> Markdown version of [/jobs/ext/3057222-security-engineer](https://www.wearedevelopers.com/jobs/ext/3057222-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Rvo Health - **Location:** Denver, CO, United States (Remote available) - **Experience:** Experienced - **Salary:** $100,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Build Automation, Cloud Computing Security, Code Review, Cyber Security, Github, Secure Coding, Software Engineering, Systems Integration, Scripting, Large Language Models, Software Security, Mitre Att&ck, Containerization, Information Technology, Terraform, Prisma Cloud Platform, Devsecops, Programming Languages - **Published:** September 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=746fa24bbaf507f3 ## About the Role * Bachelor's degree in Computer Science, related field OR equivalent experience * Minimum 4+ years of experience in application security, cloud security, or a related cybersecurity role. * Solid understanding of cloud security principles, architectures, and services (AWS or Azure preferred). * Hands-on experience with cloud security posture management or CNAPP tooling (e.g., Wiz, Orca, Prisma Cloud), and a track record of driving vulnerability findings to closure with engineering teams. * Experience building security automation, tooling, and integrations, with working proficiency in at least one scripting or programming language. * Working knowledge of secure coding practices. * Knowledge of security frameworks, standards, and regulations (e.g., NIST CSF, HIPAA, MITRE ATT&CK). * Strong problem-solving and analytical skills, with the ability to think critically and make sound decisions. * Experience in incident response and recovery. Preferred: * Professional certifications (e.g., CISSP, CCSP, OSCP, GIAC). * Expertise in AWS security controls, monitoring, and orchestration (SCPs, GuardDuty, Config, Macie, etc.) * Working familiarity with Terraform, GitHub, and DevSecOps workflows - particularly securing GitHub Actions and other CI/CD pipelines. * Experience securing AI- or LLM-assisted development workflows, or reviewing AI-generated code at scale. * Experience with internal developer platforms or portals (e.g., Backstage). * Experience working alongside an MDR or managed SOC provider. ## Description RVO Health is a first-of-its-kind comprehensive consumer healthcare platform that meets people where they are in their personal journeys and connects them with both the information and the care they need. RVO Health is a partnership between Red Ventures and UnitedHealth Group. Together we're focused on delivering on our vision of a stronger and healthier world. RVO Health has the largest consumer health and wellness audience online. Every month, we help nearly 100 million people take steps on their daily journey to lifelong well-being. As part of our RVO Health Security team, you will play a major part in strategic initiatives that improve our security posture and protect our sensitive data. You will work in a collaborative Agile environment, working closely with the business, IT, and engineering teams. You will apply your skills in a highly dynamic, innovative, cloud-native environment with a strong security-minded culture., * Design, implement, and maintain security controls and architectures to protect the company's cloud infrastructure, applications, and data from cyber threats. * Improve our cloud security posture and vulnerability management program - pull-request scanning, triage and tracking of findings to closure across engineering teams, and coverage and license optimization. * Build and enforce software supply chain controls across the developer toolchain - package, dependency, and extension guardrails, with enforcement thresholds tuned to reduce noise rather than generate it. * Extend security into CI/CD pipelines, including the emerging problem of governing AI-authored code at the pipeline chokepoint. * Build automation, internal tooling, and integrations against our developer platform and security stack so that security controls are self-service rather than ticket-driven. * Partner with Platform & Software Engineering teams to create visibility and awareness of security issues and work to prioritize their resolution in a collaborative way. * Perform security assessments, including code reviews and application security testing, to identify and mitigate risk in new and changing systems. * Participate in a weekly on-call rotation for managed detection and response escalations; investigate potential threats, respond to security incidents, and perform root cause analysis. * Develop and maintain security standard operating procedures and policies in accordance with industry best practices and regulatory requirements (e.g., HIPAA, NIST CSF). * Stay informed of the latest developments in tactics, techniques, and procedures related to application and infrastructure vulnerabilities - especially in the healthcare space - and adapt the strategy or tooling to address new threats. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)