> Markdown version of [/jobs/ext/2722452-security-architect](https://www.wearedevelopers.com/jobs/ext/2722452-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - **Company:** Enzo Health, Inc. - **Location:** Lehi, UT, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Artificial Intelligence, Amazon Web Services, Cloud Computing, Cyber Security, Computer Programming, Databases, Continuous Integration, Python (Programming Language), Node.Js, Red Team (Cyber Security), TypeScript, Large Language Models, Software Security, Build Management, AI Platforms - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-architect-enzo-health-8307604 ## About the Role * 7+ years in security engineering, application security, or security architecture, with a strong track record of shipping code * Deep experience in at least one of: vulnerability research, red team / offensive security, or secure systems design * Comfort building systems, not just auditing them-you've shipped tooling, not just findings * Strong programming skills in Python, TypeScript/Node, Go, or Rust * Experience securing cloud infrastructure (AWS preferred) and modern stacks: containers, IaC, managed databases, CI/CD * Familiarity with HIPAA, SOC 2, HITRUST, or other regulated compliance environments * Adversarial mindset-you reflexively threat-model your own designs and the systems around you * Experience or strong interest in AI/ML security: prompt injection, model integrity, LLM-powered offense and defense * Bias toward action and a strong sense of end-to-end ownership * Able to work full-time, on-site in Lehi, UT (relocation considered for the right candidate) ## Description * Enzo Scribe: Auto-generates OASIS documentation, clinical narratives, and care plans, reducing documentation time by up to 75%. * Enzo QA: Ensures documentation meets the highest clinical standards with approximately 95% coding accuracy, reducing compliance risk while increasing reimbursement by an average of $185 per episode. Our Impact Trusted by top-performing home health agencies nationwide, Enzo delivers measurable results: documentation time under 25 minutes per visit, referral intake under 5 minutes, and 30-50% savings per episode of care. These efficiencies effectively double staff capacity while maintaining exceptional quality and compliance. As reimbursement pressures intensify, Enzo Health empowers agencies to navigate cost-cutting measures without compromising care quality, positioning AI as the essential strategy for sustainable growth in home health. About the role We're looking for a hands-on Security Architect to design and build the systems that keep Enzo Health-and the protected health information we're entrusted with-safe at the speed AI is changing the threat landscape. Offensive tooling, AI-assisted fuzzing, and LLM-powered scanners have compressed time-to-exploit from weeks to hours. Closing that gap is the job. This is a builder's role, not a policy role. You'll own the end-to-end security architecture of a HIPAA-regulated AI platform, design automated pipelines that discover, validate, and remediate vulnerabilities, and write the code that makes it real. You'll work directly with engineering leadership to shape both technical direction and security posture from the foundation up. This is a full-time, in-office role at our Lehi, UT headquarters. Remote work is not available for this position. What you'll do * Design and build automated security pipelines that operate at the speed of modern, AI-assisted adversaries * Own the full vulnerability lifecycle: discovery * dynamic validation * automated remediation * verification * Build exploit validation harnesses, LLM-powered remediation tooling, and PR-time security analysis into our CI/CD * Threat-model our own systems, including AI-specific attack surfaces (prompt injection, model supply chain, agent abuse) * Lead HIPAA, SOC 2, and emerging compliance programs as engineering work, not paperwork * Partner with engineering on secure-by-default architecture: auth, secrets, data isolation, BAA chain, SSO/SCIM * Establish detection, incident response, and observability for the security pipeline itself * Write clean, maintainable code and set the bar for security practices across the engineering team * Move quickly-balancing rigorous adversarial thinking with shipping working systems ## Related Videos - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)