Security Engineer III
GHX Hyderabad, Telangana, India
Hospitals and Health Care · 1,001-5,000 employees
About the role
The Security Engineer will architect and maintain the Wiz CNAPP suite to secure AWS ecosystems and AI-driven application pipelines. They will also implement automated security guardrails, enforce least privilege policies, and collaborate with engineering teams to embed secure-by-design patterns.
What they look for
Requirements
Candidates must have 4+ years of experience in DevSecOps or Cloud Security with deep expertise in AWS and Wiz CNAPP. Proficiency in Infrastructure as Code (Terraform), automation scripting (Python), and securing AI/ML pipelines is required.
Full description
Role: Security Engineer III Location: Hyderabad, India (Hybrid) Department: Infrastructure/Info Security
About GHX: GHX (Global Healthcare Exchange) is a leading healthcare technology company on a mission to simplify the business of healthcare and improve patient outcomes. Founded in 2000, GHX has built the GHX Global Network — the world’s largest cloud-based supply chain community connecting healthcare providers, suppliers, distributors, and partners to automate key processes, reduce costs, and increase operational efficiency. Its solutions span electronic trading, procurement automation, inventory and contract management, business intelligence, and data synchronization, helping healthcare organizations improve productivity and focus more on patient care. Over the years, GHX has enabled significant cost savings for the industry and continues to innovate with intelligent automation and AI-driven capabilities.
Website: https://www.ghx.com/ LinkedIn: https://www.linkedin.com/company/ghx/
Role Overview
We are seeking a highly skilled Cybersecurity Engineer with 4+ years of experience to secure our production AWS ecosystems and modern AI-driven application pipelines. In this business-critical role, you will take operational ownership of the entire Wiz Cloud Native Application Protection Platform (CNAPP) suite. You will bridges the gap between infrastructure protection and software development by deploying Wiz Code and Wiz Code to Cloud architectures, tracing software defects, vulnerabilities, and hardcoded secrets directly from git environments up to running containerized architectures. Additionally, you will design guardrails protecting LLM structures and pipeline environments from next-generation adversarial patterns.
Key Responsibilities
Shift-Left Security & Wiz Portfolio Ownership
- Wiz CNAPP: Architect, configure, and maintain the Wiz CNAPP suite globally across our AWS enterprise structure, leveraging security graphs to aggregate risk profiles.
- Wiz Code Deployment: Integrate Wiz Code natively within engineering workflows, provisioning scanning capabilities across Git platforms (GitHub/GitLab) and automated CI/CD engines.
- Code to Cloud Traceability: Leverage Wiz Code to Cloud context to instantly map live, running AWS workload exploits back to distinct repository blocks, code branches, and specific developers to isolate structural roots.
- Supply Chain Assurance: Analyze and intercept Software Composition Analysis (SCA) alerts, malicious package risks, hardcoded infrastructure secrets, and broken Infrastructure as Code (IaC) architectures prior to merge pipelines.
AWS Cloud Infrastructure Security
- Graph Risk Analytics: Isolate toxic combinations within the Wiz Security Graph, evaluating attack paths that bind internet exposure, workload misconfigurations, vulnerable packages, and excess IAM capabilities together.
- Least Privilege Enforcement: Implement Cloud Infrastructure Entitlement Management (CIEM) reviews to detect and lock down excessive permissions on AWS resources (ECS, EC2, S3, EKS, AWS Lambda).
- Automated Compliance: Translate framework regulations (CIS AWS Foundations Benchmark, SOC 2, ISO 27001) into active compliance monitoring tracks across codebases and clouds.
AI/ML Pipeline & LLM Engineering Guardrails
- Pipeline Hardening: Deconstruct risks and deliver secure engineering patterns across AWS native platforms including Amazon Bedrock, SageMaker, and specialized training cluster nodes.
- Adversarial Defense: Construct mitigations targeting prompt injection tactics, training set data poisoning vectors, model inversion mechanics, and SSRF flaws inside runtime configurations.
- LLM Security Governance: Enforce guardrails modeled after the OWASP Top 10 for LLM Applications alongside MITRE ATLAS matrix standards.
Incident Support & DevSecOps Collaboration
- Automated Guardrails: Convert high-fidelity Wiz risk data into automated enforcement blockers inside continuous deployment workflows.
- Incident Tracing: Assist internal Security Operations with telemetry context during threat activities, blending Wiz insights, AWS CloudTrail, and GuardDuty payloads.
- Security Advocacy: Co-author engineering guidelines alongside product teams to embed secure-by-design patterns cleanly across everyday development lifecycles.
Required Skills & Qualifications
Technical Experience
- Professional Experience: 4+ years of focused technical practice in DevSecOps, Enterprise Application Security, or Cloud Security engineering roles.
- Wiz Competency: 1 to 2+ years of hands-on platform administration across Wiz CNAPP, including proven deployment depth utilizing Wiz Code or Wiz Code to Cloud pipelines.
- AWS Ecosystem Mastery: Deep structural knowledge of AWS IAM, KMS, Security Hub, CloudTrail, GuardDuty, VPC topologies, and multi-account Organization structures.
- AI/ML Engineering Exposure: Familiarity securing AI interfDaces (OpenAI API, Amazon Bedrock, SageMaker) and hardening orchestration components like LangChain or vector databases.
- Infrastructure as Code: Deep fluency reading, validating, and writing secure Infrastructure as Code manifests, specifically Terraform.
- Automation Scripting: Competency engineering automation routines using Python (Boto3) or Shell scripts to handle automated ingestion or compliance fixes.
Soft Skills & Certifications
- Engineering Collaboration: Proven track record collaborating closely with platform engineers to remediate deep code issues without stalling continuous delivery cycles.
- Certifications (Preferred): AWS Certified Security - Specialty, Certified DevSecOps Professional (CDP), CCSP, or specialized cloud native security architecture validations.
GHX: It's the way you do business in healthcare Global Healthcare Exchange (GHX) enables better patient care and billions in savings for the healthcare community by maximizing automation, efficiency and accuracy of business processes.
GHX is a healthcare business and data automation company, empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics and services. We bring together healthcare providers and manufacturers and distributors in North America and Europe - who rely on smart, secure healthcare-focused technology and comprehensive data to automate their business processes and make more informed decisions.
It is our passion and vision for a more operationally efficient healthcare supply chain, helping organizations reduce - not shift - the cost of doing business, paving the way to delivering patient care more effectively. Together we take more than a billion dollars out of the cost of delivering healthcare every year. GHX is privately owned, operates in the United States, Canada and Europe, and employs more than 1000 people worldwide. Our corporate headquarters is in Colorado, with additional offices in Europe.
Disclaimer Global Healthcare Exchange, LLC and its North American subsidiaries (collectively, “GHX”) provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. All qualified applicants will receive consideration for employment without regard to any status protected by applicable law. This EEO policy applies to all terms, conditions, and privileges of employment, including hiring, training and development, promotion, transfer, compensation, benefits, educational assistance, termination, layoffs, social and recreational programs, and retirement.GHX believes that employees should be provided with a working environment which enables each employee to be productive and to work to the best of his or her ability. We do not condone or tolerate an atmosphere of intimidation or harassment based on race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. GHX expects and requires the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere. Improper interference with the ability of GHX’s employees to perform their expected job duties is absolutely not tolerated.
Read our GHX Privacy Policy
Similar roles
-
Senior Network Security Engineer
Ascension United States · $116K–$162K/yr
-
Information Security Engineer, Principal
Blue Shield of California Oakland, California, United States · $168K–$252K/yr
-
Finance Manager, IT & Cybersecurity
Trane Italia Davidson, North Carolina, United States · $124K–$173K/yr
-
Cloud Security Engineer / Cloud Security Specialist (Hybrid | Cubao)
Accenture Manila, Metro Manila, Philippines
-
Cybersecurity Co-Founder / CCO (100 % remote) (m/f/d)
EWOR GmbH Washington, District of Columbia, United States
-
Cybersecurity Co-Founder / CMO (100 % remote) (m/f/d)
EWOR GmbH San Antonio, Texas, United States