logo[мetahunt]
> Djinni
senior

Security Engineer

format:Remote
soc 2gdprcloud securityvulnerability managementincident response
iso 27001saascloud
englishB2
domainHealthTech
> full description

Location: Remote — Worldwide
Engagement: Full-time / Part-time
Duration: Long-term
Start: ASAP
Seniority: Senior / Architect / Consultant
English: B2+
Compensation: Negotiable, based on experience and availability

 

About the Project

We are looking for an experienced Senior Security / GRC Consultant to support an innovative healthcare technology company developing a robotic remote ultrasound solution for hospitals in the US and EU.

The product involves remote medical examinations, patient data processing, and healthcare software integrations.

The primary objective is to establish a robust security and compliance framework, prepare the company for SOC 2 certification readiness and a successful external audit, and address cybersecurity requirements from healthcare customers.

This is a hands-on consulting role requiring proven experience leading SOC 2 readiness and audit preparation, not simply working as an engineer in a SOC 2-compliant environment.

 

Key Responsibilities

SOC 2 Readiness & Audit Preparation

  • Independently lead SOC 2 readiness and compliance initiatives.
  • Conduct gap assessments and identify security and compliance risks.
  • Develop and implement security policies, procedures, and controls.
  • Organize evidence collection and audit documentation.
  • Coordinate with external auditors and support the SOC 2 audit process.
  • Provide actionable recommendations to engineering and management teams.

Healthcare Security & Compliance

  • Ensure alignment with HIPAA, GDPR, and healthcare data protection requirements.
  • Define security requirements for handling Protected Health Information (PHI).
  • Assess cybersecurity risks associated with medical software and patient data.
  • Support compliance with security expectations of US and EU hospitals.

Security Documentation & Customer Support

  • Prepare comprehensive security white papers describing security architecture, controls, processes, and data protection practices.
  • Independently complete and review customer security questionnaires.
  • Participate in client calls and address technical security and compliance questions.
  • Develop technical security specifications and implementation guidelines for the development team.

Medical Software Compliance

  • Collaborate with the client's QA/RA Manager on IEC 62304-related processes and documentation.
  • Contribute to Software Requirements Specifications (SRS), software architecture documentation, and Verification & Validation (V&V) processes.

 

Required Qualifications

  • Senior-level experience in information security, GRC, security compliance, or security consulting.
  • Proven hands-on experience independently preparing at least one organization for SOC 2 and supporting it through a successful external audit.
  • Strong understanding of SOC 2 Trust Services Criteria, security controls, audit evidence, and compliance processes.
  • Practical experience implementing security policies and compliance frameworks.
  • Knowledge of HIPAA, GDPR, and PHI protection requirements.
  • Experience creating security white papers and responding to enterprise customer security questionnaires.
  • Ability to translate regulatory and compliance requirements into clear technical tasks for engineering teams.
  • Strong communication and stakeholder management skills.
  • English B2+ or higher, with the ability to independently lead client discussions.

 

Nice to Have

  • Previous SOC 2 audit preparation experience in healthcare, MedTech, or digital health.
  • Experience with medical devices or medical software.
  • Familiarity with IEC 62304 and medical software lifecycle documentation.
  • Knowledge of ISO 27001, ISO 13485, or other healthcare-related standards.
  • Experience with cloud infrastructure, SaaS security, or security architecture.
  • Experience supporting enterprise sales or technical presales.

 

Engagement Details

The engagement will begin with a technical presales phase, during which the consultant will independently assess the client's security and compliance needs, answer relevant questions, and help define the scope of work.

Following successful presales, the consultant will take ownership of SOC 2 readiness and security compliance activities.

The initial workload is expected to be substantial, potentially full-time, with the possibility of transitioning to part-time involvement as the project progresses.

Part-time consultants are also welcome to apply. The exact workload and engagement model will be determined together with the selected specialist.

The project is long-term, with potential team expansion and additional healthcare software initiatives, including ultrasound video streaming, robotic HMI, and urgent examination booking platforms.

Important

 

We are specifically looking for someone who has personally led SOC 2 preparation and successfully supported an external audit.

Experience developing software within a SOC 2-compliant organization alone is not sufficient.

Candidates should be ready to discuss concrete examples of previous SOC 2 projects, their responsibilities, implemented controls, evidence collection processes, and audit outcomes.

 

How to Apply

Please share your CV, expected hourly rate, availability, and a brief description of your hands-on SOC 2 audit preparation experience.

We are particularly interested in candidates who can demonstrate successful SOC 2 readiness projects and independently lead security compliance discussions with healthcare clients.