×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer

Remote / Online - Candidates ideally in
Waco, McLennan County, Texas, 76796, USA
Listing for: AxisCare
Full Time, Remote/Work from Home position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below

Senior Security Engineer

Reports To:

Director of Engineering

Summary

Axis Care is hiring a full-time, fully remote Senior Security Engineer to own security and compliance across our SaaS platform, the market-leading product powering the home care industry.

This is not a job where you'll write policies that nobody reads. You'll work directly with product engineering teams, embedded in how we build software, shaping our security posture. You'll own engineering's side of our SOC 2 Type II compliance program, lead us toward HITRUST certification, and keep our AWS infrastructure, Docker pipelines, and PHP/React codebase hardened as we move fast.

We're also building AI-powered products on top of Amazon Bedrock and our own machine learning models, and we use AI heavily in how we develop software. That creates new kinds of risk that most security playbooks don't cover yet. We need someone who's thinking about this already and building the guardrails that agents need to write secure software.

Home care agencies trust us to run their business every day. Their data includes protected health information. We need someone who takes that personally.

What You'll Do

Own Axis Care Engineering's security program as an individual contributor. Continually improve our security standards as threats evolve, strengthen the systems that enforce them, and work directly with engineers to close gaps.

Own engineering's share of SOC 2 Type II compliance: control design, evidence collection, audit prep, and gap remediation. Chart the path toward HITRUST certification, mapping what we already have and building what we don't.

Threat-model our application and infrastructure. We run a PHP/React modular monolith on AWS, managed with Terraform, deployed in Docker containers, backed by MySQL in RDS. Raise the bar on this stack's security (IAM policies, VPC design, secrets management, container security, database access controls) and keep raising it as the architecture evolves.

Own and improve our security scanning program. Tune findings, cut false positives, and make sure scan results turn into developer action.

Assess and mitigate the security risks inherent in our AI products: prompt injection, data leakage, model output filtering, abuse scenarios. Set guardrails for AI-assisted development workflows so the team ships faster without opening new attack surface.

Strengthen our detection and response capabilities: logging, alerting, incident response playbooks. Coordinate penetration tests, track findings, and drive remediation.

Keep our security policies clear, current, and short. Train developers on secure practices without burying them in process.

What We're Looking For

A builder, not just an auditor. You've built or run a security program inside a product company, not just assessed one from the outside. You can point to systems, controls, and habits you put in place that made a real difference.

A technical peer to engineers. You read code, read Terraform, and talk to developers in their language. When you flag a vulnerability, you can explain the fix, not just the finding.

A pragmatist. You understand that we need to ship. You weigh tradeoffs, probability, and impact, not by saying no to everything.

A strong writer. Remote work demands it, and clear writing is clear thinking. You'll write policies, incident reports, audit narratives, and messages to engineers explaining why something matters. Clarity counts.

An AI-aware security thinker. You're already wrestling with what AI means for security: new attack surfaces, new tooling, and new ways that development workflows create risk.

Experience required:
  • 5+ years in application security, infrastructure security, or security engineering at a SaaS company
  • Hands-on experience with AWS security…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary