Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer image - Rise Careers
Job details

Senior Security Engineer

At Bluesight, our mission is to create groundbreaking solutions that increase efficiency, safety and visibility for health systems, hospital pharmacy, and pharmaceutical manufacturers.  We empower our customers to deliver the right medicine to the right patient at the right time, every time.  We are a high growth healthcare information technology company with a start-up 'vibe' but over 2,000 customers using our proven solutions.



Bluesight is looking for a talented and experienced Senior Security Engineer to join our team. As a member of the team, you can expect to work in a highly visible, cross-functional role. As an engineer on this team, you’ll play an advisory role across the whole company, and you’ll help all Bluesight product teams build secure-by-default architectures, triage issues, and remediate vulnerabilities on their systems.


As Senior Security Engineer, you’ll be responsible for building scanning and threat detection systems to monitor Bluesight’s AWS cloud deployment and other digital assets. You’ll train all Bluesight employees on security best practices, conduct risk assessments of new vendor integrations and product launches, and develop internal protocols, controls, and relationships to ensure customer assurance and trust. Most importantly, you’ll build and maintain core standards around security, privacy, and confidentiality, reflected in our compliance certifications, and the automation to monitor and enforce these standards across Bluesight.


We’re excited to share with you our passion for building scalable and secure products for our healthcare customers. Your perspective and experience will help shape our team’s goals. You will be responsible for contributing to, operating, and improving all things related to our security and compliance requirements for SOC2, HIPAA, CGMP.


Bluesight is a fully remote company, this position and open to qualified applicants in the continental United States who are eligible to work in the United States without Visa sponsorship.




Representative Duties:
  • Build and manage, well-architected and relevant cloud-based data classification and threat detection systems for assessing and resolving risk vectors
  • Partner with internal product teams to implement a secure-by-default design into their own products
  • Perform security audits and risk assessments, identify vulnerabilities, and create plans and preventative measures to protect against threats. 
  • Assist with responses to customer questions, questionnaires, and contract issues regarding compliance and security.
  • Conduct reviews, train employees and advise on matters related to security and compliance across Bluesight
  • Lead security incident response teams and partner with Bluesight engineering teams to understand and resolve incidents that arise 
  • Promote a culture of operational excellence by monitoring our systems and code, and being on-call to support the health of our services
  • Design security policies and procedures that will keep pace with the rapid growth of Bluesight
  • Document your work and decision-making processes, and lead presentations and discussions in a way that is easy for others to understand
  • Uphold a culture of collaboration, transparency, creativity, inclusion, and making data-driven decisions


Qualifications and Requirements:
  • 5+ years of experience in product or infrastructure security-related software engineering roles
  • Proficiency in a programming language, testing practices, and thorough documentation
  • Expertise with multiple technologies in the Bluesight Security System and our infrastructure as required: Cloud-based IaaS Systems - AWS required, Vulnerability Mgmt. and Scanning (such as Nessus, OpenVAS)SIEM and logging technology (such as Splunk, Elastic, LogRhythm, SolarWinds)Enterprise VPN (such as Cisco AnyConnect, Fortinet VPN, Palo Alto Global Protect)Host-based security tools (such as Sophos, ClamAV, Wazuh/OSSEC, Tripwire)
  • Experience developing, implementing, and monitoring internal practices for SOC2, HIPAA or ISO information security compliance standards
  • Ability to represent Bluesight’s security posture and the maturity of our operations to customers
  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company
  • Track record of building self-service and high-quality tools with a customer-driven mindset
  • A desire to share your expertise through documentation and mentorship
  • A desire to work with individuals with diverse security ideas and priorities
  • Autonomy and proactivity around driving work to completion in the face of ambiguity


Preferred qualifications:
  • Experience with cybersecurity frameworks such as NIST 800-53, CIS and CSF
  • Experience securing data in a regulated industry (HIPAA, FDA CGMP)
  • Any code, writing or projects that are public or shareable demonstrating your experience, understanding or approach to security and compliance


$110,000 - $130,000 a year
This is the standard base pay range for this role. In addition to a base salary, this position is also eligible for an amazing benefits package. The actual amount of salary offered will vary depending on the position level, experience, performance, and location. This position is fully remote and open to applicants in the continental United States.

This position is a remote position and open to qualified applicants in the continental United States who are eligible to work in the United States without Visa sponsorship.

This position is a remote position and open to applicants in the continental United States.


Why Bluesight?

Bluesight’s culture is built on innovation and teamwork. There’s room to grow and opportunities to take initiative. You will partner with sharp, motivated teammates looking to disrupt a massive industry—and have fun doing it.  We truly believe that where you work and what you do matters.  Join us as we revolutionize the hospital pharmacy landscape!

-Competitive salary

-Time off when you need it – unlimited vacation days!

-Generous insurance coverage

-401k program with a company match

-Fun, collaborative culture!


EOE AA M/F/VET/Disability


All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, religion, color, national origin, sex, protected veteran status, disability, or any other basis protected by federal, state or local laws.

Bluesight Glassdoor Company Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Bluesight DE&I Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Bluesight
Bluesight CEO photo
Kevin MacDonald
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$110000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer, Bluesight

At Bluesight, we're on a mission to revolutionize the healthcare industry with innovative technology that maximizes safety and efficiency for health systems, hospital pharmacies, and pharmaceutical manufacturers. We're seeking a passionate and experienced Senior Security Engineer to join our dynamic remote team. This is a highly visible role where you'll collaborate across various departments to design secure architectures from the ground up, triage security issues, and address vulnerabilities in our systems. Your responsibilities will include developing threat detection systems to monitor our AWS cloud deployment and other digital assets, while also training fellow employees on best security practices. You'll conduct risk assessments with new vendors and product launches, build strong internal protocols, and carry the torch for security standards and compliance certifications such as SOC2 and HIPAA. In this role, your expertise will shape our security roadmap, fostering a culture of operational excellence while guiding and mentoring team members through both training and hands-on security incident responses. By partnering with Bluesight’s dedicated engineers and product teams, you'll help ensure that our systems are not only secure but also maintain the trust of our valued customers. Join us and be a part of this exciting journey as we combine large-scale healthcare solutions with advanced security measures, all in a collaborative, fun environment that values innovation and growth.

Frequently Asked Questions (FAQs) for Senior Security Engineer Role at Bluesight
What are the responsibilities of a Senior Security Engineer at Bluesight?

As a Senior Security Engineer at Bluesight, you will take on crucial responsibilities such as building and managing threat detection systems, performing security audits and risk assessments, training employees on security best practices, and actively collaborating with product teams to implement a secure design. Your role will also involve developing compliance protocols to maintain our adherence to SOC2, HIPAA, and CGMP standards.

Join Rise to see the full answer
What qualifications are needed for the Senior Security Engineer position at Bluesight?

To qualify for the Senior Security Engineer role at Bluesight, candidates should have at least 5 years of experience in software engineering related to product or infrastructure security. Proficiency in programming, understanding threat detection technologies like AWS and vulnerability management tools, and experience with compliance standards are essential. Additionally, a strong ability to assess risks and articulate security needs is crucial.

Join Rise to see the full answer
How does Bluesight promote a culture of security and compliance?

At Bluesight, one of the key responsibilities of the Senior Security Engineer is to cultivate a culture of security and compliance across the organization. This is achieved by conducting regular training for employees, leading security incident response efforts, and developing clear security policies and procedures that adapt to our growth while providing assurance to customers regarding our compliance certifications.

Join Rise to see the full answer
What technologies will I work with as a Senior Security Engineer at Bluesight?

As a Senior Security Engineer at Bluesight, you will work with various cutting-edge technologies. Some examples include AWS for cloud-based infrastructure, vulnerability management tools like Nessus and OpenVAS, logging solutions like Splunk and Elastic, and enterprise VPN technologies. Your role will involve integrating these tools to create a secure environment for our healthcare solutions.

Join Rise to see the full answer
What are the benefits of working remotely as a Senior Security Engineer at Bluesight?

As a fully remote company, Bluesight offers flexibility and work-life balance for its Senior Security Engineers. You'll enjoy benefits like unlimited vacation days, generous insurance coverage, a 401k program with a company match, and the opportunity to work in a collaborative culture that emphasizes creativity and excellence, all while contributing to impactful healthcare solutions.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer
Can you explain your experience with security compliance standards such as SOC2 or HIPAA?

When answering this question, provide specific examples of how you've developed, implemented, or monitored practices for compliance with SOC2, HIPAA, or similar standards. Highlight your role in audits, your understanding of the requirements, and any direct impact your work had on your organization's compliance posture.

Join Rise to see the full answer
What threat detection and vulnerability management tools are you familiar with?

Identify tools you're experienced with, such as Nessus, OpenVAS, or any SIEM solutions. Discuss how you have used these tools in previous roles, any challenges you faced, and how you overcame them to enhance security measures.

Join Rise to see the full answer
How do you approach building secure architectures for cloud-based systems?

Discuss your methodology for integrating security in the design phase. Mention specific principles such as the principle of least privilege, secure coding practices, and proactive vulnerability assessments that you have found effective in your work.

Join Rise to see the full answer
Can you describe a security incident you managed and the outcome?

Detail an actual incident, your immediate responses, team collaboration, and lessons learned. Explain how you coordinated with various stakeholders and what improvements were made to prevent similar issues in the future.

Join Rise to see the full answer
How do you stay updated on the latest security threats and trends?

Mention resources such as security blogs, forums, online courses, and conferences you attend. Illustrate your commitment to continuous learning and how you apply newly learned information to your role.

Join Rise to see the full answer
How would you handle a disagreement with a product team regarding security protocols?

Share your approach to conflict resolution, emphasizing open communication and collaboration. Describe a scenario where you successfully navigated a difference of opinion and how you ensured that security needs were met in the final plan.

Join Rise to see the full answer
What experience do you have with training employees on security best practices?

Discuss your approach to designing and delivering training programs. Provide examples of the topics you've covered, the impact of your training, and feedback received from team members.

Join Rise to see the full answer
Can you outline your process for conducting a risk assessment?

Walk through your systematic approach to risk assessment, including how you identify, analyze, evaluate, and prioritize risks. Share any methodologies or frameworks you use to document and communicate risk findings.

Join Rise to see the full answer
How do you incorporate feedback and improve security practices?

Explain your mindset regarding feedback, whether from audits, incidents, or team members. Provide an example of how you've adapted practices based on constructive criticism and the results of those changes.

Join Rise to see the full answer
What are your thoughts on the importance of diversity in cybersecurity teams?

Articulate your understanding of how diverse perspectives enhance problem-solving in cybersecurity. Share any personal experiences you have had working on diverse teams and how it has led to more innovative security solutions.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Customer-Centric
Mission Driven
Inclusive & Diverse
Work/Life Harmony

Join Bluesight as a Clinical Customer Training Manager, where you'll enhance hospital pharmacy training and user engagement with cutting-edge IT solutions.

Posted 2 hours ago

As a Network Engineer II at Stifel, you will be integral in managing and optimizing our network infrastructure to support our investment banking firm.

Photo of the Rise User
Lyell Immunopharma Hybrid Seattle, Washington, United States
Posted 11 days ago

Lyell is seeking a passionate Senior Engineer in Data and Analytics to enhance their cloud-based data analytics platform supporting innovative cancer therapies.

Photo of the Rise User
Posted 2 days ago

Join our dynamic team as a Database Administrator, where you will manage and optimize database systems to enhance our data-driven efforts.

Quantum Dynamics, Inc. Hybrid Lackland AFB, San Antonio, Texas, United States
Posted 4 days ago

Join Quantum Dynamics as an Information Assurance Technician, providing crucial IT support within a military environment at Lackland AFB.

Photo of the Rise User

Join the University of Maryland Medical System as a Senior Clinical Informaticist to lead innovative healthcare informatics initiatives within a hybrid work environment.

Photo of the Rise User

Join Desjardins as a Programmer Analyst to enhance IT efficiency through the development and maintenance of innovative software solutions.

Photo of the Rise User
Posted 10 days ago

Saviynt seeks an experienced Director of Information Security to advance their FedRAMP compliance strategies in a dynamic, remote environment.

Clear Capital is looking for a Cloud Security Engineer with a focus on AWS security to help safeguard our cloud environment.

Transform the health system pharmacy supply chain through software, connecting hospitals and manufacturers from production through utilization of medications.

24 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Flexible CultureBadge Future MakerBadge Work&Life BalanceBadge Rapid Growth
CULTURE VALUES
Customer-Centric
Mission Driven
Inclusive & Diverse
Work/Life Harmony
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 23, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!