AdaptX is searching for a Cybersecurity Engineer to join our team. This person will have 3–5 years of
experience securing cloud infrastructure in AWS, ideally within a healthcare or highly regulated
environment. The ideal candidate combines hands-on technical security engineering skills with a strong
understanding of SOC 2 compliance frameworks and healthcare data protection requirements
(HIPAA/HITRUST). This person will play a key role in protecting patient data, maintaining audit readiness,
and hardening our cloud environment against evolving threats. They will thrive in a fast-paced, startup
environment.
Key Responsibilities:
- Design, implement, and maintain security controls across AWS infrastructure (IAM, VPC, GuardDuty, Security Hub, CloudTrail, KMS, WAF, etc.)
- Monitor cloud environments for security events, misconfigurations, and anomalous activity; respond to and remediate incidents
- Support and maintain SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination
- Ensure infrastructure and application security practices align with HIPAA and other healthcare regulatory requirements
- Conduct vulnerability assessments, penetration test coordination, and remediation tracking
- Implement and manage security automation (Infrastructure as Code security scanning, CI/CD pipeline security gates)
- Perform risk assessments on new AWS services, third-party integrations, and vendor relationships (especially those touching PHI)
- Develop and maintain security policies, procedures, and incident response playbooks
- Collaborate with engineering, DevOps, and compliance teams to embed security into the SDLC
- Support internal and external audits (SOC 2, HITRUST, HIPAA risk assessments)
- Manage secrets, encryption key lifecycle, and access control reviews
- Stay current on emerging threats, AWS security services, and regulatory changes affecting healthcare data
- 3–5 years of experience in cybersecurity engineering, cloud security, or a related role
- Strong hands-on experience securing AWS environments (IAM policies, Security Groups, VPC design, encryption, logging/monitoring services)
- Practical experience supporting SOC 2 audits (Type I and/or Type II) control implementation, evidence gathering, or remediation
- Experience with PHI/PII and understanding of HIPAA Security Rule requirements
- Familiarity with security frameworks such as NIST CSF, NIST 800-53, or HITRUST CSF
- Experience with security monitoring/SIEM tools (e.g., Splunk, Datadog, AWS Security Hub, GuardDuty)
- Experience managing and securing SaaS productivity and identity platforms such as Google Workspace, JumpCloud, Vanta, or similar tools, including configuration hardening, access governance, and integration with broader security monitoring
- Scripting proficiency (Python, Bash, or similar) for automation and tooling
- Strong experience with Infrastructure as Code (Terraform, CloudFormation) and associated security scanning tools
- Solid grasp of network security, encryption standards, and identity/access management principles
- Working knowledge of AI and machine learning technologies, particularly frontier/large language models, including an understanding of their associated security, privacy, and governance considerations
- Strong written and verbal communication skills, including ability to translate technical risk into business terms
Nice-to-Have qualifications:
- Relevant certifications: AWS Certified Security – Specialty, CISSP, CISA, CCSP, or HCISPP
- Experience in a healthcare, health-tech, or life sciences organization
- Familiarity with HITRUST certification processes
- Experience with container security (ECS/EKS) and serverless security (Lambda)
- Exposure to GRC tooling (Vanta, Drata, OneTrust, or similar)
- Experience responding to real-world security incidents in a production healthcare environment
AdaptX is an equal opportunity employer. All applicants will receive consideration for employment
without regard to age, ancestry, color, family, medical care leave, gender identity or expression, genetic
information, marital status, medical condition, national origin, physical or mental disability, political
affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any
other characteristic protected by applicable laws, regulations, and ordinances. AdaptX does not exclude
people or treat them differently because of race, color, national origin, age, disability, or sex. AdaptX
provides reasonable accommodation to all applicants to apply for positions and to all employees to
perform essential functions of their roles.
AdaptX offers a comprehensive, industry-competitive benefits package, which includes medical, dental,
and vision insurance as well as flexible paid time off. The salary range for the role is $110,000-$130,000.