# Cloud Security and Infrastructure Engineer

**Company:** [Chamber Cardio](https://hotfix.jobs/companies/chamber-cardio)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** AWS, IAM, Guardduty, Security Hub, Cloudtrail, Kms, Inspector, Control Tower, Organizations, Vpc, ECS, EKS, AWS Lambda, HIPAA, Cis
**Posted:** 2026-07-30

> Build and mature AWS cloud security program and infrastructure for a cardiology platform company. Own security architecture, detection/response, HIPAA compliance, and infrastructure decisions balancing security, cost, and reliability.

## Job Description

## Key Responsibilities
- Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls (SCPs, secrets management, encryption, runtime threat detection) across multiple AWS accounts.
- Build automated detection and response pipelines, using AI tools to turn security findings into fast, actionable remediation.
- Maintain GitHub-based CI/CD pipelines and automation frameworks alongside the engineering team.
- Lead cross-functional security initiatives, embedding threat modeling and security reviews into the architecture and development lifecycle.
- Own vulnerability management, AWS security posture monitoring, incident detection and response, and HIPAA compliance programs.
- Shape cloud architecture decisions — balancing security, cost, and reliability — around zero-trust and defense-in-depth principles.
- Review and document the workflows, staffing, and tooling for each active care program, and produce a written summary of gaps and immediate priorities.

## First 90 Days
- Complete a security/configuration gap analysis against CIS, HIPAA, and existing tooling (AWS Inspector, Security Hub, Datadog).
- Identify automation opportunities and standardize AWS account deployment using Control Tower.
- Validate SIEM logging ingestion and flag gaps.
- Evaluate next-gen vulnerability scanners and build a comparison scorecard.

## Requirements
- 5+ years of hands-on AWS cloud security and infrastructure engineering (IAM, network security, threat detection, compliance) in production — ideally including building a security program from scratch.
- Deep fluency with AWS security services (GuardDuty, Security Hub, Config, CloudTrail, KMS, Inspector) and IAM policy design.
- Experience with multi-account AWS governance (Control Tower, Organizations, VPC/network design) and container/serverless infrastructure (ECS, EKS, Lambda).
- Familiarity with security frameworks and compliance standards (CIS, HIPAA, HITRUST, AWS Well-Architected).
- US Citizenship is required.

## Nice-to-Haves
- Experience building a security program from scratch.
- Familiarity with Datadog, GitHub CI/CD, AI tools for security remediation.

## Similar jobs

- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Security Engineer](https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f) - hud - San Francisco, CA
- [Abuse Research Engineer](https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264) - Stripe - Remote
- [Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e5c4fc22-2c3a-4334-8eae-e8ab5bcf2a8a) - Anthropic - San Francisco, CA - $300k – $320k/yr

**Apply:** https://hotfix.jobs/jobs/0ed9ae6e-cf90-45ea-a1cc-6e89d41e8baf
**Canonical:** https://hotfix.jobs/jobs/0ed9ae6e-cf90-45ea-a1cc-6e89d41e8baf