Application Engineer
Listed on 2026-06-12
-
IT/Tech
Cybersecurity
Parachute Health is transforming post-acute care through the leading digital ordering platform for medical equipment and supplies. We replace the outdated, error‑prone paper and fax process, which negatively impacts over 30 million patients annually, with a system that’s 10 times faster. Our platform connects a vast network of Home Medical Equipment (HME) providers, clinicians, and payors across all 50 states, ensuring millions of patients get the life‑saving products they need quickly and efficiently.
Join our team and make a difference in patient care.
About the RoleYou’ll be the software engineer embedded in Parachute Health’s IT & Security team, building the internal platforms, automations, and AI‑powered workflows that keep our healthcare technology environment secure, compliant, and operationally efficient.
You’ll write code that touches on identity, endpoint, network, cloud security, compliance, evidence collection, and incident response in an environment governed by HITRUST, SOC 1, and SOC 2.
ResponsibilitiesInternal tooling & automation
- Design, develop, and maintain internal applications and automations that eliminate manual IT/Security work, including provisioning, access reviews, compliance evidence collection, audit preparation, and ticket triage.
- Develop and maintain integrations across the security and IT stack, including Okta, Zscaler, Splunk/Wazuh, Lacework, Drata, Datadog, AWS, GCP, Git Hub, and n8n.
- Package, deploy, and operate IT/Security tooling using Parachute’s standard deployment patterns and observability stack.
AI & agentic workflows
- Architect agentic AI workflows for IT and Security operations, including automated alert triage, log correlation, root‑cause analysis, guided remediation, access‑review automation, and audit evidence collection.
- Build the context layer (MCP servers, retrieval pipelines, and embeddings) that grounds AI agents in Parachute‑specific systems, policies, and runbooks.
- Drive AI adoption across the IT/Security team through pairing, architecture reviews, and reusable skills/plugins/workflows.
- Build an MCP‑based agent that automates audit evidence collection from multiple sources
- Replace manual access‑review workflows with an agentic pipeline
Security
- Develop, tune, and maintain SOAR/SIEM detections, dashboards, and correlation rules in Splunk/Wazuh.
- Support threat hunting, incident investigation, pen test, and/or red teaming, and forensic analysis with custom tooling and queries (Redshift, Big Query, log platforms)
- Apply MITRE ATT&CK, NIST CSF, and HITRUST CSF to guide detection engineering and control implementation.
- Contribute to SOC runbooks, SOPs, and automation playbooks (SOAR).
Security audits & reliability
- Automate compliance evidence collection and control validation across SOC 2, HITRUST CSF, HITRUST AI, and HIPAA.
- Participate in an on‑call rotation for IT/Security incidents; contribute to post‑incident reviews and continuous improvement.
- Maintain stable, performant, and auditable internal application stacks.
- 2+ years of writing production code in a web‑based environment.
- Hands‑on experience with AWS (IAM, EC2, ECS/EKS, S3, RDS, Lambda) and infrastructure‑as‑code.
- Demonstrated experience integrating with REST/Graph
QL APIs and building automations across SaaS platforms. - Working knowledge of at least one compliance framework - SOC 2, HITRUST, HIPAA, ISO 27001, or NIST.
- Security‑first mindset: you think about least privilege, secrets handling, PHI exposure, and audit trails by default.
- Strong fundamentals in data structures, design patterns, and TDD.
- Must reside in the U.S.
- Experience building agentic AI systems in production - agent architectures, tool integration via MCP, retrieval‑augmented generation, evaluation frameworks.
- Experience setting up AI development environments and driving AI adoption across a technical team.
- Familiarity with our stack:
Okta, ZScaler, Splunk/Wazuh, Lacework, Drata, Datadog, n8n workflows and/or Argo workflows. - SIEM detection engineering or SOC tooling experience (Splunk SPL, Wazuh rules, Sigma).
- Healthcare technology background - exposure to HIPAA, PHI handling, or DME workflows.
- Security or cloud certifications…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).