Security Engineer

About the Role
Security is a core part of the Medplum platform. We build open source healthcare infrastructure that stores and processes sensitive health information for healthcare organizations ranging from startups to large enterprises.
As a Security Engineer at Medplum, you will work across our application, cloud infrastructure, developer tooling, and security operations to identify vulnerabilities and make our systems more secure.
This is a hands-on engineering role. You might investigate a suspicious production event, review an authorization change, improve our vulnerability scanning, build security automation, analyze AWS logs, fix a security bug, or implement a new control required by one of our security and compliance programs.
You will work closely with Medplum's engineering team and company leadership on real-world security problems across a large and rapidly evolving healthcare platform.
What You Will Do
Find and Fix Security Issues
Investigate vulnerabilities across the Medplum stack and work directly with engineers to remediate them.
Perform security reviews of new features and architecture changes, analyze authentication and authorization behavior, investigate dependency and infrastructure vulnerabilities, and help improve defensive controls throughout the platform.
Build Security Tools and Automation
Build tools that make Medplum easier to secure.
Improve vulnerability detection, dependency scanning, cloud security monitoring, audit logging, secrets management, security testing, and other automated controls. Look for opportunities to replace repetitive security and compliance work with software.
Investigate Security Events
Participate in security incident response and forensic investigations.
Analyze application, infrastructure, database, and cloud logs; reconstruct relevant system activity; help determine impact; and work with the broader team to remediate issues and improve future detection.
Improve Application and Cloud Security
Work across our TypeScript applications and AWS infrastructure to strengthen Medplum's security architecture.
Help improve authentication and authorization, multi-tenant isolation, network security, infrastructure configuration, secure development practices, and production monitoring.
Support Security and Compliance
Help maintain the technical controls behind Medplum's security and compliance programs, including SOC 2, HIPAA, HITRUST, and other healthcare requirements.
Work with engineers, auditors, and company leadership to gather evidence, address findings, and implement controls that improve both security and compliance.
Help Customers Understand Medplum Security
Assist with technical security questions from customers and partners. Help investigate customer-reported issues, explain relevant parts of the Medplum architecture, and contribute to security documentation and technical responses.
About You
- You are a strong engineer with a serious interest in security.
- You have experience in application security, cloud security, infrastructure security, security engineering, or backend software engineering.
- You are comfortable reading and debugging production code.
- You understand common web and API security issues including authentication, authorization, injection, SSRF, XSS, CSRF, secrets management, and dependency vulnerabilities.
- You are comfortable working with Linux, networking, SQL databases, and cloud infrastructure.
- You enjoy investigating ambiguous technical problems and following evidence until you understand what happened.
- You like automating repetitive work rather than relying on manual processes.
- You write clear technical documentation and can communicate security findings constructively to other engineers.
- You take ownership of problems and are comfortable operating in a fast-moving startup environment.
- You have 3+ years of experience in security engineering, software engineering, infrastructure engineering, or a related technical role.
- You're based in the SF Bay Area and available for twice-weekly in-person collaboration.
Bonus
- Experience with TypeScript or Node.js.
- Experience with AWS, Kubernetes, PostgreSQL, or Redis.
- Experience with application security or secure code review.
- Experience with incident response, security monitoring, or digital forensics.
- Experience with OAuth 2.0, OpenID Connect, or complex authorization systems.
- Healthcare or health-tech experience.
- Familiarity with HIPAA, SOC 2, HITRUST, or other compliance frameworks.
- Experience working on open source software.
- Experience securing multi-tenant SaaS platforms.
About Medplum
Medplum is redefining healthcare with our open source, API-first electronic health record (EHR) platform, trusted by leading digital health and life sciences companies. Our mission is to catalyze change in the healthcare industry by improving the access, privacy, and utility of health data. At Medplum, we have a unique opportunity to impact the lives of patients, speed medical research, and contribute to the open source ecosystem.
Benefits
- Competitive compensation package with equity
- Flexible time off
- Inclusive healthcare package
- The chance to shape the future of healthcare tech – leave your mark on this vital industry
Join us in our mission to revolutionize healthcare. If you're excited about solving difficult security problems, building secure infrastructure, and protecting systems that support millions of patients, we'd love to hear from you. Reach out to careers@medplum.com.