Security Engineer
Who we are
HINA is a Healthcare Technology Company that finds healthcare challenges and solves them through technology and business—from improving real work to creating new products and ventures.
Technology is not the end in itself. We combine AI, software, data and business building to create systems that help better care reach more people.
About the role
Own security across the design, development and operation of HINA’s AI products and healthcare systems. Map data flows and permissions for services handling sensitive customer data, interview recordings and transcripts, then design and implement appropriate controls.
Go beyond reporting findings: agree remediation with engineers and drive fixes, validation and prevention. On healthcare transformation projects, assess risks in the context of customers’ operations and constraints, working with delivery teams on practical controls.
This is a hybrid role combining remote and in-person work. In-person activities may include customer visits, on-site discovery, implementation support and team meetings. Locations and frequency will be agreed according to your responsibilities.
What you’ll achieve
- Review designs and model threats across data storage, transfer, deletion and integrations with external AI services.
- Review and help implement authentication, authorization, tenant isolation, least privilege and secrets management, including tests.
- Assess Azure infrastructure and container configurations and improve network controls, access management, audit logging and encryption.
- Assess web applications and APIs, review code and scan dependencies, prioritizing remediation by risk.
- Integrate security checks into CI/CD and establish workflows for detection, remediation and verification.
- Establish monitoring, alerts and incident response procedures; drive investigations, impact assessment, recovery and prevention.
- Respond to customer security reviews and document data management practices and implemented controls.
Technology stack
- Application: Next.js / React / TypeScript / Hono / Node.js / REST API / WebSocket
- Cloud: Azure Container Apps / Azure SQL / Blob Storage / Service Bus / Docker / Azure Bicep
- AI: OpenAI / Azure OpenAI / Azure AI Speech
Skills you’ll bring
- 3+ years of professional experience in application or cloud security.
- Experience investigating web application and API vulnerabilities and working with developers through remediation and verification.
- Experience reviewing and improving IAM, network, logging and secrets configurations on Azure, AWS or GCP.
- Understanding of authentication, authorization, session management and tenant isolation, with the ability to test access controls.
- Ability to read TypeScript, JavaScript or Python and write scripts for investigation and validation.
- Ability to explain risks to technical and non-technical stakeholders and deliver controls considering impact and implementation effort.
Nice to have
- Experience securing systems that handle health information or personal data.
- Experience assessing prompt injection, data leakage and external tool permissions in LLM applications or AI agents.
- Experience with incident response, log analysis, recovery procedures and exercises.
- Experience introducing SAST, DAST or dependency scanning, or delivering security training for developers.
A note on AI
Deep AI expertise is not required for every role. We do value curiosity, experimentation and using AI as a collaborator to make work better. Where AI fluency is central to a role, we will say so clearly.
Equal opportunity
HINA is building a team where people with different backgrounds and perspectives can do their best work. If this role interests you, we encourage you to apply even if you do not meet every requirement. Please let us know if you need accommodations during the process.