Compliance & Regulatory Expertise:
● Lead efforts to ensure all healthcare applications and infrastructure meet stringent
compliance requirements, including US PII, HIPAA, HITRUST, and other relevant healthcare
regulations.
● Develop and implement security controls and processes to achieve and maintain HITRUST
certification readiness.
● Participate in compliance audits, provide evidence, and address findings related to security
controls.
● Stay abreast of evolving healthcare regulations and industry best practices to proactively
adapt security strategies.
● FDA Clearance Exposure: Work on or have exposure to the security aspects required for FDA
clearance processes for medical devices or software as a medical device (SaMD), ensuring
security documentation and controls align with regulatory expectations.
Cloud Security Architecture & Implementation (AWS Focus):
● Design, build, and secure AWS platform infrastructure using IaC (CloudFormation /
Terraform).
● Implement and manage security controls across AWS environments (IAM, KMS, Secrets
Manager, Network Firewall, WAF).
● Build automated security guardrails and compliance checks using AWS Security Hub, Config,
and IAM Access Analyzer.
● Develop secure CI/CD pipelines, including automated policy checks, vulnerability scans, and
artifact integrity validation for healthcare applications.
● Implement centralized logging and monitoring using CloudWatch, SIEM tools (e.g., Splunk,
Sumo Logic), GuardDuty, and VPC Flow Logs, with a focus on HIPAA-compliant logging.
● Collaborate with application and DevOps teams to define secure architecture patterns,
network segmentation, and zero-trust controls for healthcare workloads.
Security Operations & Governance:
● Conduct regular security assessments, risk reviews, and threat modeling for workloads
hosted on AWS and integrated with Epic.
● Enforce tagging standards, data-classification controls, and lifecycle policies across AWS
resources, particularly for PHI.
● Support incident response activities, root-cause analysis, remediation planning, and
post-incident improvements, with a focus on PHI breach protocols.
● Document platform security design, runbooks, best practices, and alignment with enterprise
security standards and healthcare regulations.
● Manage and integrate security tools such as SIEM, DLP, Cloud Proxy, CASB, or Isolation
systems when relevant to AWS workloads and Epic integrations.
● Provide training and guidance to engineering teams on secure AWS usage, identity
governance, and least-privilege access within a healthcare context.
● Experience integrating AWS environments with Security Operations Centers (SOC) for
real-time alerting, threat detection, and incident escalation workflows, specifically for
PHI-related events.
Basic Qualifications (BQ):
● Overall 8-10 years of Experience in cloud platform/security engineering, with at least 3-5
years specifically in cloud security/cybersecurity.
● Deep, hands-on expertise with Epic modules and their security configurations, including
integration points with UI applications.
● Proven experience with US PII, HIPAA, HITRUST, and other compliance requirements for
regulatory healthcare applications.
● Experience working on or exposure to FDA clearance processes, particularly the security
aspects.
● Deep knowledge of AWS security services: IAM, KMS, Security Hub, GuardDuty, AWS Config,
VPC Security, WAF, Network Firewall.
● Strong understanding of cloud security models, zero-trust principles, least privilege,
encryption, data protection, and network security fundamentals.
● Hands-on experience with either of IaC tools: CloudFormation, Terraform, CDK.
● Proficiency in scripting languages such as Python or Bash for automation.
● Experience setting up centralized logging, SIEM integrations, and security event monitoring,
with a focus on audit trails for PHI.
● Strong understanding of CI/CD security, artifact scanning, secrets management, and pipeline
hardening.
● Knowledge of network security tools and concepts: firewalls, proxies, routing, segmentation,
DLP, isolation appliances.
● Familiarity with compliance frameworks (GDPR, HIPAA, PCI, SOC2) and ability to enforce
security baseline standards.
● Strong analytical and troubleshooting skills to resolve platform and security issues.
● Excellent communication and collaboration skills to work across cross-functional
engineering and security teams, including clinical and compliance stakeholders.
● Exposure to advanced data protection practices such as data classification, DLP controls,
encryption strategy design, and secure data lifecycle management for PHI.
Preferred Qualifications (PQ):
● Experience securing multi-cloud (AWS + GCP/Azure) environments.
● Experience with container security for ECS/EKS (image scanning, runtime protection, IAM
roles for tasks).
● Knowledge of SIEM platforms like Sumo Logic, Splunk, or Datadog.
● Experience with AWS Macie, Detective, and advanced data governance solutions.
● Exposure to zero-trust security, identity federation, and SSO (Azure AD/Okta).
● Familiarity with incident response processes and playbook automation (SOAR).
● Experience designing isolation, or exfiltration-prevention controls.
● Additional security certifications (CISSP, CISM, CCSP, AWS Security Specialty).
● Understanding of SOC processes, including Tier-1/2/3 triage, playbook execution, case
management, ticketing systems, and threat intelligence enrichment.
● Hands-on knowledge of security incident management, including detection, investigation,
containment, eradication, recovery, and post-incident reviews.
● Experience with other healthcare-specific security frameworks or standards (e.g., NIST CSF
for Healthcare).
● Familiarity with Epic's security architecture and best practices documentation.