Lead Security Engineer
Job description
Lead Security Engineer at Hinge Health.
About the role
You will architect and enforce security guardrails that protect the platform enabling millions to move beyond musculoskeletal pain. You will operate at the forefront of AI-assisted development, designing frameworks that secure AI-powered code generation, automated pull request reviews, agent sandboxing, and MCP gateway integrations. This role demands you partner deeply with Application Security, SRE, and R&D Engineering to embed security-by-design across our AWS infrastructure, CI/CD pipelines, and developer tooling. You will ensure that security never impedes velocity but instead provides the confidence to innovate rapidly and safely. This is your opportunity to directly improve patient outcomes and advance healthcare security at scale.
Key facts
What you'll do
Perform threat modeling and risk assessments for new AI-assisted development workflows and infrastructure changes before implementation.
Design and implement identity and access management strategies that enforce least privilege across AWS accounts and microservices.
Develop security policies and guardrails for AI tools, including secure agent sandboxing, prompt validation, and data handling protocols.
Conduct in-depth security audits of the AWS environment, identifying misconfigurations and exposure risks in compute, storage, and networking layers.
Build and maintain security monitoring, detection, and response capabilities tailored to cloud-native and AI-driven engineering workflows.
Collaborate with SRE and R&D teams to integrate security checks directly into CI/CD pipelines without disrupting developer experience.
Evaluate and integrate AI security tooling to automate vulnerability detection, compliance checks, and anomaly detection.
Define standards and runbooks for managing AI model APIs, MCP servers, and third-party integrations securely.
Partner with Application Security to coordinate penetration testing, vulnerability remediation, and secure code review processes.
Lead incident response efforts for cloud and AI-related events, ensuring timely mitigation and clear communication across stakeholders.
Create technical documentation and training materials to educate engineering teams on secure development practices and AI safety.
Drive the adoption of security metrics and key performance indicators to measure the effectiveness of security controls.
Work closely with compliance stakeholders to ensure all implementations meet HIPAA, SOC 2, and other relevant regulatory requirements.
Continuously research emerging threats, including adversarial machine learning, supply chain risks, and infrastructure vulnerabilities.
Serve as the primary security advisor for major platform initiatives, influencing architecture decisions from the earliest stages.
Requirements
Bachelor's degree in a technical, engineering, or scientific field - or comparable education/experience.
3+ years in cybersecurity, with 3+ years focused on security operations or IAM.
2+ years of experience in cloud security operations, specifically AWS.
2+ years of coding experience (e.g., Python, Go, or TypeScript) with hands-on experience developing Terraform and infrastructure-as-code.
Hands-on experience securing AI/ML systems, including data pipelines, model deployments, API integrations, and their security challenges.
Must be within commuting distance to New York City.
Ability to work full-time hours in alignment with business needs, including occasional after-hours on-call responsibilities as required.
Willingness to adhere to company policies and security protocols without exception.
Demonstrated capability to lead technical projects and mentor peers through knowledge sharing and clear communication.
Nice to have
AWS Solutions Architect or Security Specialty certification.
AI/ML security certifications or familiarity with adversarial machine learning threats and mitigation strategies.
Experience building or integrating security controls into CI/CD pipelines and AI-assisted development workflows.
Experience managing an Enterprise IdP, especially Okta, with deep understanding of OAuth 2.0 and SAML.
SOC 2, PCI, or HIPAA audit/training certifications.
Knowledge of low-level networking principles.
Practical notes
Candidates must be within commuting distance to New York City.
Full-time engagement with flexibility to handle after-hours on-call as needed for security incidents.
No sponsorship is available for this role at this time.
The position requires consistent collaboration across distributed engineering and compliance teams.