Security Engineer III

GHX · Hyderabad, Telangana, India · Engineering

Posted 2026-08-15

Apply for this role →

Role: Security Engineer III

Location: Hyderabad, India (Hybrid)

Department: Infrastructure/Info Security

About GHX:

GHX (Global Healthcare Exchange) is a leading healthcare technology company on a mission to simplify the business of healthcare and improve patient outcomes. Founded in 2000, GHX has built the GHX Global Network — the world’s largest cloud-based supply chain community connecting healthcare providers, suppliers, distributors, and partners to automate key processes, reduce costs, and increase operational efficiency. Its solutions span electronic trading, procurement automation, inventory and contract management, business intelligence, and data synchronization, helping healthcare organizations improve productivity and focus more on patient care. Over the years, GHX has enabled significant cost savings for the industry and continues to innovate with intelligent automation and AI-driven capabilities.

Website: https://www.ghx.com/

LinkedIn: https://www.linkedin.com/company/ghx/

Role Overview

We are seeking a highly skilled Cybersecurity Engineer with 4+ years of experience to secure our production AWS ecosystems and modern AI-driven application pipelines. In this business-critical role, you will take operational ownership of the entire Wiz Cloud Native Application Protection Platform (CNAPP) suite. You will bridges the gap between infrastructure protection and software development by deploying Wiz Code and Wiz Code to Cloud architectures, tracing software defects, vulnerabilities, and hardcoded secrets directly from git environments up to running containerized architectures. Additionally, you will design guardrails protecting LLM structures and pipeline environments from next-generation adversarial patterns.

Key Responsibilities

Shift-Left Security & Wiz Portfolio Ownership

Wiz CNAPP: Architect, configure, and maintain the Wiz CNAPP suite globally across our AWS enterprise structure, leveraging security graphs to aggregate risk profiles.

Wiz Code Deployment: Integrate Wiz Code natively within engineering workflows, provisioning scanning capabilities across Git platforms (GitHub/GitLab) and automated CI/CD engines.

Code to Cloud Traceability: Leverage Wiz Code to Cloud context to instantly map live, running AWS workload exploits back to distinct repository blocks, code branches, and specific developers to isolate structural roots.

Supply Chain Assurance: Analyze and intercept Software Composition Analysis (SCA) alerts, malicious package risks, hardcoded infrastructure secrets, and broken Infrastructure as Code (IaC) architectures prior to merge pipelines.

AWS Cloud Infrastructure Security

Graph Risk Analytics: Isolate toxic combinations within the Wiz Security Graph, evaluating attack paths that bind internet exposure, workload misconfigurations, vulnerable packages, and excess IAM capabilities together.

Least Privilege Enforcement: Implement Cloud Infrastructure Entitlement Management (CIEM) reviews to detect and lock down excessive permissions on AWS resources (ECS, EC2, S3, EKS, AWS Lambda).

Automated Compliance: Translate framework regulations (CIS AWS Foundations Benchmark, SOC 2, ISO 27001) into active compliance monitoring tracks across codebases and clouds.

AI/ML Pipeline & LLM Engineering Guardrails

Pipeline Hardening: Deconstruct risks and deliver secure engineering patterns across AWS native platforms including Amazon Bedrock, SageMaker, and specialized training cluster nodes.

Adversarial Defense: Construct mitigations targeting prompt injection tactics, training set data poisoning vectors, model inversion mechanics, and SSRF flaws inside runtime configurations.

LLM Security Governance: Enforce guardrails modeled after the OWASP Top 10 for LLM Applications alongside MITRE ATLAS matrix standards.

Incident Support & DevSecOps Collaboration

Automated Guardrails: Convert high-fidelity Wiz risk data into automated enforcement blockers inside continuous deployment workflows.

Incident Tracing: Assist internal Security Operations with telemetry context during threat activities, blending Wiz insights, AWS CloudTrail, and GuardDuty payloads.

Security Advocacy: Co-author engineering guidelines alongside product teams to embed secure-by-design patterns cleanly across everyday development lifecycles.

Required Skills & Qualifications

Technical Experience

Professional Experience: 4+ years of focused technical practice in DevSecOps, Enterprise Application Security, or Cloud Security engineering roles.

Wiz Competency: 1 to 2+ years of hands-on platform administration across Wiz CNAPP, including proven deployment depth utilizing Wiz Code or Wiz Code to Cloud pipelines.

AWS Ecosystem Mastery: Deep structural knowledge of AWS IAM, KMS, Security Hub, CloudTrail, GuardDuty, VPC topologies, and multi-account Organization structures.

AI/ML Engineering Exposure: Familiarity securing AI interfDaces (OpenAI API, Amazon Bedrock, SageMaker) and hardening orchestration components like LangChain or vector databases.

Infrastructure as Code: Deep fluency reading, validating, and writing secure Infrastructure as Code manifests, specifically Terraform.

Automation Scripting: Competency engineering automation routines using Python (Boto3) or Shell scripts to handle automated ingestion or compliance fixes.

Soft Skills & Certifications

Engineering Collaboration: Proven track record collaborating closely with platform engineers to remediate deep code issues without stalling continuous delivery cycles.

Certifications (Preferred): AWS Certified Security - Specialty, Certified DevSecOps Professional (CDP), CCSP, or specialized cloud native security architecture validations.

Apply for this role →

← Back to all jobs