Apply

Security Engineer

Posted 1 day agoViewed

View full description

πŸ’Ž Seniority level: Junior, 1+ years

πŸ” Industry: Healthcare

🏒 Company: Clover HealthπŸ‘₯ 501-1000πŸ’° $300,000,000 Post-IPO Equity about 3 years agoπŸ«‚ Last layoff almost 2 years agoMedicalHealth InsuranceHospitalHealth Care

πŸ—£οΈ Languages: English

⏳ Experience: 1+ years

Requirements:
  • 1+ years of experience in a security role with a focus on engineering.
  • Experience investigating and triaging security incidents.
  • Basic understanding of operating systems such as Linux and OSX, as well as networking fundamentals.
  • Strong understanding of at least one technology among Python, JavaScript/TypeScript, or Shell Scripting.
  • Comfortable conducting frequent code reviews for security vulnerabilities.
  • Experience in assessing the security of APIs and systems by analyzing authentication, authorization mechanisms, input validation, and potential vulnerabilities.
  • Excellent written and verbal communication skills with the ability to create clear reports and research for engineering stakeholders.
  • Up-to-date with latest research on threats, attack vectors, and security trends with a willingness to apply them.
  • Knowledge of cybersecurity frameworks and standards like NIST, ISO, CIS.
Responsibilities:
  • Implement, operationalize and monitor various security applications including EDR, DLP, SAST, Vulnerability Management, and CSPM systems.
  • Serve as a Subject Matter Expert (SME) for security-related code and technical design reviews.
  • Identify security vulnerabilities in software, systems, and infrastructure and collaborate with engineering and SRE to resolve them.
  • Assess and enhance systems for compliance with security requirements, policies, guidelines, and standards.
  • Interface with external customers regarding cybersecurity reviews and assessments.
  • Work to improve overall security posture and processes including secure development practices and SecDevOps.
  • Contribute to the planning, definition, and implementation of new security solutions or related developments.
Apply

Related Jobs

Apply

πŸ” Healthcare technology

  • Experience in GRC (governance, risk, compliance) and technical security.
  • Familiarity with industry frameworks, best practices, and regulatory requirements.

  • Play a central role in securing our enterprise and cloud native environments.
  • Understand and implement governance, risk, compliance, privacy, and data protection.
  • Support protecting patients, employees, and Aledade as a whole.
Posted 1 day ago
Apply
Apply

🧭 Full-Time

πŸ” Healthcare technology

  • Bachelor (or higher) in Computer Science, Information Technology, Cybersecurity, or related field, or 6 years security domain experience without a degree.
  • 4+ years combined experience as a GRC specialist in an enterprise environment, preferably cloud.
  • 3+ years of relevant work experience in risk reporting and working on audits/assessments.
  • 2+ years experience in performing third party risk management activities.

  • Working cross-functionally to measure & report on risk, achieve & maintain compliance.
  • Manage assessments/audits and contribute to security GRC strategy & advisory efforts.
  • Leverage data to understand trends and improve security posture.
  • Lead risk management efforts, spearheading qualitative risk assessments & quantitative risk analysis.
  • Oversee third party risk management (TPRM) and participate in Customer Trust mitigation strategies.
  • Craft and refine security documentation relevant to the Security Program.
Posted 1 day ago
Apply
Apply

πŸ“ Singapore

🧭 Full-Time

πŸ” Cybersecurity Consulting

  • Bachelor’s or Master’s degree in Computer Science, Computing, Electrical Engineering, Information Technology, or equivalent.
  • At least 5 years of experience in cybersecurity engineering, with focus on protecting IT infrastructures and sensitive data.
  • Minimum of 2 years of experience in public sector or government cybersecurity projects.
  • Must possess certifications such as CREST or OSCE and OSCP.

  • Conduct Threat Risk Assessments (TRAs) to identify vulnerabilities and recommend mitigation strategies.
  • Perform continuous penetration testing on services to simulate attacks and maintain security posture.
  • Lead design and implementation of secure cloud architectures, ensuring compliance with cybersecurity regulations.
  • Respond to security incidents, managing breach identification, containment, and remediation.

AWSPythonBashCybersecurityGCPAzureCompliance

Posted 3 days ago
Apply
Apply

🧭 Full-Time

πŸ’Έ 89000.0 - 134000.0 USD per year

πŸ” Cyber Security

NOT STATED

  • Overseeing the management, evaluation, deployment, and optimization of various security tools and technologies within the organization's cybersecurity infrastructure.
  • Collaborating with cross-functional teams to address security requirements.
  • Ensuring the effective operation of security tools to safeguard the organization's information systems and data assets.
Posted 3 days ago
Apply
Apply

πŸ“ Argentina

🧭 Full-Time

πŸ” Cybersecurity

🏒 Company: Onapsis

  • 1+ years of experience using SIEM tools for security monitoring and incident detection.
  • Understanding of security protocols, networking, operating systems, and cryptography.
  • Familiarity with alerting systems, ticketing systems, and triaging security incidents.
  • Understanding of vulnerability management processes, including scanning and remediation.
  • Knowledge of antivirus software and Endpoint Detection and Response (EDR) solutions.
  • Practical experience in programming/scripting languages like Python, Bash, Powershell.
  • Upper intermediate spoken and written English level.
  • Strong communication and teamwork skills, and self-motivation.

  • Monitor security alerts, investigate potential incidents, and respond using SIEM tools.
  • Participate in vulnerability scanning and support remediation by coordinating with teams.
  • Assist in deployment and monitoring of endpoint detection and response solutions.
  • Proactively search for indicators of compromise in the network.
  • Help maintain and update security policies for compliance with regulations.
  • Stay updated on emerging threats and security technologies.

PythonBash

Posted 3 days ago
Apply
Apply

πŸ“ U.S.

πŸ” Information Security

🏒 Company: GuidePoint Security

  • Minimum 8-10 years of experience building or managing cloud environments.
  • Professional certification in Azure, such as Azure Solutions Architect Expert preferred.
  • Strong understanding of cloud computing technologies and business drivers.
  • Proficient in Azure services including Entra ID, Azure VMs, and more.
  • Must pass the CCSK or (ISC)2 CCSP within 6 months.

  • Design Azure cloud solutions with a secure-by-design approach.
  • Collaborate with customer IT teams to implement and secure cloud resources.
  • Develop scalable and resilient cloud architecture solutions in Azure environments.
  • Create and implement migration strategies for on-premises to Azure.
  • Ensure compliance with architectural policies and enforce security requirements.

Microsoft AzureCI/CDTerraformNetworking

Posted 3 days ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ’Έ 180000.0 - 230000.0 USD per year

πŸ” Cybersecurity

🏒 Company: Trail of BitsπŸ‘₯ 11-50SecurityNational SecurityCyber SecuritySoftware

  • Extensive experience in application security, focusing on identifying and mitigating cloud infrastructure vulnerabilities.
  • Track record of conducting technical security assessments across different platforms.
  • Strong programming and code auditing skills with experience in fuzzing and static analysis tools.
  • Proficiency in programming languages such as Go, Python, Rust, and JavaScript.
  • Ability to communicate complex security concepts effectively and mentor junior engineers.

  • Lead comprehensive security reviews of cloud-native applications and architectures, including cloud platform configurations.
  • Design and implement custom security tools for automated vulnerability detection.
  • Perform detailed architecture reviews and threat modeling, providing remediation guidance.
  • Work directly with industry-leading teams to analyze and recommend security improvements.
  • Contribute to application security advancement through research and development efforts.

AWSDockerPythonCloud ComputingCybersecurityGCPJavascriptKubernetesAPI testingAzureGoRustMicroservices

Posted 4 days ago
Apply
Apply

πŸ“ United States

πŸ’Έ 120000.0 - 175000.0 USD per year

πŸ” Cybersecurity

🏒 Company: PraetorianπŸ‘₯ 101-250πŸ’° $10,000,000 Series A almost 5 years agoPenetration TestingSecurityCloud SecuritySoftware EngineeringCyber SecurityEnterprise SoftwareNetwork Security

  • Demonstrated passion for offensive security and adversarial engineering.
  • 2+ years of IoT security experience in hardware/software reverse engineering, firmware analysis, embedded cryptography, wireless protocols, or IoT PaaS security.
  • Additional experience in product security testing, network security testing, web app penetration testing, and cloud security.
  • Understanding of threat models and attack paths.
  • Ability to write technical reports and present findings.

  • Provide technical execution on offensive security projects focused on IoT Security.
  • Identify nuanced vulnerabilities in advanced systems.
  • Develop custom methodologies, payloads, exploits, and tools.
  • Document mitigation strategies for emerging or undocumented risks.
  • Create comprehensive reports and presentations for clients.
  • Mentor other engineers in technical and professional development.
  • Collaborate with the security community to develop novel attack techniques.

AWSPythonEmbedded SystemsIoTMentoring

Posted 4 days ago
Apply
Apply

πŸ’Έ 125000.0 - 175000.0 USD per year

πŸ” Cybersecurity

🏒 Company: SimSpaceπŸ‘₯ 251-500πŸ’° $45,000,000 about 1 year agoSecurityCyber SecurityNetwork SecuritySoftware

  • Deep understanding of tactics and techniques used during offensive network operations and the ability to modify them to counter defensive measures.
  • Extensive experience (5+ years) emulating real-world cyber threats, covering full attack chains and applying threat intelligence.
  • Professional experience in Python 3, PowerShell, or other scripted languages, and compiled languages (C/C++, Golang, etc.).
  • Demonstrated experience leading projects with distributed systems, communication frameworks (RESTful API and rMQ), and proper security constructs.
  • Advanced cybersecurity knowledge, including familiarity with industry standards like MITRE ATT&CK and the NIST Cybersecurity Framework.
  • Experience with defensive tools/techniques and commonly-used attack frameworks (Metasploit, Cobalt Strike, etc.).

  • Research, implement, integrate and automate new attack content (attack tools, attack scenarios, etc.) into the Scenario Development portfolio.
  • Perform end-to-end testing of attack content to ensure functionality in complex environments and the ability to evade common defensive tools.
  • Collaborate with software developers on the Offensive Engineering team to ensure the Scenario Development team’s work is effective during customer events.
Posted 4 days ago
Apply
Apply

πŸ“ United States, Canada, Singapore, Poland, UK

πŸ’Έ 120000.0 - 175000.0 USD per year

πŸ” Cybersecurity

🏒 Company: PraetorianπŸ‘₯ 101-250πŸ’° $10,000,000 Series A almost 5 years agoPenetration TestingSecurityCloud SecuritySoftware EngineeringCyber SecurityEnterprise SoftwareNetwork Security

  • Demonstrated passion for offensive security and adversarial engineering.
  • 2+ years of experience in one or more offsec domains: software, hardware, network, or cloud penetration testing.
  • Ability to write technical reports and present technical findings both internally and externally.
  • Experience with startup and/or high-tech companies.
  • Prior security consulting experience a major plus.
  • Software development experience in core offsec languages such as golang or python.
  • Track record in vulnerability research, exploit development, and CVE assignments.

  • Provide technical execution on challenging offensive security projects for our customers.
  • Identify nuanced vulnerabilities in advanced systems.
  • Develop custom methodologies, payloads, exploits, and tools to ensure project success.
  • Develop documentation for novel mitigation strategies to emerging or undocumented security risks identified in client environments.
  • Develop comprehensive reports and presentations for our customers.
  • Serve as a mentor to other engineers in their technical and professional development.
  • Collaborate with the security community to develop novel attack techniques, tactics, and procedures (TTPs) through community engagement.

PythonSoftware Development

Posted 5 days ago
Apply

Related Articles

Posted 5 months ago

Insights into the evolving landscape of remote work in 2024 reveal the importance of certifications and continuous learning. This article breaks down emerging trends, sought-after certifications, and provides practical solutions for enhancing your employability and expertise. What skills will be essential for remote job seekers, and how can you navigate this dynamic market to secure your dream role?

Posted 5 months ago

Explore the challenges and strategies of maintaining work-life balance while working remotely. Learn about unique aspects of remote work, associated challenges, historical context, and effective strategies to separate work and personal life.

Posted 5 months ago

Google is gearing up to expand its remote job listings, promising more opportunities across various departments and regions. Find out how this move can benefit job seekers and impact the market.

Posted 5 months ago

Learn about the importance of pre-onboarding preparation for remote employees, including checklist creation, documentation, tools and equipment setup, communication plans, and feedback strategies. Discover how proactive pre-onboarding can enhance job performance, increase retention rates, and foster a sense of belonging from day one.

Posted 5 months ago

The article explores the current statistics for remote work in 2024, covering the percentage of the global workforce working remotely, growth trends, popular industries and job roles, geographic distribution of remote workers, demographic trends, work models comparison, job satisfaction, and productivity insights.