Gifthealth Inc
Cloud Security Engineer
Columbus, OH
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 26 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Description
About Us
At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.
Position Summary
We are seeking a Cloud Security Engineer to design, implement, and maintain security controls across the organization's cloud infrastructure and cloud-native technology environments. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.
This role partners with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams to establish secure cloud architectures, identify cloud risks, implement preventative controls, and continuously improve the organization's cloud security posture.
The Cloud Security Engineer serves as the primary technical security resource for cloud infrastructure and helps ensure security controls are scalable, automated, and integrated into the way cloud environments are designed and operated.
Key Responsibilities
Cloud Security Architecture:
- Develop and maintain security standards and reference architectures for cloud environments.
- Participate in architecture reviews for new cloud services, platforms, and major infrastructure changes.
- Evaluate proposed architectures for security risks and recommend appropriate controls.
- Establish secure patterns for cloud networking, identity, encryption, logging, storage, compute, and managed services.
- Evaluate the security boundary between AWS-managed infrastructure and externally managed platforms (e.g., Heroku, Snowflake) to ensure consistent controls across both.
Cloud Security Posture Management:
- Identify insecure cloud configurations and excessive permissions.
- Continuously assess cloud environments against established security standards and benchmarks.
- Prioritize cloud security findings based on technical severity and business risk.
- Partner with system owners to remediate cloud security findings.
- Identify systemic issues that can be addressed through platform-level controls.
Cloud Identity and Access Security:
- Work with IAM teams to establish least-privilege access models for cloud resources.
- Review cloud roles, permissions, service accounts, and privileged access.
- Identify excessive, unused, or risky cloud privileges.
- Establish controls for administrative and privileged cloud access.
- Support secure workload identity and service-to-service authentication patterns.
Cloud Security:
Develop security controls for:
- Compute workloads
- Storage
- Databases
- Networking
- Serverless services
- VPN and remote access infrastructure (Site-to-Site and client VPN)
- Data warehouse platforms (e.g., Snowflake, BigQuery)
- APIs
- Secrets and key management
- Establish secure configuration baselines.
- Work with engineering teams to implement cloud security guardrails.
Cloud Detection and Monitoring:
- Ensure appropriate cloud logging and security telemetry is available for security monitoring.
- Develop or assist with detections for suspicious cloud activity.
- Partner with Security Operations to investigate cloud security events.
- Improve visibility into administrative activity, authentication, workload behavior, and configuration changes.
Infrastructure-as-Code and Automation:
- Embed cloud security requirements into Infrastructure-as-Code.
- Develop automated checks and preventative security controls.
- Build reusable secure cloud modules and templates with engineering teams.
- Use APIs, scripts, and cloud-native services to automate security processes.
Cloud Vulnerability Management:
- Support vulnerability management across cloud infrastructure and workloads.
- Identify vulnerable cloud resources, operating systems, containers, and services.
- Coordinate remediation with infrastructure and engineering teams.
- Help distinguish vulnerabilities requiring immediate remediation from findings better addressed through compensating controls or risk acceptance.
Governance and Security Standards:
- Develop and maintain cloud security standards and technical requirements.
- Map cloud controls to applicable security and compliance requirements.
- Provide technical evidence for audits and assessments when needed.
- Evaluate new AI-enabled cloud services (e.g., Amazon Q) for security and data-handling implications before broader rollout.
Qualifications
Education: Not specified as a requirement; we evaluate demonstrated hands-on experience.
Licensure/Certification: Not required. Relevant AWS, cloud security, Kubernetes, or security certifications are a plus.
Experience: 3+ years of experience in cloud engineering, cloud security, infrastructure engineering, DevOps, security engineering, or a related field.
Knowledge, Skills, and Abilities:
- Hands-on experience securing environments within at least one major public cloud platform. Gifthealth's AWS environment hosts VPN infrastructure, Redis, Amazon Q, and core security/logging tooling, while the primary application runs on Heroku (a separate PaaS), so comfort securing that kind of hybrid boundary is valuable.
- Strong understanding of cloud IAM, networking, encryption, secrets management, logging and monitoring, compute and storage security, vulnerability management, and cloud-native security services.
- Ability to secure workloads across a hybrid environment that spans direct cloud infrastructure (AWS) and externally managed platforms (e.g., Heroku, Snowflake).
- Experience scripting or automating infrastructure and security activities, with an understanding of least privilege and cloud-native identity models.
- Ability to evaluate cloud architectures and communicate security requirements clearly to technical teams.
- Demonstrated application of the above Qualification
- Preferred: strong AWS security experience, including multi-account cloud environments.
- Preferred: experience with Kubernetes, containers, or serverless technologies. Gifthealth's core application currently runs on Heroku rather than Kubernetes.
- Preferred: experience with Cloud Security Posture Management or Cloud-Native Application Protection platforms, and familiarity with CIS cloud benchmarks, NIST guidance, or other cloud security frameworks.
- Preferred: familiarity with VPN architectures (Site-to-Site and client VPN) for secure remote and third-party access.
- Preferred: experience implementing column-level masking, row-level security, or PHI field-level governance in analytics warehouses such as Snowflake or BigQuery. This is an active initiative at Gifthealth as data infrastructure migrates to Snowflake.
- Preferred: experience with Infrastructure-as-Code such as Terraform or CloudFormation and building preventative cloud guardrails using policies, automation, or IaC (confirm current IaC tooling with the Infrastructure team, as usage across the AWS estate hasn't been fully verified), plus experience working within regulated environments.
Measures of Success
Success in this role includes:
- Cloud security requirements are incorporated into architecture before systems are deployed.
- High-risk cloud misconfigurations and excessive permissions are identified and remediated.
- Security controls increasingly operate as automated guardrails rather than manual reviews.
- Cloud environments have reliable security logging and monitoring coverage.
- Cloud vulnerabilities and configuration findings have clear ownership and remediation paths.
- Secure cloud patterns are documented and reusable by engineering teams.
- Security becomes a standard part of cloud architecture and platform engineering decisions.
Work Environment
Location:
Similar jobs
- AI Security Engineer, AWS Security - AISecAmazon · Austin, Texas, USAFirst seen today
- Application Security EngineerAmazon · Arlington, Virginia, USAFirst seen today
- Information Systems Security Engineer (Active DOD Secret Clearance required)CompQsoft Inc. - ACTIVE · KITTERY, MEFirst seen today
- Software Product Security Engineer - HP IQHp · San Francisco, California, United States of AmericaFirst seen today
- Systems Security Engineer I – Anti-Tamper / Program Protection (On-site)Globalhr · US-AZ-TUCSON-801 ~ 1151 E Hermans Rd ~ BLDG 801 (External Site)First seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job