Trust

Security Engineer
Remote

At CAN Health, security is not a layer — it is the foundation. As a Security Engineer on the Trust team you will protect the data and systems that patients and clinicians depend on, spanning application security, cloud infrastructure, and compliance programmes. You will work closely with every engineering team, embedding security thinking into the development lifecycle rather than auditing after the fact.

The role

What you'll do.

Responsibilities

  • Conduct threat modelling, security design reviews, and code audits across CareOS, CAN Companion, and CAN Devices integrations.
  • Own vulnerability management: triage findings, coordinate remediation, and track risk to closure.
  • Lead and maintain HIPAA, SOC 2 Type II, and emerging AI governance compliance programmes.
  • Build security tooling and automation that makes doing the right thing the path of least resistance for engineers.
  • Respond to security incidents, lead post-mortems, and drive systemic improvements from findings.

What we're looking for

  • 4+ years of security engineering experience spanning application security and cloud infrastructure.
  • Hands-on experience with HIPAA technical safeguards and at least one SOC 2 audit lifecycle.
  • Proficiency in common attack patterns (OWASP Top 10, SSRF, injection) and their mitigations in modern web and API stacks.
  • Familiarity with AWS or GCP security services, IAM design, and network segmentation.
  • Security certifications (CISSP, OSCP, CEH, or equivalent) preferred but not required — demonstrated skills matter more.
Details

Role details.

TeamTrust
LocationRemote
TypeFull-time

Apply by writing to us at hello@can.co with the subject line Application: Security Engineer. A real person reads every note.

Open roles

More openings.

See everything we're hiring for across engineering, design, clinical, and operations.

Care, made human.
Help us build it.

Whether you are a future colleague, partner, or customer, we would be honored to hear from you.