Security Engineer
Ai Code Security
Application Security
Cloud Native Application Protection Platform
Cloud Native Security
Cloud Platforms
Cloud Security
Cloud Security Posture Management
Cloud Workload Protection
Data Security
DevSecOps
Engineer
Information Security
InfoSec
Security
Security Automation
Security Engineer
Security Operations
Security Standards
Security Testing
Software Security
Job Description
The Security Engineer role supports RVO Health’s Security team by strengthening the organization’s security posture and safeguarding sensitive data in a cloud-native environment. This position focuses on building security controls, integrating security into CI/CD workflows, and supporting incident response and continuous improvement.
Key Responsibilities
- Design, implement, and maintain security controls and architectures to protect cloud infrastructure, applications, and data from cyber threats.
- Strengthen cloud security posture and vulnerability management, including pull-request scanning, triage and tracking of findings through closure with engineering teams, and coverage and license optimization.
- Develop and enforce software supply chain controls across the developer toolchain, including package, dependency, and extension guardrails, with enforcement thresholds tuned to reduce noise.
- Extend security into CI/CD pipelines, including governance of AI-authored code at the pipeline chokepoint.
- Build security automation, internal tooling, and integrations against the developer platform and security stack so security controls are self-service rather than ticket-driven.
- Partner with Platform and Software Engineering teams to provide visibility and awareness of security issues and collaboratively prioritize remediation.
- Conduct security assessments such as code reviews and application security testing to identify and mitigate risk in new and changing systems.
- Participate in a weekly on-call rotation for managed detection and response escalations, investigating potential threats, responding to incidents, and performing root cause analysis.
- Develop and maintain security standard operating procedures and policies aligned with industry best practices and regulatory requirements, including HIPAA and NIST CSF.
- Stay current on application and infrastructure vulnerability tactics, techniques, and procedures, with emphasis on the healthcare space, and adapt strategy or tooling to address emerging threats.
Required Qualifications
- Bachelor’s degree in Computer Science, related field, or equivalent experience.
- Minimum 4+ years of experience in application security, cloud security, or a related cybersecurity role.
- Solid understanding of cloud security principles, architectures, and services (AWS or Azure preferred).
- Hands-on experience with cloud security posture management or CNAPP tooling (examples: Wiz, Orca, Prisma Cloud), including driving vulnerability findings to closure with engineering teams.
- Experience building security automation, tooling, and integrations, with working proficiency in at least one scripting or programming language.
- Working knowledge of secure coding practices.
- Knowledge of security frameworks, standards, and regulations (examples: NIST CSF, HIPAA, MITRE ATT&CK).
- Strong problem-solving and analytical skills with the ability to make sound, critical decisions.
- Experience in incident response and recovery.
Preferred Qualifications
- Professional certifications (examples: CISSP, CCSP, OSCP, GIAC).
- Expertise in AWS security controls, monitoring, and orchestration (examples: SCPs, GuardDuty, Config, Macie).
- Working familiarity with Terraform, GitHub, and DevSecOps workflows, particularly securing GitHub Actions and other CI/CD pipelines.
- Experience securing AI- or LLM-assisted development workflows, including reviewing AI-generated code at scale.
- Experience with internal developer platforms or portals (example: Backstage).
- Experience working alongside an MDR or managed SOC provider.
Technologies
- AWS
- Azure
- Wiz
- Orca
- Prisma Cloud
- HIPAA
- NIST CSF
- MITRE ATT&CK
- Terraform
- GitHub
- GitHub Actions
- CNAPP
Compensation and Benefits
- Starting Salary: $100,000 - $130,000*
- Health Insurance Coverage (medical, dental, and vision)
- Life Insurance
- Short and Long-Term Disability Insurance
- Flexible Spending Accounts
- Paid Time Off
- Holiday Pay
- 401(k) with match
- Employee Assistance Program
- Paid Parental Bonding Benefit Program
- Pharmacy Benefits
- Income Protection Plans
- Pet Services Plans
- Mental Health Support
- Wellness Coaching
- HSA - Health Savings Account
- Commuter Benefits
- Gym & Fitness Center Discount Program
*Note: Actual salary is based on geographic location, qualifications and experience.
Work Location
- Minneapolis, MN (Hybrid)
- Office collaboration: Tuesday through Thursday each week
- Remote flexibility: Mondays and Fridays (optional)
- Address: 11000 Optum Cir Eden Prairie, MN 55344
State Pay Act Summary
Starting salary is summarized as $100,000 - $130,000*, with eligibility for health and insurance benefits and other listed compensation elements. Actual salary depends on geographic location, qualifications, and experience.