Sr. Staff Security Engineer
Jobgether United States
Internet Marketplace Platforms · 11-50 employees
About the role
The Sr. Staff Security Engineer will own and evolve security architecture across cloud, application, and network infrastructure while leading threat modeling initiatives. They will partner with engineering and product teams to embed secure-by-default practices and ensure compliance with healthcare regulatory standards.
What they look for
Requirements
Candidates must have 10+ years of progressive security experience with at least 5 years focused on security architecture in enterprise and cloud environments. A bachelor's degree in Computer Science or a related field is required, along with deep expertise in application security, IAM, and regulatory frameworks like HIPAA.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Staff Security Engineer based in United States.
This is a senior-level security architecture role with broad ownership across cloud infrastructure, applications, identity, networks, and data protection.You will serve as a key technical authority, shaping secure-by-default architectures and influencing how engineering teams design and operate systems.The role combines hands-on architecture with strategic leadership, threat modeling, governance, and security enablement.You will work closely with engineering, product, technology leadership, privacy, compliance, and security teams to embed security throughout the development lifecycle.A major focus will be building scalable security practices that enable teams rather than creating unnecessary delivery bottlenecks.You will also help protect sensitive health information while strengthening resilience against evolving threats in a highly regulated environment.This is an opportunity to establish durable architecture standards, mentor security professionals, and make a measurable organization-wide impact.
\n
Accountabilities:
- Own and continuously evolve security architecture across cloud infrastructure, applications, corporate systems, identity, networks, and data, establishing standards, patterns, and reference architectures for engineering teams.
- Lead threat modeling for product, engineering, and infrastructure initiatives, with particular attention to sensitive health data flows, patient-facing applications, and virtual care systems, while coaching engineers to perform threat modeling independently.
- Conduct architecture reviews for new and existing systems, assess designs against security principles and regulatory requirements, and provide practical recommendations that balance risk, usability, scalability, and delivery speed.
- Design and scale the architecture review process through self-service patterns, risk-tiered workflows, and clear criteria for when deeper security review is required.
- Partner with technology and enterprise architecture leaders to integrate security governance into existing technical processes rather than creating parallel or disruptive workflows.
- Define and promote application security standards covering secure design, API security, authentication and authorization, OAuth/OIDC, SAML, data protection, and healthcare interoperability standards such as HL7 and FHIR.
- Establish and govern zero trust strategies across identity, network, endpoint, and data layers, as well as key management, secrets management, encryption, and certificate lifecycle practices.
- Define security architecture for third-party integrations and external systems, ensuring supply-chain and integration risks are addressed at the design stage.
- Act as a trusted security partner to product and engineering leaders, participating early in design and planning discussions to help teams build secure-by-default systems.
- Translate privacy, compliance, audit, and governance requirements into concrete architectural controls, with particular attention to HIPAA Security Rule technical safeguards, HITRUST, NIST, and SOC 2.
- Maintain architecture decision records, reference designs, control frameworks, and other durable documentation that supports consistent security practices.
- Partner with senior security leadership on long-term architecture strategy, risk measurement, executive reporting, and security roadmap development.
- Mentor and elevate security engineers and promote stronger architectural thinking across security and engineering teams.
- Monitor emerging threats and attack techniques, particularly those affecting healthcare environments, and incorporate relevant intelligence into security architecture decisions.
- Establish measurable outcomes around architecture risk, threat modeling adoption, reference architecture usage, and the shift of security findings from late-stage remediation toward earlier design-stage prevention.
Requirements:
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
- 10+ years of progressive security experience, including at least 5 years focused on security architecture across enterprise and cloud environments.
- Deep expertise across multiple security domains, including application security, cloud security, identity and access management, network security, and data protection.
- Strong hands-on experience architecting cloud security solutions covering network security, IAM, encryption, key management, secrets management, and cloud-native security services.
- Proven experience leading structured threat modeling using methodologies such as STRIDE, PASTA, or equivalent, from individual features through complex systems, and mentoring engineers in threat-modeling practices.
- Strong knowledge of secure software development lifecycles, OWASP principles, application security patterns, and modern authentication and authorization approaches including OAuth 2.0, OIDC, and SAML.
- Experience designing key management, secrets management, PKI, and certificate lifecycle controls in cloud-native environments.
- Working knowledge of HIPAA and its Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2, with the ability to translate requirements into practical technical controls.
- Demonstrated ability to communicate complex technical risks clearly to both engineering teams and executive stakeholders.
- Experience working across identity, network, application, and data security rather than operating within a single security domain.
- Strong architectural judgment and the ability to balance security, operational practicality, scalability, and engineering velocity.
- Self-directed and comfortable bringing structure to ambiguous technical problems while influencing decisions across teams.
- Preferred experience in healthcare, digital health, or another highly regulated industry.
- Preferred experience designing or scaling zero trust architectures and enterprise architecture review processes, including risk-tiering and self-service models.
- Familiarity with API security, HL7, FHIR, SABSA, or TOGAF security extensions is advantageous.
- Experience mentoring senior engineers or establishing security architecture practices from the ground up is a plus.
Benefits:
- Remote work opportunity for employees based in the United States or Toronto, Canada.
- Medical, dental, and vision insurance plans.
- Flexible Spending Accounts and Health Savings Accounts.
- Flexible paid time off.
- 401(k) retirement plan with company matching.
- Life insurance coverage.
- Pet insurance.
- Opportunity to work in a relatively flat environment that encourages autonomy, ownership, and ideas from employees.
- Significant opportunity to influence security architecture, engineering practices, and organization-wide technical standards.
- Leadership and mentoring opportunities at the highest technical level of the security function.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Cybersecurity Engineer II
Atlantic Health System Morristown, New Jersey, United States
-
Senior Cloud Security Engineer
Delta Exchange India
-
Lead Cybersecurity Architect
JPMorgan Chase & Co. Bengaluru, Karnataka, India
-
Staff Security Engineer, Third Party Security Diligence
Google Singapore
-
Cyber Security Engineer
Tamara Riyadh, Riyadh Region, Saudi Arabia
-
Senior Lead Cybersecurity Architect – Blockchain Security (Smart Contracts) Specialist
JPMorgan Chase & Co. Singapore, Singapore, Singapore