{"id":1927405,"url":"https://alion.io/job/med-metrix-senior-cloud-security-engineer","title":"Senior Cloud Security Engineer","company":{"id":3787069,"name":"Med-Metrix","domain":"med-metrix.com","url":"https://alion.io/company/med-metrix","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"inferred_payroll_markers","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":102000,"max_usd":210000,"period":"year","method":"global_role_seniority_cell","sample_n":1567},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon EKS","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure AKS","optional":false},{"name":"Bicep","optional":false},{"name":"CI/CD","optional":false},{"name":"CloudFormation","optional":false},{"name":"Docker","optional":false},{"name":"HIPAA","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Office","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP","optional":false},{"name":"PCI DSS","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Zero Trust","optional":false},{"name":"Amazon SageMaker","optional":true},{"name":"Databricks","optional":true},{"name":"GCP","optional":true},{"name":"Harbor","optional":true},{"name":"Kubeflow","optional":true},{"name":"Red Teaming","optional":true},{"name":"Vertex AI","optional":true}],"status":"live","first_seen_at":"2026-10-05T16:48:32Z","employer_posted_date":null,"last_verified_at":"2026-10-05T16:48:32Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":2},"description":"Job Purpose The Senior Cloud Security Engineer will design, implement, and maintain security controls across our multi-cloud environment, with a particular emphasis on securing AI/ML workloads and leveraging AI-driven security tooling. The Senior Cloud Security Engineer will serve as a technical leader, partnering with engineering, application development, and DevOps teams to embed security into every stage of the cloud and AI development lifecycle.\nDuties & Responsibilities\nDesign and implement secure cloud architecture across AWS and Azure, including identity, network security, encryption, and key management\n\nImplement cloud-native logging, monitoring, and threat detection to improve visibility and incident response\n\nBuild Infrastructure-as-Code (Terraform, CloudFormation, Bicep), Policy-as-Code, and automated compliance controls\n\nImplement and enhance Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), and CNAPP capabilities\n\nConduct threat modeling, security architecture reviews, and risk assessments for cloud services and applications\n\nDesign and secure AI/ML environments, including MLOps pipelines, model security, inference endpoints, and AI governance\n\nAssess and mitigate AI-specific threats, including prompt injection, model poisoning, adversarial attacks, and data leakage\n\nPartner with engineering and data science teams to implement secure-by-design and privacy-preserving controls for regulated data\n\nDevelop automated detections, SOAR playbooks, and AI-driven threat hunting capabilities\n\nLead technical response to cloud and AI security incidents, including forensic analysis and remediation\n\nDesign and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements\n\nSupport technical readiness, evidence collection, and remediation activities for security audits and compliance assessments\n\nDevelop and maintain cloud security standards, technical guidance, and AI governance documentation\n\nSupport enterprise risk management and vendor security assessments\n\nIntegrate security throughout the DevSecOps lifecycle, including application, container, and secrets management\n\nDevelop security metrics, communicate technical risks to stakeholders, and recommend continuous security improvements\n\nMentor junior engineers and champion security best practices across engineering teams\n\nOther duties as assigned\n\nUse, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards\n\nUnderstand and comply with Information Security and HIPAA policies and procedures at all times\n\nLimit viewing of PHI to the absolute minimum as necessary to perform assigned duties\n\nQualifications\nHigh school diploma or equivalent required\n\n6+ years of experience in information security, with at least 4 years focused on cloud security engineering\n\nDeep hands-on expertise in both AWS and Microsoft Azure, including native security services (e.g., AWS GuardDuty, Security Hub, IAM Identity Center; Microsoft Defender for Cloud, Sentinel, Entra ID)\n\nStrong knowledge of IAM, zero trust architecture, network security, encryption, and secrets management in cloud environments\n\nPractical experience securing AI/ML systems or LLM-based applications, or demonstrable working knowledge of AI security frameworks (OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF)\n\nProficiency in at least one scripting/programming language (Python preferred) and infrastructure-as-code tooling\n\nExperience with container and orchestration security (Docker, Kubernetes, EKS/AKS)\n\nSolid understanding of DevSecOps practices and CI/CD security integration\n\nHands-on experience supporting compliance programs such as HIPAA, HITRUST CSF, PCI DSS, and SOC 2 in cloud environments, including audit evidence and control implementation\n\nProficiency in Microsoft Office Suite\n\nStrong interpersonal skills, ability to communicate well at all levels of the organization\n\nStrong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses\n\nHigh level of integrity and dependability with a strong sense of urgency and results oriented\n\nExcellent written and verbal communication skills required\n\nPreferred Qualifications\nExperience with Google Cloud Platform (GCP) in addition to AWS and Azure\n\nExperience deploying or securing MLOps platforms (SageMaker, Vertex AI, Azure ML, Databricks, Kubeflow)\n\nFamiliarity with AI-driven security platforms and building custom detections using ML techniques\n\nRelevant certifications such as CISSP, CCSP, HCISPP, CCSFP (HITRUST), AWS Security Specialty, Azure Security Engineer (AZ-500), GCP Professional Cloud Security Engineer, or GIAC certifications\n\nPrior experience in healthcare, health tech, or revenue cycle management environments handling PHI at scale\n\nExperience with red teaming or adversarial testing of AI systems\n\nKnowledge of data privacy regulations as they apply to AI training data and model outputs, particularly de-identification standards under HIPAA (Safe Harbor and Expert Determination)\n\nContributions to security communities, open-source tooling, or published research\n\nWorking Conditions\nTravel may be required for training, conferences, etc.\n\nMust possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes\n\nPhysical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear\n\nMental Demands: The employee must be able to follow directions, collaborate with others, and handle stress\n\nWork Environment: The noise level in the work environment is usually minimal\n\nMed-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.\nOriginally posted on Himalayas","description_format":"text","description_chars":6409,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Health insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security","Revenue Cycle & Medical Billing"],"lifecycle":[{"event":"open","at":"2026-10-05T20:28:30Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":1,"expected_fill_days":28,"reasons":["seen:1","win:early"],"computed_at":"2026-10-07T05:47:15Z"},"pay":null,"html_url":"https://alion.io/job/med-metrix-senior-cloud-security-engineer","json_url":"https://alion.io/job/med-metrix-senior-cloud-security-engineer.json","meta":{"generated_at":"2026-10-08T01:41:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2948,"day_limit":5000,"remaining_today":2052,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3787069},"rest":"https://alion.io/mcp/rest/get_company?id=3787069"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fmed-metrix-senior-cloud-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fmed-metrix-senior-cloud-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fmed-metrix-senior-cloud-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/med-metrix-senior-cloud-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fmed-metrix-senior-cloud-security-engineer"}]}