1,103,002open jobs
64,065companies
186,136added this week
Browse all
Salary
$115k – $150k per year
Location
In office (Columbus)
Seniority
Middle · 3+ years exp

Confirmed on the employer's own hiring board on Oct 2, 2026. First seen by Alion on Sep 15, 2026.

Overview
Company
Impact
Profile match
Gifthealth, the first digital pharmacy to offer DTP at scale, powers a seamless prescription journey with our single partner platform—no gaps, no lags, no friction.

Description

About Us

At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.

Position Summary

We are seeking a Cloud Security Engineer to design, implement, and maintain security controls across the organization's cloud infrastructure and cloud-native technology environments. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.

This role partners with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to establish secure cloud architectures, identify cloud risks, implement preventative controls, and continuously improve the organization's cloud security posture.

The Cloud Security Engineer serves as the primary technical security resource for cloud infrastructure and helps ensure security controls are scalable, automated, and integrated into the way cloud environments are designed and operated.

Key Responsibilities

Cloud Security Architecture:

  • Develop and maintain security standards and reference architectures for cloud environments.
  • Participate in architecture reviews for new cloud services, platforms, and major infrastructure changes.
  • Evaluate proposed architectures for security risks and recommend appropriate controls.
  • Establish secure patterns for cloud networking, identity, encryption, logging, storage, compute, and managed services.
  • Evaluate the security boundary between AWS-managed infrastructure and externally managed platforms (e.g., Heroku, Snowflake) to ensure consistent controls across both.

Cloud Security Posture Management:

  • Identify insecure cloud configurations and excessive permissions.
  • Continuously assess cloud environments against established security standards and benchmarks.
  • Prioritize cloud security findings based on technical severity and business risk.
  • Partner with system owners to remediate cloud security findings.
  • Identify systemic issues that can be addressed through platform-level controls.

Cloud Identity and Access Security:

  • Work with IAM teams to establish least-privilege access models for cloud resources.
  • Review cloud roles, permissions, service accounts, and privileged access.
  • Identify excessive, unused, or risky cloud privileges.
  • Establish controls for administrative and privileged cloud access.
  • Support secure workload identity and service-to-service authentication patterns.

Cloud Security:

Develop security controls for:

  • Compute workloads
  • Storage
  • Databases
  • Networking
  • Serverless services
  • VPN and remote access infrastructure (Site-to-Site and client VPN)
  • Data warehouse platforms (e.g., Snowflake, BigQuery)
  • APIs
  • Secrets and key management
  • Establish secure configuration baselines.
  • Work with engineering teams to implement cloud security guardrails.

Cloud Detection and Monitoring:

  • Ensure appropriate cloud logging and security telemetry is available for security monitoring.
  • Develop or assist with detections for suspicious cloud activity.
  • Partner with Security Operations to investigate cloud security events.
  • Improve visibility into administrative activity, authentication, workload behavior, and configuration changes.

Infrastructure-as-Code and Automation:

  • Embed cloud security requirements into Infrastructure-as-Code.
  • Develop automated checks and preventative security controls.
  • Build reusable secure cloud modules and templates with engineering teams.
  • Use APIs, scripts, and cloud-native services to automate security processes.

Cloud Vulnerability Management:

  • Support vulnerability management across cloud infrastructure and workloads.
  • Identify vulnerable cloud resources, operating systems, containers, and services.
  • Coordinate remediation with infrastructure and engineering teams.
  • Help distinguish vulnerabilities requiring immediate remediation from findings better addressed through compensating controls or risk acceptance.

Governance and Security Standards:

  • Develop and maintain cloud security standards and technical requirements.
  • Map cloud controls to applicable security and compliance requirements.
  • Provide technical evidence for audits and assessments when needed.
  • Evaluate new AI-enabled cloud services (e.g., Amazon Q) for security and data-handling implications before broader rollout.

Qualifications

Education: Not specified as a requirement; we evaluate demonstrated hands-on experience.

Licensure/Certification: Not required. Relevant AWS, cloud security, Kubernetes, or security certifications are a plus.

Experience: 3+ years of experience in cloud engineering, cloud security, infrastructure engineering, DevOps, security engineering, or a related field.

Knowledge, Skills, and Abilities:

  • Hands-on experience securing environments within at least one major public cloud platform. Gifthealth's AWS environment hosts VPN infrastructure, Redis, Amazon Q, and core security/logging tooling, while the primary application runs on Heroku (a separate PaaS), so comfort securing that kind of hybrid boundary is valuable.
  • Strong understanding of cloud IAM, networking, encryption, secrets management, logging and monitoring, compute and storage security, vulnerability management, and cloud-native security services.
  • Ability to secure workloads across a hybrid environment that spans direct cloud infrastructure (AWS) and externally managed platforms (e.g., Heroku, Snowflake).
  • Experience scripting or automating infrastructure and security activities, with an understanding of least privilege and cloud-native identity models.
  • Ability to evaluate cloud architectures and communicate security requirements clearly to technical teams.
  • Demonstrated application of the above Qualification
  • Preferred: strong AWS security experience, including multi-account cloud environments.
  • Preferred: experience with Kubernetes, containers, or serverless technologies. Gifthealth's core application currently runs on Heroku rather than Kubernetes.
  • Preferred: experience with Cloud Security Posture Management or Cloud-Native Application Protection platforms, and familiarity with CIS cloud benchmarks, NIST guidance, or other cloud security frameworks.
  • Preferred: familiarity with VPN architectures (Site-to-Site and client VPN) for secure remote and third-party access.
  • Preferred: experience implementing column-level masking, row-level security, or PHI field-level governance in analytics warehouses such as Snowflake or BigQuery. This is an active initiative at Gifthealth as data infrastructure migrates to Snowflake.
  • Preferred: experience with Infrastructure-as-Code such as Terraform or CloudFormation and building preventative cloud guardrails using policies, automation, or IaC (confirm current IaC tooling with the Infrastructure team, as usage across the AWS estate hasn't been fully verified), plus experience working within regulated environments.

Measures of Success

Success in this role includes:

  • Cloud security requirements are incorporated into architecture before systems are deployed.
  • High-risk cloud misconfigurations and excessive permissions are identified and remediated.
  • Security controls increasingly operate as automated guardrails rather than manual reviews.
  • Cloud environments have reliable security logging and monitoring coverage.
  • Cloud vulnerabilities and configuration findings have clear ownership and remediation paths.
  • Secure cloud patterns are documented and reusable by engineering teams.
  • Security becomes a standard part of cloud architecture and platform engineering decisions.

Work Environment

Location: Not specified in the source job description; to be confirmed with the hiring manager.

Schedule: Full-time; standard business hours.

May require flexibility for cloud security incident response or urgent remediation of high-risk findings.

Regular collaboration with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to ensure alignment.

Key Essential Functions

  • Must be able to work at a computer for extended periods
  • Must be able to communicate effectively, verbally and in writing, with infrastructure, engineering, and security stakeholders
  • Must be able to handle and access sensitive cloud infrastructure and security data in compliance with organizational data handling requirements
  • Must be able to respond to critical cloud security incidents outside standard working hours when required

Employment Classification

Status: Full-time

FLSA: Exempt

Equal Employment Opportunity (EEO) Statement

Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.

We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!

Disclaimer

This job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time.

Salary Description

$115,000-$150,000

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,103,002 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Columbus
$209k – $239k per year • In office • Full-Time • 8+ years exp • High School Diploma • Richmond
Python
JavaScript
DevOps
Terraform
CloudFormation
CI/CD
AWS
Apply
$209k – $239k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Plano
DevOps
Splunk
AWS
Cybersecurity
Crowdstrike
Qualys Cloud Platform
Management
Agile
Apply
≈ $71k – $152k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Temple Terrace
Python
DevOps
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
ISO 27001
SOC 2
CVSS
Apply
≈ $68k – $136k per year (Estimated) • Remote (United States) • Full-Time • 1+ year exp • Bachelor's Degree • Alpharetta
Python
JavaScript
TypeScript
C#
Databases
Google BigQuery
BigQuery
AI/ML
Claude Code
Model Context Protocol
AI Agents
Frontend
Angular
React.js
DevOps
Rest API
GCP
Azure DevOps
Azure
CI/CD
Google Cloud Run
GitLab
Amazon S3
IAM
Cybersecurity
OWASP Top 10
Least Privilege
OWASP
Analytics
ETL/ELT
Looker
Management
Google Sheets
Apply
$85k – $162k per year • Remote (United States) • Full-Time • 4+ years exp • Bachelor's Degree • Chicago
PowerShell
DevOps
Azure
IAM
Cybersecurity
Okta
ISO 27001
Microsoft Entra ID
Active Directory
Apply
≈ $91k – $189k per year (Estimated) • Remote (United Kingdom)
DevOps
Terraform
Ansible
GCP
GitHub Actions
Datadog
Packer
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Incident Management
Cybersecurity
ISO 27001
SOC 2
Management
ITIL
Apply
≈ $94k – $218k per year (Estimated) • Remote (likely EAEU) • Full-Time
Java
Kotlin
SQL
Java
Spring Boot
Databases
PostgreSQL
Apache Kafka
DevOps
GitLab CI
CI/CD
Docker
Kubernetes
GitLab
Apply
≈ $74k – $165k per year (Estimated) • Remote (likely EAEU) • Full-Time • 5+ years exp
JavaScript
TypeScript
SQL
Databases
Redis
Frontend
GraphQL
DevOps
Rest API
WebSockets
CI/CD
Docker
Kubernetes
QA
Playwright
Apply
In office • 2+ years exp • Minsk
Python
Go
Databases
PostgreSQL
Weaviate
Milvus
pgvector
FAISS
Qdrant
AI/ML
LangGraph
AutoGen
Weights & Biases
LangChain
llama.cpp
LlamaIndex
LoRA
Model Context Protocol
vLLM
MLFlow
Fine-tuning
Embeddings
Function Calling
AI Agents
Langfuse
Ollama
PEFT
QLoRA
TGI
CrewAI
LLM
RAG
Hallucination
Reranking
OpenAI
Anthropic
LLMOps
DPO
SFT
Human-in-the-Loop
Tool Use
DevOps
Rest API
CI/CD
Git
Docker
Kubernetes
Management
Agile
Scrum
Apply
Telco Cloud Architect 5 hours ago
≈ $70k – $161k per year (Estimated) • Remote (France) • Full-Time • Bachelor's Degree • France
DevOps
Ansible
Red Hat
OpenShift
GitOps
Kubernetes
OpenStack
Linux
Management
Agile
Apply
DevSecOps Engineer 1 day ago
$115k – $165k per year • In office • 3+ years exp • Columbus
Python
JavaScript
Ruby
PowerShell
Ruby
Ruby on Rails
Brakeman
Databases
PostgreSQL
Redis
DevOps
Terraform
CloudFormation
Heroku
CI/CD
Git
AWS
Kubernetes
Platform Engineering
Trunk-Based Development
GitHub
Cybersecurity
CodeQL
OWASP Top 10
Threat Modeling
Dependabot
Apply
$73k – $86k per year • In office • 2+ years exp • Bachelor's Degree • Columbus
Python
PowerShell
DevOps
AWS
Linux
Windows
Cybersecurity
Okta
SentinelOne
PCI DSS
SOC 2
HIPAA
Apply
$106k – $132k per year • In office • 4+ years exp • Bachelor's Degree • United States
Design
Figma
Sketch
FigJam
Management
Agile
Scrum
Apply
≈ $122k – $241k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Columbus
Ruby
Ruby
Ruby on Rails
Databases
PostgreSQL
DevOps
CI/CD
Management
Agile
Apply
$99k – $124k per year • Hybrid • 5+ years exp • Bachelor's Degree • United States
Management
Slack
Apply
$73k – $86k per year • In office • 2+ years exp • Bachelor's Degree • Columbus
Python
PowerShell
DevOps
AWS
Linux
Windows
Cybersecurity
Okta
SentinelOne
PCI DSS
SOC 2
HIPAA
Apply
≈ $66k – $124k per year (Estimated) • Remote (United States) • Full-Time • 4+ years exp • Bachelor's Degree • Columbus
AI/ML
Copilot
DevOps
Azure DevOps
Azure
Management
Jira
ServiceNow
Agile
Scrum
Apply
$70k – $154k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Chicago • Waterloo • Houston • Birmingham • Milwaukee
Management
Microsoft Office
Apply
$65k – $100k per year • In office • Associate's Degree • Columbus
Management
Outlook
Microsoft Office
Apply
≈ $70k – $134k per year (Estimated) • Remote (United States) • Full-Time • 5+ years exp • Columbus • Orlando • Austin • Atlanta • Dallas
Management
Slack
Apply
See all jobs
This is one of many
1,103,002 more open roles from verified company boards, updated every day.