuous improvement.

WHAT YOU’LL RECEIVE:

• Competitive salary 

• Medical, Dental and Vision benefits 

• 401k match

• Generous PTO plan 

 Our compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.

Reveleer E-Verifies all new hires.

Reveleer is an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, disability status or genetic information, in compliance with applicable federal, state and local law.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Reveleer headquarters

Glendale, CA

Company size

100–200 employees

Founded

2009

Total raised

$208,799,984

View company profile ↗

Funding rounds