Cybersecurity Engineer – AWS & Healthcare Compliance
Fully Remote
Description

AdaptX is searching for a Cybersecurity Engineer to join our team. This person will have 3–5 years of

experience securing cloud infrastructure in AWS, ideally within a healthcare or highly regulated

environment. The ideal candidate combines hands-on technical security engineering skills with a strong

understanding of SOC 2 compliance frameworks and healthcare data protection requirements

(HIPAA/HITRUST). This person will play a key role in protecting patient data, maintaining audit readiness,

and hardening our cloud environment against evolving threats. They will thrive in a fast-paced, startup

environment.


Key Responsibilities:

  • Design, implement, and maintain security controls across AWS infrastructure (IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, WAF, etc.)
  • Monitor cloud environments for security events, misconfigurations, and anomalous activity; respond to and remediate incidents
  • Support and maintain SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination
  • Ensure infrastructure and application security practices align with HIPAA and other healthcare regulatory requirements
  • Conduct vulnerability assessments, penetration test coordination, and remediation tracking
  • Implement and manage security automation (Infrastructure as Code security scanning, CI/CD pipeline security gates)
  • Perform risk assessments on new AWS services, third-party integrations, and vendor relationships (especially those touching PHI)
  • Develop and maintain security policies, procedures, and incident response playbooks
  • Collaborate with engineering, DevOps, and compliance teams to embed security into the SDLC
  • Support internal and external audits (SOC 2, HITRUST, HIPAA risk assessments)
  • Manage secrets, encryption key lifecycle, and access control reviews
  • Stay current on emerging threats, AWS security services, and regulatory changes affecting healthcare data



Requirements
  • 3–5 years of experience in cybersecurity engineering, cloud security, or a related role
  • Strong hands-on experience securing AWS environments (IAM policies, Security Groups, VPC design, encryption, logging/monitoring services)
  • Practical experience supporting SOC 2 audits (Type I and/or Type II) control implementation, evidence gathering, or remediation
  • Experience with PHI/PII and understanding of HIPAA Security Rule requirements
  • Familiarity with security frameworks such as NIST CSF, NIST 800-53, or HITRUST CSF
  • Experience with security monitoring/SIEM tools (e.g., Splunk, Datadog, AWS Security Hub, GuardDuty)
  • Experience managing and securing SaaS productivity and identity platforms such as Google Workspace, JumpCloud, Vanta, or similar tools, including configuration hardening, access governance, and integration with broader security monitoring
  • Scripting proficiency (Python, Bash, or similar) for automation and tooling
  • Strong experience with Infrastructure as Code (Terraform, CloudFormation) and associated security scanning tools
  • Solid grasp of network security, encryption standards, and identity/access management principles
  • Working knowledge of AI and machine learning technologies, particularly frontier/large language models, including an understanding of their associated security, privacy, and governance considerations
  • Strong written and verbal communication skills, including ability to translate technical risk into business terms

Nice-to-Have qualifications:

  • Relevant certifications: AWS Certified Security – Specialty, CISSP, CISA, CCSP, or HCISPP
  • Experience in a healthcare, health-tech, or life sciences organization
  • Familiarity with HITRUST certification processes
  • Experience with container security (ECS/EKS) and serverless security (Lambda)
  • Exposure to GRC tooling (Vanta, Drata, OneTrust, or similar)
  • Experience responding to real-world security incidents in a production healthcare environment


AdaptX is an equal opportunity employer. All applicants will receive consideration for employment

without regard to age, ancestry, color, family, medical care leave, gender identity or expression, genetic

information, marital status, medical condition, national origin, physical or mental disability, political

affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any

other characteristic protected by applicable laws, regulations, and ordinances. AdaptX does not exclude

people or treat them differently because of race, color, national origin, age, disability, or sex. AdaptX

provides reasonable accommodation to all applicants to apply for positions and to all employees to

perform essential functions of their roles.

AdaptX offers a comprehensive, industry-competitive benefits package, which includes medical, dental,

and vision insurance as well as flexible paid time off. The salary range for the role is $110,000-$130,000.