{"id":1702111,"url":"https://alion.io/job/gifthealth-cloud-security-engineer","title":"Cloud Security Engineer","company":{"id":3854482,"name":"Gifthealth","domain":"gifthealth.com","url":"https://alion.io/company/gifthealth","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-08T05:49:30Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Columbus, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":115000,"max":150000,"currency":"USD","period":"year","gross":null,"usd_annual":150000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"BigQuery","optional":false},{"name":"Google BigQuery","optional":false},{"name":"Heroku","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Snowflake","optional":false},{"name":"VPN","optional":false},{"name":"CloudFormation","optional":true},{"name":"Redis","optional":true},{"name":"Terraform","optional":true}],"status":"live","first_seen_at":"2026-09-15T16:04:24Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-09T02:23:44Z","board_verified":true,"closed_at":null,"days_open":23,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":23},"description":"Description\nAbout Us\nAt Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.\nPosition Summary\nWe are seeking a Cloud Security Engineer to design, implement, and maintain security controls across the organization's cloud infrastructure and cloud-native technology environments. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.\nThis role partners with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to establish secure cloud architectures, identify cloud risks, implement preventative controls, and continuously improve the organization's cloud security posture.\nThe Cloud Security Engineer serves as the primary technical security resource for cloud infrastructure and helps ensure security controls are scalable, automated, and integrated into the way cloud environments are designed and operated.\nKey Responsibilities\nCloud Security Architecture:\nDevelop and maintain security standards and reference architectures for cloud environments.\nParticipate in architecture reviews for new cloud services, platforms, and major infrastructure changes.\nEvaluate proposed architectures for security risks and recommend appropriate controls.\nEstablish secure patterns for cloud networking, identity, encryption, logging, storage, compute, and managed services.\nEvaluate the security boundary between AWS-managed infrastructure and externally managed platforms (e.g., Heroku, Snowflake) to ensure consistent controls across both.\nCloud Security Posture Management:\nIdentify insecure cloud configurations and excessive permissions.\nContinuously assess cloud environments against established security standards and benchmarks.\nPrioritize cloud security findings based on technical severity and business risk.\nPartner with system owners to remediate cloud security findings.\nIdentify systemic issues that can be addressed through platform-level controls.\nCloud Identity and Access Security:\nWork with IAM teams to establish least-privilege access models for cloud resources.\nReview cloud roles, permissions, service accounts, and privileged access.\nIdentify excessive, unused, or risky cloud privileges.\nEstablish controls for administrative and privileged cloud access.\nSupport secure workload identity and service-to-service authentication patterns.\nCloud Security:\nDevelop security controls for:\nCompute workloads\nStorage\nDatabases\nNetworking\nServerless services\nVPN and remote access infrastructure (Site-to-Site and client VPN)\nData warehouse platforms (e.g., Snowflake, BigQuery)\nAPIs\nSecrets and key management\nEstablish secure configuration baselines.\nWork with engineering teams to implement cloud security guardrails.\nCloud Detection and Monitoring:\nEnsure appropriate cloud logging and security telemetry is available for security monitoring.\nDevelop or assist with detections for suspicious cloud activity.\nPartner with Security Operations to investigate cloud security events.\nImprove visibility into administrative activity, authentication, workload behavior, and configuration changes.\nInfrastructure-as-Code and Automation:\nEmbed cloud security requirements into Infrastructure-as-Code.\nDevelop automated checks and preventative security controls.\nBuild reusable secure cloud modules and templates with engineering teams.\nUse APIs, scripts, and cloud-native services to automate security processes.\nCloud Vulnerability Management:\nSupport vulnerability management across cloud infrastructure and workloads.\nIdentify vulnerable cloud resources, operating systems, containers, and services.\nCoordinate remediation with infrastructure and engineering teams.\nHelp distinguish vulnerabilities requiring immediate remediation from findings better addressed through compensating controls or risk acceptance.\nGovernance and Security Standards:\nDevelop and maintain cloud security standards and technical requirements.\nMap cloud controls to applicable security and compliance requirements.\nProvide technical evidence for audits and assessments when needed.\nEvaluate new AI-enabled cloud services (e.g., Amazon Q) for security and data-handling implications before broader rollout.\nQualifications\nEducation: Not specified as a requirement; we evaluate demonstrated hands-on experience.\nLicensure/Certification: Not required. Relevant AWS, cloud security, Kubernetes, or security certifications are a plus.\nExperience: 3+ years of experience in cloud engineering, cloud security, infrastructure engineering, DevOps, security engineering, or a related field.\nKnowledge, Skills, and Abilities:\nHands-on experience securing environments within at least one major public cloud platform. Gifthealth's AWS environment hosts VPN infrastructure, Redis, Amazon Q, and core security/logging tooling, while the primary application runs on Heroku (a separate PaaS), so comfort securing that kind of hybrid boundary is valuable.\nStrong understanding of cloud IAM, networking, encryption, secrets management, logging and monitoring, compute and storage security, vulnerability management, and cloud-native security services.\nAbility to secure workloads across a hybrid environment that spans direct cloud infrastructure (AWS) and externally managed platforms (e.g., Heroku, Snowflake).\nExperience scripting or automating infrastructure and security activities, with an understanding of least privilege and cloud-native identity models.\nAbility to evaluate cloud architectures and communicate security requirements clearly to technical teams.\nDemonstrated application of the above Qualification\nPreferred: strong AWS security experience, including multi-account cloud environments.\nPreferred: experience with Kubernetes, containers, or serverless technologies. Gifthealth's core application currently runs on Heroku rather than Kubernetes.\nPreferred: experience with Cloud Security Posture Management or Cloud-Native Application Protection platforms, and familiarity with CIS cloud benchmarks, NIST guidance, or other cloud security frameworks.\nPreferred: familiarity with VPN architectures (Site-to-Site and client VPN) for secure remote and third-party access.\nPreferred: experience implementing column-level masking, row-level security, or PHI field-level governance in analytics warehouses such as Snowflake or BigQuery. This is an active initiative at Gifthealth as data infrastructure migrates to Snowflake.\nPreferred: experience with Infrastructure-as-Code such as Terraform or CloudFormation and building preventative cloud guardrails using policies, automation, or IaC (confirm current IaC tooling with the Infrastructure team, as usage across the AWS estate hasn't been fully verified), plus experience working within regulated environments.\nMeasures of Success\nSuccess in this role includes:\nCloud security requirements are incorporated into architecture before systems are deployed.\nHigh-risk cloud misconfigurations and excessive permissions are identified and remediated.\nSecurity controls increasingly operate as automated guardrails rather than manual reviews.\nCloud environments have reliable security logging and monitoring coverage.\nCloud vulnerabilities and configuration findings have clear ownership and remediation paths.\nSecure cloud patterns are documented and reusable by engineering teams.\nSecurity becomes a standard part of cloud architecture and platform engineering decisions.\nWork Environment\nLocation: Not specified in the source job description; to be confirmed with the hiring manager.\nSchedule: Full-time; standard business hours.\nMay require flexibility for cloud security incident response or urgent remediation of high-risk findings.\nRegular collaboration with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to ensure alignment.\nKey Essential Functions\nMust be able to work at a computer for extended periods\nMust be able to communicate effectively, verbally and in writing, with infrastructure, engineering, and security stakeholders\nMust be able to handle and access sensitive cloud infrastructure and security data in compliance with organizational data handling requirements\nMust be able to respond to critical cloud security incidents outside standard working hours when required\nEmployment Classification\nStatus: Full-time\nFLSA: Exempt\nEqual Employment Opportunity (EEO) Statement\nGifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.\nWe celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply!\nDisclaimer\nThis job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time.\nSalary Description\n$115,000-$150,000","description_format":"text","description_chars":9658,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security","Health Care","Pharmacies"],"lifecycle":[{"event":"open","at":"2026-10-02T13:46:58Z"}],"visa":[],"liveness":{"score":35,"band":"fade","label":"Fading","p_open":1,"p_active":0.634,"p_room":0.55,"age_days":22,"expected_fill_days":18,"reasons":["conf:0","velocity","win:tail"],"computed_at":"2026-10-08T05:49:30Z"},"pay":{"stated_usd_annual":150000,"is_top_pay":true},"html_url":"https://alion.io/job/gifthealth-cloud-security-engineer","json_url":"https://alion.io/job/gifthealth-cloud-security-engineer.json","meta":{"generated_at":"2026-10-09T04:47:11Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4802,"day_limit":5000,"remaining_today":198,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3854482},"rest":"https://alion.io/mcp/rest/get_company?id=3854482"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fgifthealth-cloud-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fgifthealth-cloud-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fgifthealth-cloud-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/gifthealth-cloud-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fgifthealth-cloud-security-engineer"}]}