The Opportunity
Were looking for a hands-on Infrastructure Security Engineer to help design, implement, and mature Curative AIs cloud security architecture across Azure, AWS, and Microsoft 365. Reporting to the Director of IT, you will be the primary technical lead for securing our infrastructure, implementing SOC 2 and HIPAA controls, and driving automation to keep our environments compliant and resilient.
Responsibilities
- Design and maintain secure infrastructure across Azure, AWS, and M365, including networking, IAM, storage, and compute.
- Deploy and manage security tools such as vulnerability scanners, EDR / XDR (Defender P2), SIEM, and secrets management systems.
- Implement and document compliance controls aligned with SOC 2 Type 1 / 2 and HIPAA frameworks.
- Harden systems including Windows, Linux, container workloads (Kubernetes / EKS / AKS), and CI / CD pipelines.
- Collaborate with IT and DevOps to enforce identity governance (Okta, Azure AD / Entra ID, Conditional Access, MFA, least-privilege).
- Support endpoint compliance policies in Intune, including encryption, patch management, and secure configurations.
- Automate configuration and compliance checks using Terraform, PowerShell, or Python.
- Participate in incident response and assist with forensic investigations.
- Maintain clear documentation for security architecture, baselines, and operational procedures.
- Partner with IT and engineering leadership to strengthen ISMS maturity and BCP / DR strategies.
Qualifications
5+ years in infrastructure, cloud, or security engineering.Deep understanding of Azure and AWS security services, networking, and IAM.Strong background in Windows Server / Active Directory, Linux, and virtualization.Experience with M365 security & compliance, Intune, and Defender P2.Hands-on experience with automation (PowerShell, Python, Bash) and IaC tools (Terraform, CloudFormation).Familiarity with SOC 2 and HIPAA control requirements.Proven ability to translate compliance objectives into actionable technical controls.Preferred
Experience implementing Zero Trust or Remote Access Security (FortiGate, NordLayer, Teleport, etc.).Knowledge of SSO protocols, PKI, and certificate management.Cloud or security certifications (e.g., AZ-500, AWS Security Specialty, CISSP, GIAC).Prior experience in healthcare or regulated SaaS environments.Compensation And Benefits
Base Salary Range : $115,000 - $137,500 (commensurate with experience and qualifications)Target Annual Performance BonusEquity Package : Generous equity participation in the companys future successComprehensive benefits package including medical, dental, vision, Life and AD&D insurance; 401K; paid time off and holidaysOpportunity to work on cutting-edge AI projects and make an impact on the companys successChance to impact the companys AI strategy and innovationCurative AI, Inc. is an Equal Opportunity Employer (EEO) and does not discriminate on the basis of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, political affiliation, disability, genetic information (including family medical history), age, marital status, veteran status, or other non-merit-based factors. Curative AI, Inc. does not currently sponsor H1B visas and therefore candidates must be legally authorized to work for any employer in the United States on a full-time basis and not require current or future visa sponsorship for employment. Curative AI, Inc. is committed to creating a diverse and inclusive workforce. We value the unique perspectives and talents that each individual brings to our company, and we are committed to providing an environment where all employees feel respected, valued, and empowered to reach their full potential. We encourage qualified individuals from all backgrounds to apply for our open positions.
#J-18808-Ljbffr