{"id":1975767,"url":"https://alion.io/job/reveleer-sr-information-security-engineer","title":"Sr. Information Security Engineer","company":{"id":7698,"name":"Reveleer","domain":"reveleer.com","url":"https://alion.io/company/reveleer","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Breezy","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":116000,"max_usd":212000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":256},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AI Agents","optional":false},{"name":"Amazon ECS","optional":false},{"name":"Amazon EKS","optional":false},{"name":"Amazon SageMaker","optional":false},{"name":"Ansible","optional":false},{"name":"AWS","optional":false},{"name":"AWS Bedrock","optional":false},{"name":"AWS Lambda","optional":false},{"name":"Azure","optional":false},{"name":"Bitbucket","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"CloudFormation","optional":false},{"name":"Cortex XDR","optional":false},{"name":"Databricks","optional":false},{"name":"DLP","optional":false},{"name":"Fine-tuning","optional":false},{"name":"GCP","optional":false},{"name":"HashiCorp Vault","optional":false},{"name":"HIPAA","optional":false},{"name":"Human-in-the-Loop","optional":false},{"name":"IAM","optional":false},{"name":"Jenkins","optional":false},{"name":"Least Privilege","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Machine Learning","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"MLFlow","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"PowerShell","optional":false},{"name":"Prisma Cloud","optional":false},{"name":"Python","optional":false},{"name":"RAG","optional":false},{"name":"SBOM","optional":false},{"name":"Semgrep","optional":false},{"name":"SIEM","optional":false},{"name":"Snyk","optional":false},{"name":"SOC 2","optional":false},{"name":"StackHawk","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Tokenization","optional":false},{"name":"Windows","optional":false},{"name":"Wiz","optional":false},{"name":"Kubernetes","optional":true}],"status":"live","first_seen_at":"2026-10-06T20:10:10Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-09T00:57:40Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Sr. Information Security Engineer\nHybrid/Remote\nAbout Reveleer\nReveleer delivers a unified platform spanning risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations navigating the complexity of value-based care. Trusted by 80+ customer organizations nationwide, the platform integrates data, analytics, and intelligent workflow automation into one governed system designed to support traceable documentation across diagnoses, quality measures, and submissions. With regulatory expertise and transparent, human-in-the-loop AI at its core, Reveleer supports organizations working to advance care quality, strengthen documentation integrity, and sustain the operational readiness needed to navigate audits with confidence.\nPosition Summary\nThe Senior Information Security Engineer plays a key role in safeguarding Reveleer's cloud-based healthcare SaaS platforms, AI/ML systems, infrastructure, and customer data. This position designs, implements, and manages enterprise-grade security solutions aligned to HIPAA, HITRUST, SOC 2, NIST 800-53, and NIST AI RMF. Because Reveleer's platform relies heavily on AI and large language models to process clinical data, this role carries direct responsibility for securing AI pipelines, models, and the PHI that flows through them. The ideal candidate is a hands-on technologist with depth in cloud security, AI/LLM security, application security, DevSecOps, identity, and security automation. \nCloud and Infrastructure Security\nDesign and maintain secure architectures across AWS, Azure, and GCP, with emphasis on infrastructure-as-code security (Terraform, CloudFormation) and policy-as-code enforcement (OPA, Sentinel, AWS SCPs). \nImplement guardrails using AWS Security Hub, GuardDuty, Macie, Inspector, Config, Azure Defender for Cloud, and native IAM controls. \nOperate CSPM/CNAPP tooling (e.g., Wiz, Prisma Cloud, Orca) to detect misconfigurations, toxic combinations, and exposed PHI data stores. \nSecure containerized and serverless workloads across EKS/ECS and Lambda, including image scanning, admission control, runtime protection, and least-privilege task roles. \nEnforce network segmentation, TLS/encryption standards, and centralized key and secrets management (AWS KMS, Secrets Manager, HashiCorp Vault). \nAI and Machine Learning Security\nPartner with Data Science and AI Engineering to secure model development, training, fine-tuning, inference, and RAG pipelines that handle PHI and PII. \nApply the OWASP Top 10 for LLM Applications and MITRE ATLAS to threat model AI features, addressing prompt injection, insecure output handling, training data poisoning, model and data exfiltration, and excessive agency in agentic workflows. \nImplement AI gateway, guardrail, and content-filtering controls (e.g., Bedrock Guardrails, Azure AI Content Safety, LLM firewalls) along with input/output validation, rate limiting, and prompt and completion logging for audit. \nGovern third-party and foundation model usage: vendor security review, data residency and retention terms, zero-retention and no-training contractual controls, and BAA coverage for any AI service touching PHI. \nEstablish controls against shadow AI, including discovery of unsanctioned generative AI tools, DLP policies for AI endpoints, and enterprise-approved alternatives. \nSecure the ML supply chain: model and artifact provenance, signed models, dependency scanning for ML libraries, notebook and MLOps platform hardening (SageMaker, Databricks, MLflow). \nContribute to AI governance alongside Compliance and Legal, mapping controls to NIST AI RMF, ISO/IEC 42001, HITRUST AI assurance criteria, and emerging state and federal AI regulation. \nApplication and SaaS Security\nEmbed security into CI/CD pipelines with SAST, DAST, SCA, secrets scanning, and IaC scanning (Snyk, StackHawk, Semgrep, etc). \nPerform threat modeling, secure design reviews, and code reviews for microservices, APIs, and AI-enabled features. \nSecure API and machine-to-machine authorization patterns (OAuth 2.0, OIDC, mTLS, scoped service tokens) across internal and partner integrations. \nManage software supply chain risk through SBOM generation, dependency governance, and artifact signing. \nDrive penetration testing, bug bounty intake, and remediation validation; track findings to closure with Engineering. \nEnsure PHI and PII protection across SaaS platforms through data classification, tokenization, de-identification, and DLP. \nEndpoint and Identity Security\nManage and tune EDR/XDR platforms (Palo Alto Cortex XDR, Microsoft Defender for Endpoint), including detection engineering and response automation. \nImplement identity security through Microsoft Entra ID, Conditional Access, PIM, and risk-based authentication; advance phishing-resistant MFA and password less adoption. \nGovern non-human identities, service principals, workload identities, and AI agent credentials with least privilege and short-lived tokens. \nSupport Intune and MDM compliance baselines for Windows, macOS, iOS, and Android; apply CIS Benchmarks and configuration drift monitoring. \nOperate SaaS security posture management (SSPM) for third-party app integrations and OAuth grant risk. \nSecurity Operations and Incident Response\nMonitor and triage alerts, investigate incidents, and coordinate response with the SOC and MDR partners. \nBuild and maintain detection content in the SIEM, including detection-as-code, log pipeline coverage, and MITRE ATT&CK mapping. \nDevelop incident response runbooks, playbooks, and forensic procedures, including scenarios specific to AI systems such as model misuse, data leakage through prompts, and compromised AI integrations. \nAutomate response and enrichment through SOAR workflows, Python, and PowerShell. \nParticipate in tabletop exercises, purple team activity, and post-incident reviews. \nGovernance, Risk, and Compliance\nSupport audits and evidence collection for HIPAA, HITRUST, SOC 2 Type 2, NIST 800-53, and customer security assessments; leverage compliance automation platforms. \nMaintain asset and AI system inventories, risk registers, and remediation tracking with clear SLAs. \nConduct vendor and third-party risk reviews, with added scrutiny for AI subprocessors and data flows. \nPartner with Compliance to keep technical controls, policies, and standards in alignment. \nContribute to security awareness and training, including secure and responsible AI use guidance for employees and engineers. \nQualifications\nRequired:\nBachelor’s degree in Computer Science, Information Security, or equivalent experience. \n5+ years of experience in security engineering or related technical security roles. \nStrong knowledge of cloud-native security (AWS, Azure, GCP) and modern SaaS architectures. \nHands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation. \nFamiliarity with HIPAA, HITRUST, NIST, and SOC 2 requirements. \nExperience securing containerized and serverless workloads (e.g., EKS, Lambda). \nPreferred:\nCertifications such as CISSP, CISM, CCSP, AWS Security Specialty, or GIAC (GSEC, GCIA, GCIH). \nExperience with Terraform, Ansible, or CloudFormation for infrastructure-as-code security. \nExperience in DevSecOps pipelines and tools (e.g., Jenkins, Bitbucket). \nStrong scripting skills (Python, PowerShell, or Bash). \nKey Competencies\nAnalytical and detail-oriented with strong problem-solving skills. \nAbility to balance business needs with risk mitigation. \nExcellent communication skills, able to translate complex technical topics for non-technical stakeholders. \nCollaborative team player with a proactive approach to continuous improvement. \nWHAT YOU’LL RECEIVE:\nCompetitive salary\nMedical, Dental and Vision benefits\n401k match\nGenerous PTO plan\nOur compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.\nReveleer E-Verifies all new hires.\nReveleer is an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, disability status or genetic information, in compliance with applicable federal, state and local law.","description_format":"text","description_chars":8348,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["401k plan"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Revenue Cycle & Medical Billing","Health Data & Interoperability"],"lifecycle":[{"event":"open","at":"2026-10-06T21:14:13Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 3","filings_12m":3,"filings_prev_12m":0,"green_card_filings_12m":0,"median_offered_wage_usd":182500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":0}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":38,"reasons":["conf:1","velocity","win:early"],"computed_at":"2026-10-08T05:49:30Z"},"pay":null,"html_url":"https://alion.io/job/reveleer-sr-information-security-engineer","json_url":"https://alion.io/job/reveleer-sr-information-security-engineer.json","meta":{"generated_at":"2026-10-09T03:18:49Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1822,"day_limit":5000,"remaining_today":3178,"minute_limit":60,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":7698},"rest":"https://alion.io/mcp/rest/get_company?id=7698"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Freveleer-sr-information-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Freveleer-sr-information-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Freveleer-sr-information-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/reveleer-sr-information-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Freveleer-sr-information-security-engineer"}]}