×
Register Here to Apply for Jobs or Post Jobs. X

Senior Cloud Security Engineer

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: Healthmark Group
Full Time position
Listed on 2026-09-30
Job specializations:
  • IT/Tech
    AWS, Cybersecurity, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 150000 - 210000 USD Yearly USD 150000.00 210000.00 YEAR
Job Description & How to Apply Below

Senior Cloud Security Engineer

Healthmark Group Remote, Other / Non-US, United States

About this position

COMPANY OVERVIEW:Health Mark Group is a leading provider of health IT solutions for healthcare providers across the country. By leveraging technology to reimagine the business of healthcare, Health Mark transforms administrative processes into seamless digital solutions. From Health Mark’ s proprietary Med Release platform for Release of Information, the company is pioneering an efficient, compliant, and patient‑centric approach to support the entire spectrum of the patient information journey.

Health Mark Group was founded in 2006 with corporate headquarters in Dallas, TX, and has been named to both the Dallas 100 and the Inc. 5000 for multiple years in a row as one of the fastest‑growing companies in the region and the country.

We are a mid‑sized company in a transformation phase: modernizing legacy systems, building new products, and automating workflows that used to require rooms full of people. If you want to build things that matter (not just maintain them), this is a good time to join.

Position:
Senior Cloud Security Engineer

Location:
Remote

Role Overview:

The senior cloud security engineer is responsible for designing, implementing, and maintaining security controls for Health Mark Group developed applications and corporate systems, with a focus on the AWS cloud environment, including the platforms supporting our medical imaging business. They define AWS security guardrails appropriate for a highly‑regulated environment containing Protected Health Information (PHI) and which must adhere to security regulations and frameworks such as HIPAA, HITRUST, and SOC 2.

They serve as a leader in the Security Operations team, providing mentorship and guidance to fellow security engineers.

Primary

Roles and Responsibilities:

  • Design and build enterprise‑grade security controls utilizing native AWS services to safeguard PHI across all cloud environments.
  • Design and maintain the secure multi‑account AWS architecture — account structure, organizational units, guardrails, and baseline configuration — so that new accounts and workloads inherit required PHI protections by default.
  • Author, review, and maintain secure‑by‑default Terraform or AWS Cloud Formation templates, integrating policy‑as‑code tools (e.g., OPA, Checkov, Rego) to programmatically enforce HIPAA, HITRUST, and SOC 2 controls before deployment.
  • Align and enforce strict data‑at‑rest and data‑in‑transit encryption strategies utilizing AWS KMS, ensuring cryptographic standards satisfy HITRUST and HIPAA mandates for PHI.
  • Design and enforce strict least‑privilege access models, complex IAM policies, Service Control Policies (SCPs), and AWS Organizations boundaries to strictly control access to sensitive healthcare workloads.
  • Embed security testing, container scanning, and secrets management (AWS Secrets Manager) directly into CI/CD pipelines, creating automated evidence‑collection workflows for continuous SOC 2 and HITRUST audit readiness.
  • Collaborate with application development and cloud operations teams to triage, investigate, and remediate vulnerabilities and findings from application and cloud security tooling, such as SAST, DAST, and CSPM.
  • Develop custom detection rules using AWS Cloud Trail, Amazon Cloud Watch telemetry, and enterprise SIEM tool to monitor system activities to detect and respond to threats and incidents.
  • Serve as the senior escalation point for cloud security incidents, leading investigation and containment in AWS environment in partnership with our Managed Detection and Response provider, Cloud Operations team, and Managed Services Provider. Drive post‑incident root cause analysis and control improvements.
  • Support…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary