Base Career helps you apply smarter for this job.
Key skills for this role
Perform secure code reviews across Python/Django/FastAPI, Node.js, and React/TypeScript codebases.
Threat model new features and services; identify design-level risks before they ship. Own SAST, DAST, dependency, secret, and container scanning — including triage, false-positive reduction, and driving fixes to closure.
Run white-box (source-assisted), grey-box (authenticated, partial-knowledge), and black-box (external, zero-knowledge) security testing against our own applications and APIs.
Test authentication, authorization, multi-tenant isolation, and session handling; hunt for IDOR, privilege escalation, and tenant data leakage.
Review API security: input validation, rate limiting, authorization enforcement, and data exposure. Define and maintain secure coding standards; coach engineers through review rather than mandate.
Harden AWS infrastructure — IAM least privilege, VPC and network segmentation, security groups, encryption at rest and in transit, S3 and RDS controls.
Review Terraform and infrastructure-as-code for security defects; add policy-as-code guardrails. Secure containerized workloads (Docker, ECS/Fargate or EKS) — image hygiene, runtime configuration, secrets handling.
Own secrets management practices (AWS Secrets Manager, SOPS, Vault) and key rotation. Continuously audit cloud configuration drift and remediate exposure.
Build and tune detection and alerting across cloud, application, and access logs. Investigate security alerts; separate real signal from noise.
Lead incident response — containment, forensics, root cause, and blameless post-incident review. Maintain and exercise the incident response plan, including breach-notification readiness. Run vulnerability management end to end: discovery, risk-based prioritization, SLA tracking, verification.
Own the engineering side of HIPAA and SOC 2 — implement controls, produce evidence, and support audits.
Maintain audit logging, access review, data retention, and encryption controls. Support security questionnaires, customer security reviews, and third-party/vendor assessments. Coordinate external penetration tests and drive remediation of findings.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Bellevue, USA
Gurugram, IND
Gurugram, IND
Gurugram, IND
Bellevue, USA
Bellevue, USA
, USA
, USA
Gurugram, IND
Keep security policies and technical documentation accurate as systems change.
Embed security checks into CI/CD (GitHub Actions) so issues surface at pull-request time. Write Python and shell automation for evidence collection, configuration auditing, and remediation.
Build tooling and guardrails that make the secure path the easy path for engineers. Improve identity and access management across cloud, SaaS, and internal tooling.
Partner with engineering, DevOps, and product teams as an embedded security reviewer. Run practical security training and awareness for engineering.
Communicate risk clearly to both technical and non-technical audiences, with a recommendation attached.
Use modern AI tools to accelerate code review, detection engineering, and analysis.
Apply AI-assisted practices while maintaining rigorous verification, data-handling, and review standards.
Assess and secure the organization’s own use of AI services, including data-exposure risk.
Bachelor’s or Master’s degree in Computer Science, Information Security, or a related discipline. 6+ years in cybersecurity, with substantial application security or cloud security ownership. Strong AWS security experience — IAM, VPC networking, encryption, logging, and common misconfiguration patterns.
Ability to read and reason about production code; Python strongly preferred, plus JavaScript/TypeScript.
Hands-on web application and API security testing (OWASP Top 10, OWASP API Security Top 10) using black-box, grey-box, and white-box approaches.
Ability to write up findings with reproducible steps, impact, severity rationale, and a concrete remediation path.
Practical experience with SAST/DAST/SCA and container scanning tooling, including triage and remediation.
Working knowledge of Docker and container orchestration (ECS/Fargate or EKS). Experience with vulnerability management and incident response in production environments. Familiarity with HIPAA, SOC 2, or equivalent compliance frameworks.
Solid Linux fundamentals, networking, and cryptography basics.
Clear written and verbal English; ability to document findings and risk decisions precisely.
Secure Code Review (Python / Django / FastAPI, Node.js, React / TypeScript) Threat Modeling (STRIDE or equivalent)
OWASP Top 10 / OWASP API Security Top 10
Authentication, Authorization, Multi-Tenant Isolation
Black-Box / Grey-Box / White-Box Penetration Testing
Manual Exploitation and Proof-of-Concept Development
SAST / DAST / SCA, Secret and Dependency Scanning
Burp Suite, OWASP ZAP, Semgrep, Trivy, and similar tooling
AWS IAM, VPC, Security Groups, KMS, GuardDuty, Security Hub, CloudTrail, Config ECS / Fargate / EKS Workload Security
Terraform Security Review, Policy as Code (OPA, Checkov, tfsec)
Secrets Management (AWS Secrets Manager, SOPS, Vault)
Network Segmentation and Perimeter Controls
SIEM / Log Analytics and Detection Engineering
Incident Response and Digital Forensics
Vulnerability Management and Risk-Based Prioritization
Audit Logging, Access Review, Monitoring and Alerting
Encryption at Rest and in Transit, Key Management
PHI / PII Handling, Data Classification, Retention
HIPAA, SOC 2, HITRUST, NIST CSF, ISO 27001
Vendor and Third-Party Risk Assessment
PostgreSQL Security and Access Control
Kafka / Redpanda / Amazon MSK, Redis
GitHub Actions and CI/CD Security
Python and Shell Automation
Security certifications — OSCP, CISSP, AWS Security Specialty, GIAC (GWAPT, GCIH, GCSA), or CEH.
Experience securing multi-tenant SaaS platforms and tenant-isolation models. Prior experience carrying a SOC 2 Type II audit or HIPAA program through to completion. Offensive security background — black-box penetration testing, red teaming, or bug bounty experience.
Experience scoping and managing third-party black-box or grey-box penetration tests. Kubernetes security.
Experience with event-driven architectures and message-broker security.
Detection-as-code and security automation at scale.
Exposure to healthcare technology or other regulated domains.
Experience securing AI/LLM-integrated applications.
Genuine hands-on depth — you find real issues, not just scanner output.
Engineering mindset: you fix and automate rather than only report.
Sound risk judgment and the ability to prioritize what actually matters.
Strong collaboration; engineers should want your review, not dread it.
Precise written communication and clean documentation.
Integrity, discretion, and ownership when handling sensitive data.
Continuous learning as the threat landscape moves.
Security ownership of a healthcare platform where the stakes are real.
Breadth across application, cloud, and operational security in one role.
Modern stack: AWS, Terraform, GitHub Actions, Docker, Python, React, PostgreSQL, Kafka compatible messaging.
Direct influence on architecture and engineering practice, not a downstream audit function.
Dental software company providing an all-in-one operations, analytics, communications, payments, and marketing platform for dental practices.
Visit company websiteJobs and hiring trendsFull-time
Senior · 6+ years experience
Onsite
Apply faster on company sites with our extension.