New opportunity
Cybersecurity Engineer
About the company
We are a young and fast-growing recruiting company with five years of experience working across Latin America and the United States. We partner closely with teams and founders to help them build strong, high-impact teams through recruitment, outsourcing, and team-building services.
Our culture is built on effective communication, trust, and transparency. We believe great work happens when people feel heard, supported, and empowered to grow. Today, our team is made up of more than 80 professionals working across different projects throughout the region, collaborating remotely and learning from each other every day.
About the role
We’re looking for a Senior Cybersecurity Engineer to help harden a live clinical platform running across Azure and multiple applications that handle Protected Health Information (PHI).
This is a hands-on security remediation role, focused on closing critical security findings, strengthening access controls and auditability, establishing the technical foundation for HIPAA compliance, and validating security controls throughout the project.
You’ll work closely with application engineering, infrastructure, and client leadership teams, taking ownership of security requirements from technical definition through implementation, validation, and final sign-off.
Responsibilities
- Lead the remediation of critical security findings, including replacing shared database credentials with individual directory-based authentication and securing administrative access through VPN or bastion infrastructure.
- Design and implement reliable audit controls across all applications and data exports, ensuring events are complete, attributable, protected from unauthorized deletion, and stored in an appropriate audit-log destination.
- Design fine-grained, patient-level authorization models so users can only access the records they are authorized to view, working closely with backend engineers on implementation.
- Define the technical inputs required for the HIPAA risk analysis and establish the security specifications and evidence needed to support the process.
- Strengthen PHI protection by removing sensitive patient data from logs, emails, and uncontrolled exports, implementing appropriate retention and access controls, and securing credentials used by companion services and scripts.
- Drive remediation of application security gaps including rate limiting, account lockout, authentication configuration, stored XSS, sender verification, and secure file-transfer configurations.
- Define security guardrails for LLM and AI integrations involving sensitive data, minimizing unnecessary PHI exposure and establishing appropriate controls for each integration.
- Define infrastructure security requirements covering network access, private endpoints, key management, and dedicated compute, and validate their implementation with the SRE team.
- Lead security validation throughout project milestones, including security checks, penetration testing, remediation, and retesting.
- Build and maintain an inventory of third-party systems and business associates that have access to PHI, supporting the client's broader HIPAA compliance efforts.
- Communicate security risks, remediation status, technical requirements, and security obligations clearly to engineering teams and client leadership.
Requirements
- Senior experience in application and cloud security, with strong hands-on experience securing Azure environments.
- Practical knowledge of Microsoft Entra ID, Azure Key Vault, private networking, database access controls, and cloud security architecture.
- Proven experience remediating security findings in production, particularly around authentication, authorization, audit logging, credentials, and access control.
- Strong working knowledge of HIPAA technical and administrative safeguards, including what a HIPAA risk analysis requires and how to produce supporting evidence.
- Experience designing fine-grained authorization models, ideally at patient, record, or resource level.
- Strong OWASP-aligned application security knowledge, with enough Python/Django familiarity to guide and review fixes in a production codebase.
- Experience defining and implementing secure LLM/AI integrations involving sensitive or regulated data.
- Strong evidence-based reporting skills and the ability to explain technical security obligations clearly to client leadership.
- Comfortable working hands-on with engineering and infrastructure teams to drive remediation through implementation and validation.
Nice to have
- Experience securing healthcare, clinical, EMR, or other regulated platforms.
- Experience with SIEM and centralized audit logging.
- Experience coordinating penetration tests, remediation, and retesting.
- Familiarity with EMR integrations and the security risks associated with direct database access by third-party systems.
- Experience with Business Associate Agreements (BAAs) and third-party PHI access inventories.
- Spanish proficiency.
Benefits
- People First culture
- Referral Program
- Free access to streaming platforms
- Free access to Spotify Premium
- GYM discount
- Travel discount
- E-Learning discount
- Birthday-day gift
- Points Program