Founding Security Engineer
About Us
Forus is building an AI-powered network that connects doctors, pharmacies, payers, and biopharma to accelerate new science to patients. Our platform automates the complexity between a doctor prescribing a medicine and a patient starting treatment, including insurance coverage, financial assistance, and supply chain navigation. We provide this support free to doctors and patients, helping them get life-changing medicine faster, cheaper, and easier. The resulting network enables biopharma companies to design better research, launch new drugs more effectively, and invest in harder-to-treat conditions.
About The Role
As a Founding Security Engineer at Forus, you will own how we protect the sensitive healthcare data at the core of our business. We automate the access workflows that determine whether patients get the care they need, which means we operate on protected health information at scale. Earning the trust of providers, payers, and life sciences partners depends on getting security right, and you will build that foundation. This is a broad, deeply technical role. You will own cloud and infrastructure security across AWS and GCP, build security into the product, secure how our AI systems handle sensitive data, and stand up detection and incident response, including the audit trails that prove how protected data is accessed. As the first security engineer, you set the technical bar for how Forus builds securely as we scale. This is a demanding role, with a high level of autonomy and responsibility. You will be expected to act like an owner and commit yourself to Forus’ success.
- Earn the trust of providers, payers, and life sciences partners by getting security right.
- Own cloud and infrastructure security (AWS, GCP): build guardrails, identity and network architecture, secrets management, and secure-by-default primitives.
- Build security into the product: lead secure design and code reviews, harden authentication and authorization, and ship libraries and tooling that make the secure path the easiest one.
- Own detection, logging, and incident response, including audit trails for how protected health information is accessed, and lead the technical response when something goes wrong.
- Secure our corporate and identity surface: SSO, device and endpoint security, SaaS hardening, and access across the employee lifecycle.
- Secure how our agentic AI systems handle sensitive data: designing isolation and data-flow controls and defending against leakage across our model pipelines.
- Build the automation and "security as code" that lets engineers move fast, and implement the technical controls behind SOC 2, HIPAA, and HITRUST.
- Partner with legal and GTM teams to translate compliance and customer requirements into controls that actually ship.