About this role.
Qventus is hiring a Senior Security Engineer to lead the design and buildout of cloud and data security tooling for a healthcare technology company. The role emphasizes security automation, policy-as-code, sensitive-data access controls, and collaboration with engineering teams. Required expertise includes cloud security fundamentals, CNAPP/CSPM or related tooling, Kubernetes security, scripting, and CI/CD or infrastructure-as-code integration. Experience securing HIPAA-regulated data in platforms such as Databricks or Snowflake is particularly relevant. This is a remote United States role with a disclosed annual salary range of $166,000 to $185,000 USD.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would first inventory data flows, classify sensitive data, and identify the cloud services, identities, and access paths involved. I would then prioritize controls around least-privilege IAM, encryption, audit logging, data-access monitoring, and continuous misconfiguration detection, mapping each control to HIPAA requirements and measurable risk reduction.
I have implemented policy checks directly in infrastructure and application delivery workflows so issues are identified before deployment. I focus on clear policies, actionable remediation messages, an exception process with expiration, and progressive enforcement so teams can adopt controls without disruptive gatekeeping.
I would assess coverage for our cloud environment and data platforms, identity and entitlement analysis, integration quality, detection fidelity, remediation workflows, API access, and support for compliance reporting. I would also validate that the tool produces prioritized findings tied to real attack paths rather than generating unmanageable alert volume.
I use layered controls: hardened cluster configuration, RBAC and workload identity, namespace isolation, network policies, image scanning and signing, admission controls, secrets management, runtime monitoring, and centralized audit logging. I also integrate these controls into CI/CD so insecure manifests and images are prevented from reaching production.
I would involve engineering teams early, explain the specific risk and tradeoffs, and make secure defaults easy to consume through templates, automation, and self-service tooling. Adoption improves when security measures reduce repetitive work, provide useful feedback, and are tracked through shared outcomes rather than imposed as standalone compliance requirements.
On this journey for over 12 years, Qventus is leading the transformation of healthcare. We enable hospitals to focus on what matters most: patient care. Our innovative solutions harness the power of machine learning, generative AI, and behavioral science to deliver exceptional outcomes and empower care teams to anticipate and resolve issues before they arise.
Our success in rapid scale across the globe is backed by some of the world’s leading investors. At Qventus, you will have the opportunity to work with an exceptional, mission-driven team across the globe, and the ability to directly impact the lives of patients. We’re inspired to work with healthcare leaders on our founding vision and unlock world-class medicine through world-class operations. #LI-MB1
About the Role
We’re looking for a Security Engineer to own the design and buildout of Qventus’ cloud and data security tooling. This role will be responsible for driving engineering security policy, collaborating with internal Qventus teams, and owning the buildout of cloud security tooling to support and improve Qventus’ security posture.
Key Responsibilities:
- Own the design, buildout, and priorities of Qventus’ cloud and data security engineering
- Collaborate with teams to automate security guardrails, not gates
- Know where our sensitive data lives and develop controls for validating secure access
- Partner with engineering teams so security is understood and owned, not imposed
What We’re Looking For
- Demonstrated ability to drive complex, ambiguous projects forward across teams collaboratively, and to communicate challenges and tradeoffs clearly
- Foundational knowledge across cloud security fundamentals: threat models, IAM, networking, encryption, access controls, phishing, and misconfiguration risks
- Working knowledge with one or more categories of cloud and data security tooling like CNAPP / CSPM (Orca, Wiz, Upwind), DSPM, CIEM, or SSPM
- Comfort with automation and scripting, whether in Python, Go, or Bash, and how to document and implement policy with those tools
- Experience implementing policy-as-code and helping integrate it into development processes, whether CI / CD, Kubernetes (via OPA), or other infrastructure-as-code tooling
- Familiarity with securing containerized workloads on Kubernetes
- A track record handling regulated data (HIPAA) in cloud data platforms like Databricks or Snowflake
Compensation for this role is based on market data and takes into account a variety of factors, including location, skills, qualifications, and prior relevant experience. Salary is just one part of the total rewards package at Qventus. We also offer a range of benefits and perks, including Open Paid Time Off, paid parental leave, professional development, wellness and technology stipends, a generous employee referral bonus, and employee stock option awards.
Salary Range
$166,000—$185,000 USD
Qventus values diversity in its workforce and proudly upholds the principles of Equal Opportunity Employment . We welcome all qualified applicants and ensure fair consideration for employment without discrimination based on any legally protected characteristics, including, but not limited to: veteran status, uniformed service member status, race, color, religion, sex, sexual orientation, gender identity, age, pregnancy (including childbirth, lactation and related medical conditions), national origin or ancestry, citizenship or immigration status, physical or mental disability, genetic information (including testing and characteristics) or any other category protected by federal, state or local law (collectively, “protected characteristics”). Our commitment to equal opportunity employment applies to all persons involved in our operations and prohibits unlawful discrimination by any employee, including supervisors and co-workers.
Qventus participates in the E-Verify program as required by law and is committed to providing reasonable accommodations to individuals with disabilities in compliance with Americans with Disabilities Act (ADA). In compliance with the California Consumer Privacy Act (CCPA), Qventus provides transparency into how applicant data is processed during the application process. Candidate information will be treated in accordance with our candidate privacy notice.
*Benefits and perks are subject to plan documents and may change at the company’s discretion.
*Employment is contingent upon the satisfactory completion of our pre-employment background investigation and drug test.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.






