
Senior Security Engineer
Sequencing · United States
- Hybrid
- Full-time
- $150,000 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Lead security for health-tech startup.
- Protect sensitive health and genomic data.
- Build security practices and tools.
- Collaborate across global, remote teams.
- Ensure compliance with HIPAA, SOC 2.
About the role
About The Position
As our first dedicated Senior Security Engineer, you will join a remote, global health‑tech team that works at the intersection of genomics, AI, and consumer health. You will report to the Head of Engineering, partner closely with DevOps, bioinformatics, and developers, and help protect highly sensitive health and genomic data as we grow. You will build security practices and your work will directly shape how the company operates and earns customer and partner trust. Success in this role means being proactive, collaborative, clear in your communication, and comfortable executing in a fast-moving, startup environment while partnering across functions and time zones.The Impact
- Lead security testing for our web apps, APIs, cloud (AWS/OCI), Kubernetes, and on‑prem servers, and clearly document vulnerabilities you find.
- Build security into our CI/CD pipelines with DevOps, including code and app scanning and stronger secrets management.
- Work with bioinformatics to secure genomic data pipelines and protect PHI/PII in line with HIPAA requirements.
- Set up and run security monitoring, alerting, and incident response, with practical playbooks and runbooks the team can follow.
- Lead the technical work needed for HIPAA, SOC 2, and ISO 27001 readiness and future audits.
- Help design and improve logging and SIEM use so the team can spot and respond to threats faster.
- Translate security findings into clear, prioritized tasks that engineering and DevOps teams can execute.
- Partner with engineers, DevOps, and bioinformatics so security is built into how we design, build, and ship systems.
- Contribute to threat modeling and secure design discussions for new and existing services.
- Maintain clear, concise security documentation, including standards, guidelines, and incident procedures.
- Support vendor and third-party security assessments by reviewing findings and driving remediation with the team.
- Provide input into security aspects of our architecture and infrastructure decisions.
- Support security aspects of our performance tasks and assessments, including translating real-world attack methods into learnings for the team.
- Help raise security awareness across the company by sharing best practices with engineers and partner teams.
- Collaborate across time zones and functions to plan, prioritize, and communicate security work and trade‑offs.
Dominant and Recessive Traits (Qualifications)
- 8+ years in security engineering, DevSecOps, or infrastructure security roles.
- Strong hands-on penetration testing and vulnerability discovery skills, using both manual methods and tools. OSCP, OSCE, or equivalent certifications are a plus; we value candidates with real-world offensive experience, not just institutional credentials.
- Deep experience securing AWS and OCI cloud and Kubernetes (RBAC, IAM, network policies, containers, secrets), as well as bare metal and on-premises server environments.
- Experience adding and tuning security tools in CI/CD (such as Semgrep, CodeQL, OWASP ZAP, Burp Suite).
- Comfortable with tools like Burp Suite, Metasploit or similar, OWASP ZAP, Semgrep or CodeQL, CloudTrail, Falco, Terraform, Docker, Git/GitHub, Cloudflare, and Google Workspace.
- Experience with SIEM or log aggregation and real‑time detection and monitoring.
- Familiarity with HIPAA, SOC 2, and how to protect PHI/PII in regulated or high-sensitivity environments.
- Clear written and verbal communication, especially for explaining security issues and recommendations to technical teams.
- Ability to influence and collaborate with engineering, DevOps, and data teams without formal authority.
- Comfortable working independently in a remote, fast-moving startup with limited existing security processes.
- Experience with eCommerce and checkout security, including securing payment flows, cart and order APIs, and protecting against fraud, skimming attacks, and checkout abuse.
- Experience with vulnerability research, responsible disclosure, or red team operations is a strong plus.
Key skills/competency
Security Engineering, DevSecOps, Cloud Security (AWS/OCI), Kubernetes Security, Penetration Testing, Vulnerability Discovery, CI/CD Security, SIEM, HIPAA, Incident Response.Skills & topics
- Senior Security Engineer
- Security Engineering
- DevSecOps
- Cloud Security
- AWS
- OCI
- Kubernetes
- Penetration Testing
- Vulnerability Management
- CI/CD Security
- HIPAA
- SOC 2
- Incident Response
- Remote
- Health-tech
How to get hired
- Tailor your resume: Highlight 8+ years in security engineering, DevSecOps, or infrastructure security, emphasizing hands-on penetration testing and cloud security experience (AWS/OCI, Kubernetes).
- Showcase relevant tools: Mention proficiency with Burp Suite, Metasploit, Semgrep, CodeQL, CloudTrail, Falco, and SIEM tools.
- Demonstrate compliance knowledge: Detail experience with HIPAA, SOC 2, and protecting PHI/PII in regulated environments.
- Emphasize collaboration and independence: Showcase your ability to influence teams without formal authority and work independently in a remote, fast-paced startup.
- Prepare for technical and behavioral questions: Be ready to discuss your offensive security experience, incident response strategies, and how you build trust in a remote setting.
Technical preparation
Practice penetration testing on cloud environments.,Build CI/CD pipelines with security tools.,Configure Kubernetes security policies.,Implement SIEM and monitoring solutions.
Behavioral questions
How do you build trust remotely?,Describe a time you influenced without authority.,How do you prioritize security risks?,How do you explain technical security issues?
Frequently asked questions
- What is the work arrangement for the Senior Security Engineer role at Sequencing?
- The Senior Security Engineer position at Sequencing is a fully remote role, allowing you to work from anywhere globally. This arrangement supports collaboration across different time zones and functions.
- What specific cloud environments does Sequencing use for its infrastructure?
- Sequencing utilizes a multi-cloud approach, with deep experience required in both AWS and OCI. You will also be working with Kubernetes, bare metal servers, and on-premises environments.
- What are the primary compliance standards Sequencing adheres to?
- Sequencing is focused on meeting stringent compliance standards, including HIPAA, SOC 2, and ISO 27001. Protecting PHI/PII is a critical aspect of this role.
- What kind of security certifications are considered a plus for this Senior Security Engineer role?
- While not strictly required, certifications like OSCP, OSCE, or equivalent are considered a plus. Sequencing values candidates with demonstrable real-world offensive security experience.
- How does Sequencing approach security within its development lifecycle?
- Sequencing integrates security into its CI/CD pipelines, working closely with DevOps. This includes code and application scanning, secrets management, and leveraging security tools like Semgrep and OWASP ZAP.
- What is the expected experience level for this Senior Security Engineer position?
- The role requires a minimum of 8 years of experience in security engineering, DevSecOps, or infrastructure security. Strong hands-on experience in penetration testing and vulnerability discovery is essential.
- How will a Senior Security Engineer at Sequencing collaborate with other teams?
- You will collaborate closely with Head of Engineering, DevOps, bioinformatics, and developers. This partnership is key to building security into systems design, development, and deployment.
- Does Sequencing have established security processes, or will this role build them?
- This role is for the first dedicated Senior Security Engineer, implying that a significant part of the job will involve building and establishing security practices and processes within the company.