Senior Security Engineer

About AgelessRx

AgelessRx is a first-of-its-kind, longevity-focused telehealth platform with an e-commerce component. Our mission is to collectively give people millions of extra healthy years, so everyone can enjoy more of what they love in a world where people are empowered to live as long as they want. We believe aging should no longer be treated as a dreadful inevitability, but instead, as a puzzle that can be solved, a fight that can be fought – just as a disease with a cure. Through our free-to-use platform, we offer trusted, data-driven longevity solutions and scientifically backed prescription therapies to help safely lower the risk of age-related diseases. 

About the role

AgelessRx is seeking a hands-on, highly capable Senior Security Engineer to serve as the technical owner of information security across our growing telehealth environment. As a healthcare company, protected health information (PHI) flows through much of what we build and operate, making security, privacy, and regulatory compliance fundamental to our products, infrastructure, and internal systems.


This is a broad security engineering role with meaningful ownership across application and product security, cloud infrastructure, identity and access management, vulnerability management, security operations, and technical security governance. This person will help define AgelessRx's security roadmap, build and operate the recurring programs that keep the company secure and audit-ready, and partner directly with Engineering to identify and mitigate risk throughout the development lifecycle.


The Senior Security Engineer will also serve as a key technical partner in AgelessRx's approach to AI security and governance. As AI becomes increasingly embedded across our products and internal operations, this person will help ensure AI tools and systems are deployed responsibly, securely, and in accordance with AgelessRx's obligations as a healthcare organization.


This is not a compliance-only role. We are looking for someone who can move comfortably between strategy and execution: reviewing a sensitive code path or investigating a vulnerability one day, establishing an access-control standard or evaluating an AI vendor the next, and translating technical and regulatory risk into clear recommendations for leadership.

What you'll do

Security Program & Risk Management

  • Own and continuously evolve AgelessRx's technical security roadmap, prioritizing initiatives based on risk, business impact, regulatory requirements, and company growth.
  • Establish and operate repeatable security programs, controls, reporting, and documentation across the organization.
  • Conduct and document security and architecture reviews for new systems, vendors, integrations, and significant technology changes.
  • Maintain visibility into security risks, vulnerabilities, remediation priorities, owners, and timelines.
  • Conduct and support security risk assessments, including those required under the HIPAA Security Rule.
  • Maintain audit-ready evidence and documentation supporting AgelessRx's technical security controls.
  • Plan and facilitate recurring security and incident-response exercises, including scenarios involving PHI exposure or other material security events.
  • Provide leadership with a clear, actionable view of the company's security posture, priorities, open risks, and remediation progress.

Identity, Cloud & Infrastructure Security

  • Define security requirements and technical standards for identity, authentication, authorization, and privileged access across AgelessRx.
  • Partner with the IT Administrator to implement and maintain SSO, MFA, privileged access management, endpoint controls, and other workforce security requirements.
  • Assess and strengthen cloud infrastructure, IAM configurations, external attack surfaces, and administrative access.
  • Own the vulnerability-management program across cloud infrastructure, endpoints, applications, and other relevant technology, including prioritization and remediation SLAs.
  • Maintain and strengthen email security and authentication controls, including DMARC, SPF, and DKIM.
  • Partner with IT on recurring access reviews and ensure identified exceptions or inappropriate access are remediated.
  • Establish security requirements for company devices and endpoints while partnering with IT on implementation and ongoing administration.

Application & Product Security

  • Embed security into AgelessRx's software development lifecycle and engineering practices.
  • Conduct security reviews of architecture, authentication flows, sensitive data handling, payments, and other security-sensitive areas of the product.
  • Develop threat models for new products, features, services, and integrations, particularly those involving PHI or other sensitive information.
  • Deploy, configure, and continuously improve application-security tooling, including SAST, SCA, dependency scanning, and software supply-chain controls.
  • Establish clear processes for reviewing, prioritizing, and remediating application-security findings.
  • Develop and maintain secure development standards, guardrails, and practical guidance for engineers.
  • Scope and coordinate third-party penetration testing and drive identified findings through remediation and closure.
  • Establish and operate an appropriate vulnerability disclosure and triage process.
  • Partner with Engineering early in the development process so security risks are identified before they reach production without unnecessarily slowing engineering velocity.

Healthcare Security & Compliance

  • Maintain technical security documentation and evidence required to demonstrate the effectiveness of AgelessRx's safeguards.
  • Support HIPAA risk analyses, audits, investigations, incident response, and other regulatory or compliance activities requiring technical security expertise.
  • Partner with Legal, Compliance, HR, Engineering, and other stakeholders to ensure security requirements are appropriately incorporated into company systems and processes.
  • Evaluate security considerations associated with vendors and partners handling PHI or other sensitive company information, including technical security posture and BAA-related requirements.
  • Monitor changes to security and technology requirements affecting AgelessRx and help translate them into actionable technical controls.

AI Security & Governance

  • Serve as the technical security owner for AgelessRx's AI governance program in partnership with Legal, Compliance, HR, Engineering, Product, and other stakeholders.
  • Maintain visibility into AI systems and tools that access PHI, patient information, proprietary company information, or other sensitive data.
  • Establish and maintain technical security requirements for the use of AI across AgelessRx, including controls designed to prevent PHI or sensitive information from reaching unapproved AI systems.
  • Conduct security and risk assessments of AI tools and vendors before deployment, including data flows, retention, model-training practices, access controls, subprocessors, and other relevant risks.
  • Partner with Legal and Compliance on AI vendor requirements, including BAAs and AI-specific data protection considerations.
  • Extend security review and threat modeling to AI-enabled products and features, including risks such as prompt injection, inappropriate model access, data leakage, output handling, and exposure of PHI through prompts, logs, or model outputs.
  • Partner with Legal and Compliance to monitor evolving AI requirements affecting healthcare, patient-facing technology, privacy, accessibility, and security and translate applicable requirements into technical controls.
  • Help align AgelessRx's AI risk-management practices with an appropriate recognized framework and maintain supporting evidence.
  • Review and implement approved MCPs and other AI-related integrations in accordance with company security and technology policies.
  • Partner with HR, Compliance, and other stakeholders on the implementation and enforcement of company policies governing employee use of AI tools.

Qualifications

  • 5+ years of experience in security engineering, cybersecurity, or a related technical security role.
  • Hands-on depth across at least two major security domains, such as application/product security, cloud and identity security, vulnerability management, security operations, or security governance.
  • Experience securing environments subject to HIPAA or comparable regulatory requirements and translating regulatory obligations into technical controls.
  • Strong working knowledge of at least one major cloud provider and associated IAM and security practices.
  • Strong understanding of identity and access management, including SSO, SAML/OIDC, MFA, privileged access, and least-privilege principles.
  • Experience with application-security tooling and practices, including SAST, SCA, dependency management, threat modeling, and secure software development.
  • Experience establishing or operating recurring security programs such as vulnerability management, access reviews, penetration testing, security assessments, or incident-response exercises.
  • Experience assessing and prioritizing vulnerabilities based on exploitability, business impact, sensitive-data exposure, and practical risk - not simply severity scores.
  • Working understanding of AI/LLM security risks and the challenges associated with governing AI systems in regulated environments.
  • Strong written communication and documentation skills, particularly for audiences that may include engineers, executives, auditors, regulators, and non-technical stakeholders.
  • Ability to operate autonomously and establish structure in an environment where security processes and infrastructure are still evolving.

PREFERRED QUALIFICATIONS

  • Direct experience conducting HIPAA Security Rule risk analyses, preparing for OCR audits, or supporting healthcare security investigations or breach response.
  • Experience securing healthcare technology, telehealth platforms, EHR integrations, or HL7/FHIR-based systems.
  • Experience building or significantly maturing a security program as an early or first dedicated security hire.
  • Experience implementing AI governance or AI risk-management programs, including familiarity with NIST AI RMF, ISO/IEC 42001, or similar frameworks.
  • Experience evaluating AI vendors or systems that process PHI or other regulated data.
  • Familiarity with emerging healthcare and AI regulatory requirements.
  • Experience with containerization platforms such as Docker.
  • Relevant security certifications such as OSCP, HCISPP, CISSP, or cloud-security certifications are valued but not required.

El rango de pago para este puesto es el siguiente:

155,000 - 170,000 USD por year (Remote (United States))

QA

Remote (United States)

Compartir en:

Términos de servicioPrivacidadCookiesPatrocinado por Rippling