Senior Engineer, IT Security
Job description
About the role
You will partner with engineering teams to design secure architectures and solutions that align with our healthcare transformation mission. You will integrate security controls directly into CI/CD pipelines, platform tooling, and application onboarding processes to enable secure delivery. You will provide technical guidance and reusable patterns that make secure development the default choice for developers. You will own and continuously improve the application onboarding and identity integration process across cloud and SaaS environments. You will translate complex security requirements into practical, scalable, and automated controls that reduce friction and increase adoption. You will collaborate closely with developers while maintaining clear ownership and accountability within the Security team. This is a hands-on engineering role focused on building and enabling secure workflows rather than performing reviews or audits. You will leverage your expertise in identity and platform security to ensure Chartis infrastructure supports innovation safely.
Key facts
What you'll do
Partner with engineering teams to design secure architectures and solutions that support scalable and reliable healthcare technology platforms.
Integrate security controls into CI/CD pipelines, platform tooling, and application onboarding processes to enable consistent and efficient secure delivery.
Provide technical guidance and reusable patterns that help development teams implement security without introducing unnecessary friction.
Own and improve the application onboarding and identity integration process to ensure lifecycle management and policy enforcement are robust and automated.
Translate security requirements into practical, scalable, and automated controls that align with cloud-native and AI-driven engineering practices.
Collaborate closely with developers, product teams, and infrastructure owners while maintaining clear ownership of security outcomes within the Security team.
Implement and manage identity and access strategies across cloud and SaaS platforms using standards such as OAuth2, OIDC, and SAML.
Design and enforce RBAC/ABAC models across cloud and SaaS environments to support least-privilege and zero trust objectives.
Perform threat modeling exercises using frameworks such as STRIDE and attack trees, and translate findings into actionable engineering controls.
Utilize Python scripting to build automation, integration tools, and operational utilities that enhance security workflows and observability.
Demonstrate hands-on administration and engineering with Microsoft Azure identity, access control, and resource governance to secure cloud-native workloads.
Apply working knowledge of AWS and Google Cloud Platform within multi-cloud environments to ensure consistent security posture across providers.
Leverage hands-on experience with Kubernetes (K8s) to manage workload identity, access controls, and platform security considerations.
Use Splunk Cloud to build alerts, dashboards, and detection logic for security-relevant events, enabling proactive monitoring and response.
Requirements
5-8+ years of hands-on experience in security engineering with a direct focus on IAM and DevSecOps practices, excluding purely advisory or oversight roles.
Demonstrated hands-on administration and engineering experience with Okta Identity Cloud (OIC), Okta Identity Governance (OIG), and Okta Workflows for application onboarding and lifecycle management.
Proven hands-on cloud administration experience in Microsoft Azure, with a strong focus on identity, access control, and resource governance.
Working knowledge of AWS and Google Cloud Platform in multi-cloud environments to support integrated security strategies.
Hands-on experience with Kubernetes (K8s), including workload identity, access controls, and platform security considerations.
Working knowledge of Splunk Cloud, including the ability to build alerts, dashboards, and detection logic for security-relevant events.
Strong understanding of modern authentication and authorization standards, including OAuth2, OIDC, and SAML, and how they apply to secure architectures.
Proficiency in Python scripting for automation, integration, and operational tooling used in security and DevSecOps workflows.
Demonstrated experience integrating security into CI/CD pipelines and infrastructure-as-code workflows to enable secure and efficient delivery.
Experience designing and implementing RBAC/ABAC models across cloud and SaaS platforms to enforce least privilege and governance.
Demonstrated experience performing threat modeling using frameworks such as STRIDE and attack trees, and translating findings into actionable engineering controls.
Ability to work effectively in a fully remote environment while collaborating with cross-functional teams across multiple time zones.
Commitment to following established security practices and contributing to continuous improvement of security processes and tools.
Willingness to engage with healthcare-focused technology challenges that impact affordability, accessibility, and safety in the US healthcare system.
Nice to have
Okta certifications, such as Okta Certified Administrator, Okta Certified Professional, or equivalent advanced certification that validates deep expertise.
Experience supporting AI/ML platforms or AI-enabled application ecosystems, including tools and workflows that integrate machine learning into production environments.
Experience with secrets management and zero trust architecture patterns that help protect sensitive data and workloads.
Experience with tools like LangSmith and other AI-related tools that support the development and monitoring of AI-driven applications.
Practical notes
This role is full-time and remote.
Compensation includes eligibility for an annual discretionary bonus in addition to the base salary range.
Benefits may include medical, dental, vision, HSA, FSA, disability insurance, life insurance, 401(k) match, paid time off, wellness stipend, and additional voluntary benefits as described in Chartis compensation materials.
Chartis offers equal opportunity employment and values diversity across race, color, religion, gender identity or expression, sexual orientation, national origin, genetics, disability status, age, marital status, or protected veteran status.