- Company Name
- Prenuvo
- Job Title
- Staff Security Engineer
- Job Description
-
**Job Title**
Staff Security Engineer
**Role Summary**
Lead the design, modernization, and hardening of mission‑critical backend services, authentication infrastructure, and API gateways. Drive secure coding, threat modeling, and compliance (HIPAA, ISO 27001, SOC 2) across CI/CD, IaC, and runtime environments, while mentoring engineering teams on secure practices and privacy‑centric design.
**Expectations**
- 10+ years of backend/platform engineering with a strong focus on application and infrastructure security.
- Proven experience with OAuth 2.0, OpenID Connect, Auth0 (or equivalent) at scale.
- Demonstrated ability to architect secure, scalable ingress patterns (AWS API Gateway, forward‑auth proxies).
- Deep knowledge of secure coding, vulnerability management, and cloud security best practices.
- Familiarity with HIPAA, ISO 27001, SOC 2, and translating regulatory requirements into technical controls.
- Strong communication, leadership, and cross‑functional collaboration skills.
**Key Responsibilities**
- Architect and modernize core backend services and authentication systems.
- Redesign Auth0 integration using best‑practice patterns (forward‑auth, tokenization, fine‑grained scopes).
- Lead transition of services behind AWS API Gateway, designing secure, scalable ingress.
- Triage and remediate security findings from tools such as Aikido, Vanta, AWS Inspector.
- Define and enforce secure defaults and infrastructure policies across CI/CD, IaC, and runtime.
- Conduct threat modeling for new features; develop reusable models and playbooks.
- Collaborate with product, compliance, and DevOps to ensure HIPAA, ISO 27001, and other standards are met.
- Mentor engineers on secure coding, security review processes, and privacy‑conscious design.
- Own or influence authentication flows (OAuth 2.0, OpenID Connect), identity federation, and permission boundaries.
**Required Skills**
- Expertise in Python (FastAPI or Flask) and modern CI/CD tools (GitHub Actions, CircleCI).
- Experience with secure session management, OAuth 2.0 proxies (OAuth2 Proxy, Traefik, or custom).
- Hands‑on implementation of API Gateway patterns and edge‑level authentication/authorization.
- Knowledge of secure coding practices, vulnerability lifecycle, and incident response (RCA, remediation).
- Familiarity with infrastructure‑as‑code (Terraform, Pulumi, AWS CDK) and automated policy enforcement (OPA, Aikido, Vanta).
- Experience with containerized environments and tools like LocalStack or containers.dev.
- Strong communication, leadership, and ability to navigate ambiguity.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Security certifications (e.g., CISSP, CISM, AWS Certified Security – Specialty) preferred.