Staff Security Engineer
Quick Summary
guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product. Publish the org's AI-security standard and drive its adoption by other engineering teams.
SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.
SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. We are a small team, and each engineer owns a domain. This role is our senior technical anchor for the two areas where we most need depth as the team grows: AI security and threat detection and response.
On the AI security side, you will own how SmarterDx adopts AI and agentic tooling safely. That includes the guardrails for agentic access to our cloud and data, the security of the AI and ML workloads in our product, and the standards other engineering teams follow so that most AI adoption can happen without a security engineer in the room. On the detection side, you will own our detection platform (Panther), our detection strategy and coverage, and our incident response readiness. As the most senior security IC on the team, you will also be a resource across cloud and code security reviews, and you will mentor teammates who are still building their security depth.
**This role is fully remote within the US**
Responsibilities
~2 min read- →Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of the AI and ML workloads in our product.
- →Publish the org's AI-security standard and drive its adoption by other engineering teams.
- →Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources, and the standards that keep detections high-signal as we grow.
- →Own incident-response readiness: the plan, the playbooks, and tested tabletops tied to the HIPAA breach-notification timeline, and help lead response when a real incident happens.
- →Lead complex security work across teams from start to finish, resolving ambiguity and coordinating with Platform, Engineering, and Compliance.
- →Act as the senior security resource across cloud security and security reviews, and the security expert other engineering teams seek out for guidance on high-stakes decisions.
- →Mentor teammates who are growing their security depth, set team standards for detection authoring and code review, and help raise our interview and hiring bar.
- →Build and grow security automation that gives a small team more reach, and contribute to the tooling the team runs on.
- →Take part in architecture reviews and threat modeling on our highest-risk designs, and communicate the resulting security architecture so the whole team can understand it and build on it.
- 8+ years in security and software engineering, with deep hands-on experience in AWS and cloud-native infrastructure, including working competence with containerized workloads (EKS) and infrastructure-as-code (Terraform).
- A track record of leading complex security work across teams and making other engineers more effective.
- Depth in AI and agentic security: securing LLM applications, agentic frameworks, and MCP, plus prompt-injection and agentic-access defenses.
- Depth in threat detection engineering: designing, authoring, and tuning detections in a modern SIEM, and reasoning about coverage against real threats.
- Incident-response experience, including building the plan and running the response.
- The ability to write production code (Python, Go, or TypeScript) and build security tooling, not only configure products.
- Strong writing and communication; you can publish a standard other teams adopt and explain a hard design to a non-security audience.
- Working knowledge of SOC 2 and HIPAA, and the judgment to design controls that hold up without stalling delivery.
- Experience mentoring and leveling up other engineers.
Nice to Have
~1 min read- Recognized AI-security work: published standards or research, contributions to AI-security tooling, or red-teaming of AI/LLM systems.
- Startup experience, especially in health tech or another regulated, data-sensitive environment.
- Deeper specialization in container security (Kubernetes/EKS, Helm) or in infrastructure-as-code and policy-as-code, beyond working competence.
- Experience consolidating or retiring a security platform with a measurable cost or coverage result.
- Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
- Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
- Languages: Go, Python, TypeScript
- AI and automation: Claude, MCP, and agentic tooling used across engineering
What We Offer
~1 min read$230k to 250k base salary
#LI-Remote
Location & Eligibility
Listing Details
- Posted
- July 21, 2026
- First seen
- July 21, 2026
- Last seen
- July 22, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 76%
- Scored at
- July 21, 2026
Signal breakdown

SmarterDx leverages AI to enhance hospital revenue integrity by accurately analyzing patient data and uncovering missed revenue opportunities.
View company profilePlease let Smarterdx know you found this job on Jobera.
3 other jobs at Smarterdx
View all →Explore open roles at Smarterdx.
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.