> Markdown version of [/jobs/ext/3002619-senior-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3002619-senior-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer - **Company:** HealthMark Group - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Software Applications, Audit Trail, Cloud Computing, Cloud Computing Security, Cyber Security, Databases, Linux, DevOps, Dicom, Identity and Access Management, Interoperability, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, Microsoft Operating Systems, Network Architecture, Routing, Windows PowerShell, Cloud Services, Runbook, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Data Logging, Cloud Platform System, Fast Healthcare Interoperability Resources, Software Security, Boto3, Software Troubleshooting, Amazon Virtual Private Cloud (VPC), Cloudformation, Build Management, Amazon Relational Database Service, Information Technology, Health Level Seven International, Enterprise Integration, Functional Programming, Cloudwatch, Terraform, Network Server, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=884b24c48caee4b2 ## About the Role * Minimum of 5 to 7 years of dedicated experience in cybersecurity, infrastructure engineering, or DevOps, with at least 3 years focused strictly on AWS compliance-driven engineering. * Deep, hands-on knowledge of core AWS services commonly holding or routing PHI (VPC, IAM, EC2, S3, RDS, Lambda, EKS) and supporting services essential for the maintenance of a secure cloud environment. * Hands-on experience securing and hardening Linux systems and Linux-based cloud workloads, including access control, logging, patching, and benchmark-based configuration standards. * Strong working knowledge of HIPAA regulations, HITRUST CSF requirements, SOC 2 trust services criteria, or similar frameworks within a cloud context. * Demonstrated experience with cloud detection engineering and security incident response, including investigation and containment in AWS using CloudTrail, CloudWatch, and SIEM telemetry. * Advanced, production-level experience deploying and managing AWS infrastructure securely via Terraform or AWS CloudFormation, including policy-as-code enforcement and security integration into CI/CD pipelines. * Strong proficiency in scripting and automation using PowerShell, Python (Boto3), or similar to automate compliance evidence gathering and remediation tasks. * Great communicator with the ability to relay critical information to engineering teams, executive leadership, and external assessors promptly and effectively. * Strong troubleshooting and analytic ability to track and solve intricate problems across technical systems, such as servers, databases, developed applications, and network infrastructure, including issues spanning platforms and ownership boundaries. * Bachelor's degree in Computer Science, Information Security, or equivalent practical engineering experience. Additional Preferred Experience: * AWS Certified Security - Specialty * Certified Information Systems Security Professional (CISSP) or Certified Cloud Security Professional (CCSP) * HITRUST Certified CSF Practitioner (CCSFP) * Experience with security and maintenance of Microsoft systems, including Windows operating system, M365, Entra, and Active Directory * Strong experience with networking and security in physical and hybrid environments, in addition to cloud * Familiarity with medical imaging or healthcare interoperability technologies (DICOM, PACS, HL7/FHIR). * Experience securing environments through mergers, acquisitions, or platform integrations. ## Description The senior cloud security engineer is responsible for designing, implementing, and maintaining security controls for HealthMark Group developed applications and corporate systems, with a focus on the AWS cloud environment, including the platforms supporting our medical imaging business. They define AWS security guardrails appropriate for a highly-regulated environment containing Protected Health Information (PHI) and which must adhere to security regulations and frameworks such as HIPAA, HITRUST, and SOC 2. They serve as a leader in the Security Operations team, providing mentorship and guidance to fellow security engineers. Primary Roles and Responsibilities: * Design and build enterprise-grade security controls utilizing native AWS services to safeguard PHI across all cloud environments. * Design and maintain the secure multi-account AWS architecture - account structure, organizational units, guardrails, and baseline configuration - so that new accounts and workloads inherit required PHI protections by default. * Author, review, and maintain secure-by-default Terraform or AWS CloudFormation templates, integrating policy-as-code tools (e.g., OPA, Checkov, Rego) to programmatically enforce HIPAA, HITRUST, and SOC 2 controls before deployment. * Align and enforce strict data-at-rest and data-in-transit encryption strategies utilizing AWS KMS, ensuring cryptographic standards satisfy HITRUST and HIPAA mandates for PHI. * Design and enforce strict least-privilege access models, complex IAM policies, Service Control Policies (SCPs), and AWS Organizations boundaries to strictly control access to sensitive healthcare workloads. * Embed security testing, container scanning, and secrets management (AWS Secrets Manager) directly into CI/CD pipelines, creating automated evidence-collection workflows for continuous SOC 2 and HITRUST audit readiness. * Collaborate with application development and cloud operations teams to triage, investigate, and remediate vulnerabilities and findings from application and cloud security tooling, such as SAST, DAST, and CSPM. * Develop custom detection rules using AWS CloudTrail, Amazon CloudWatch telemetry, and enterprise SIEM tool to monitor system activities to detect and respond to threats and incidents. * Serve as the senior escalation point for cloud security incidents, leading investigation and containment in AWS environment in partnership with our Managed Detection and Response provider, Cloud Operations team, and Managed Services Provider. Drive post-incident root cause analysis and control improvements. * Support third-party risk assessment and security certification processes through evidence collection and response to security questionnaires. * Evaluate and document cloud security exceptions and compensating controls, partnering with GRC to ensure risk acceptance decisions are appropriately assessed, approved, and tracked to closure. * Lead the security integration of newly acquired platforms into HealthMark Group's cloud security architecture - assessing inherited environments, closing control gaps, and bringing workloads into HIPAA, HITRUST, and SOC 2 scope. * Provide technical mentorship to security engineers on secure cloud design, automation, and investigative technique, and support design reviews for new and changing AWS workloads. * Develop and maintain cloud security documentation, defining architecture standards, runbooks, and incident response procedures for an evolving environment. * Define and report cloud security metrics on a recurring basis to measure control coverage, posture drift, vulnerability management, and audit-readiness in the cloud environment. * Contribute cloud and application security expertise to enterprise security awareness and developer training efforts. * Stay up to date with industry trends and advancements in attacks and remediations, making recommendations to position our defenses appropriately. * Provide other support to HealthMark Group Security Operations as required. ## Related Videos - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)