Apply

Senior Security Engineer

Posted about 2 months agoViewed

View full description

πŸ’Ž Seniority level: Senior, 5+ years

πŸ“ Location: United States

πŸ’Έ Salary: 150025.0 - 176500.0 USD per year

πŸ” Industry: Healthcare, Telemedicine

🏒 Company: Bicycle HealthπŸ‘₯ 101-250πŸ’° $5,000,000 Series B over 2 years agoPersonal HealthHealth InsuranceHealth Care

πŸ—£οΈ Languages: English

⏳ Experience: 5+ years

πŸͺ„ Skills: AWSCybersecurityComplianceRisk Management

Requirements:
  • 5+ years experience as a Senior Security Engineer or similar role.
  • Extensive knowledge of healthcare data privacy and security regulations.
  • Advanced certifications (CISSP, CISM, HITRUST CCM).
  • Strong understanding of security governance frameworks.
Responsibilities:
  • Collaborate with the executive team to align security strategies to business objectives.
  • Manage compliance with healthcare regulatory requirements.
  • Conduct security compliance audits and risk assessments.
  • Develop and implement security awareness training programs.
  • Oversee vendor security assessments.
Apply

Related Jobs

Apply

πŸ“ Canada, United States

🧭 Full-Time

πŸ’Έ 156000.0 - 210000.0 USD per year

πŸ” Security

  • Minimum of 6 years combined experience as a software, infrastructure, and/or security engineer.
  • Demonstrated success at designing, implementing, deploying, securing, and monitoring highly-available, critical production systems with broad company impact.
  • Hands-on experience with a variety of technologies and approaches in both the cloud infrastructure and security spaces; e.g. service identity, workload hardening, networking, authentication and authorization, software supply chain, etc.
  • Expertise with AWS Service Control Policies and permission boundaries.
  • Experience with software development (Golang preferred).
  • Design, build, and maintain tooling, software, and systems for securing our cloud infrastructure.
  • Own the delivery and success of infrastructure security projects that span engineering teams.
  • Work with cross-functional partners to define the best security solutions for our infrastructure and reduce unnecessary friction, while maintaining a high degree of software development velocity.
  • Provide technical leadership and mentorship to fellow engineers on the team.

AWSSoftware DevelopmentAWS EKSCloud ComputingCybersecurityKubernetesGoCI/CDRESTful APIsLinuxDevOpsTerraformNetworkingScriptingSoftware Engineering

Posted about 4 hours ago
Apply
Apply

πŸ“ United States

πŸ’Έ 145000.0 - 160000.0 USD per year

πŸ” Software Development

🏒 Company: Harness

  • At least 7 years of relevant industry experience in roles such as systems engineer, security engineer, cloud security specialist, or site reliability engineer.
  • Expert-level professional knowledge in enterprise applications and infrastructure.
  • Extensive experience working in a cloud-native environment, with proficiency in platforms like AWS, GCP, and Azure.
  • Familiarity with industry regulations and compliance certifications, including ISO 27001, SOC 2, FedRAMP, and SOX.
  • A desire to contribute to a high-growth environment and take a leading role in building new programs from the ground up.
  • Strong attention to detail and a willingness to ask questions when uncertain.
  • Comfort with ambiguity, with a proactive approach to bringing clarity in uncertain situations.
  • Take a leading role in the design of the next level of secure operations for Harness' cloud and business infrastructure
  • Take charge of implementing and overseeing security tooling, encompassing the detection and alerting systems for identifying malicious activity and insecure configurations
  • Utilize automation to effectively manage and enhance the security posture of Harness' multi-cloud Kubernetes-based infrastructure
  • Use Harness CI/CD to integrate security processes like vulnerability management into the SDLC
  • Contribute to the development, review, and implementation of technical security and compliance-related engineering requirements across global Engineering teams
  • Detect, respond, and mitigate security related events and incidents.
  • Collaborate with fellow Developers and Product Managers to analyze and implement security standards, methods, and architectures

AWSCloud ComputingCybersecurityGCPKubernetesAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceAnsibleScripting

Posted 6 days ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ” Payments, Healthcare

🏒 Company: TruemedπŸ‘₯ 1-10πŸ’° $3,500,000 Seed over 1 year agoPaymentsWellnessHealth Care

  • 5+ years of experience in security engineering, compliance, or security operations
  • Hands-on experience with SOC2 Type II audits
  • Strong background in vulnerability management, endpoint security, and secure software development practices
  • Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices
  • Experience working with GRC teams and responding to enterprise security questionnaires
  • Lead SOC2 Type II Compliance
  • Governance, Risk, and Compliance (GRC)
  • Security Tooling & Implementation
  • Incident Response & Risk Mitigation
  • Cross-Team Collaboration

CybersecurityComplianceRisk Management

Posted 8 days ago
Apply
Apply

πŸ“ Canada, United States

🧭 Full-Time

πŸ’Έ 143000.0 - 210000.0 USD per year

πŸ” Security

  • Minimum of 5+ years of combined experience in security, GRC, risk, or a related space with hands-on technical work building automation solutions as they relate to compliance controls, evidence, GRC platforms, etc.
  • Experience in effectively analyzing data and programs for security risk, compliance, and maturity.
  • Willingness to wear different hats and work on areas where needed.
  • Must excel in communication, and demonstrate the ability to explain technical security concepts to a non-technical audience.
  • Must have a highly collaborative and teamwork-focused approach, as well as a heart for mentoring and leveling up your teammates.
  • Must be able to assess and mitigate corporate risk within the organization.
  • Sophisticated program/project management abilities.
  • Nice to have: experience with Drata and/or Vanta (integrations, automation, onboarding as a GRC platform).
  • Own, design and manage the continued enhancement of various GRC programs including but not limited to strategy, roadmap, and controls to address regulatory requirements across multiple jurisdictions.
  • Communicate our compliance framework and various program requirements to all relevant stakeholders (internal and external).
  • Engage cross-functionally (with groups such as Engineering, Finance, Legal, Product, and Sales) to establish a thoughtful, strategic and tactical approach to multiple GRC programs and related processes.
  • You will assist with analysis and preparation for internal and external audits.
  • Accurately and effectively communicate our compliance position and programs to auditors and customers.
  • Partner with other members of the security team to establish security guidelines that enable the organization to move fast in a safe and secure manner.
  • To operate as a technical leader by helping define the GRC roadmap and by leveling up junior employees.
  • Build strong relationships with partner and stakeholder teams in order to build a scalable GRC program.

Project ManagementSQLCloud ComputingCybersecurityData AnalysisCommunication SkillsAnalytical SkillsCollaborationMentoringDevOpsComplianceRisk Management

Posted 20 days ago
Apply
Apply

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: DockerπŸ‘₯ 251-500πŸ’° $105,000,000 Series C about 3 years agoDeveloper ToolsDeveloper PlatformInformation TechnologySoftware

  • Have 6 to 8 years of experience in Information Technology, Security Engineering, Governance, Risk and Compliance
  • Will have familiarity setting up APIs and Webhooks, at least one scripting language, and at least one public cloud architecture and control tool
  • Experience conducting security compliance reviews and audits for SaaS products and hosted environments including AWS and Azure.
  • Have strong knowledge of information security risk management and information security technologies (e.g: SIEM, vulnerability management, data loss prevention and /or endpoint protection)
  • Thrive in fast-paced environments and can adapt quickly in the face of constantly evolving cybersecurity challenges
  • Strong project management skills with the ability to lead and execute security assessment projects, vendor evaluations and initiatives on time with multiple stakeholders
  • Enjoy fostering collaboration and cross-functional partnerships to help spread awareness and
  • Build and implementation of cybersecurity controls
  • Have experience in-depth knowledge and experience of cybersecurity frameworks including ISO 27001, 27701 and 27018
  • Experience with the entire controls monitoring lifecycle, including identifying, assessing, monitoring, and remediating controls.
  • Excellent verbal and written communication skills with the ability to document, communicate, and report security assessments
  • Serve as the subject matter expert and provide technical leadership and feedback for compliance / GRC projects
  • Appropriately handling and managing confidential information including proprietary and trade secret information
  • Stay up-to-date with changes in regulations, standards, and emerging regulatory requirements and ensure compliance
  • Lead the development, implementation and maintenance of comprehensive GRC strategies
  • Build automated evidence gathering and continuous control testing through integrations maturing our governance program.
  • Establish partnerships with internal/external auditors, regulators, business stakeholders develop security requirements and controls.
  • Optimize security compliance monitoring and alerting systems; aggregate compliance alerts and advise on system policy violations
  • Perform critical data security reviews over newly released products and features.
  • Ensure controls are operating effectively via assessment and attestation
  • Own the vulnerability management program to identify and provide guidance for improvements
  • Security Metrics - Uses automated and manual processes to produce relevant KPIs about the Information security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Recertification - Operates periodic processes to hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education progress
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls findings, and remediation activity
  • Draft policies and best practices that will be consumed by the entire organization
  • Maintain knowledge of certifications and controls such as SOC 2, ISO 27001 / ISO 27018, and 27701
  • Evaluate vendors against compliance and security standards

AWSDockerProject ManagementSQLCybersecurityJiraAPI testingAzureCommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingAgile methodologiesRESTful APIsLinuxDevOpsTerraformWritten communicationDocumentationMicroservicesComplianceMS OfficeRisk ManagementStakeholder managementScriptingSoftware Engineering

Posted 23 days ago
Apply
Apply

πŸ“ Colombia, Chile, Mexico, United States

πŸ” Sales

🏒 Company: Tenable, Inc.

  • Experience with cloud computing infrastructures such as AWS, Azure, GCP, etc.
  • Knowledge of Terraform, AWS CloudFormation, or other cloud automation tools
  • Engage with large clients to architect solutions
  • AWS Certified Security, Azure Security Engineering Certification, GCP Cloud Professional
  • Experienced in IaC DevOps workflow (DevSecOps preferred)
  • Perform tailored solution demonstrations
  • Partner with regional sales teams to drive product awareness
  • Run and own the complete PoV Process
  • Be a mentor for our customers and Channel Partners
  • Provide feedback to Product Management

AWSCloud ComputingCybersecurityGCPKubernetesSalesforceAzureCommunication SkillsCI/CDRESTful APIsMentoringDevOpsTerraformPresentation skillsComplianceJSONSales experience

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ” Software Development

🏒 Company: Monarch Money

  • 5+ years of experience in security engineering roles, with a focus on data security, application security, and infrastructure security, ideally in a cloud-first environment.
  • Proficiency in a programming language (Python preferred) to support execution of security initiatives.
  • Demonstrated experience implementing data encryption and access controls for sensitive data.
  • Experience securing cloud environments (AWS preferred) with a deep understanding of IAM, VPCs, and security groups.
  • Knowledge of secure coding principles and experience with security testing tools (SAST, DAST) within CI/CD pipelines.
  • Ability to explain complex security concepts clearly to both technical and non-technical stakeholders.
  • Implement and enforce data encryption standards for data at rest and in transit, ensuring strong key management practices.
  • Design and maintain data access controls and policies, limiting access to sensitive data (e.g., PII) and enforcing the principle of least privilege.
  • Monitor and detect data exfiltration risks, unauthorized access, and anomalies around data handling.
  • Conduct regular audits of PII storage, access, and handling to ensure sensitive data remains secure.
  • Embed security best practices within the Software Development Lifecycle (SDLC), including secure coding, code review, and application security testing.
  • Deploy and maintain security tools in the CI/CD pipeline, such as SAST, DAST, and dependency scanning tools, to identify and remediate application vulnerabilities.
  • Perform threat modeling, vulnerability assessments, and penetration testing to identify and mitigate risks.
  • Design and enforce security configurations in cloud environments (e.g., AWS), including IAM roles, security groups, and VPC segmentation.
  • Establish automated monitoring and alerting to detect anomalies or potential breaches across cloud infrastructure.
  • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote data security practices.
  • Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure decisions.

AWSDockerPostgreSQLPythonCloud ComputingCybersecurityKubernetesMySQLCommunication SkillsCI/CDRESTful APIsLinuxDevOpsTerraformComplianceJSONAnsible

Posted about 1 month ago
Apply
Apply

πŸ“ United States, United Kingdom

🧭 Full-Time

πŸ’Έ 147000.0 - 184000.0 USD per year

πŸ” Security

🏒 Company: HackerOne

  • 5+ years of experience in detection and response related security roles
  • Experience working with AWS (or similar cloud environment), Linux, OSX, SentinelOne (or other similar endpoint security software)
  • Experience working with DataDog (or other similar log analysis and querying software)
  • Familiarity with modern programming languages of some kind such as Ruby, Python, Rust, JavaScript, and similar.
  • Proficient in responding to alerts and incidents within a cloud based SAAS environment
  • Adaptable thinker, able to creatively solve old problems in new ways and new problems in old ways
  • Strong collaboration and communication skills with other teams to plan a project, align priorities, lead and model the work, document your decisions, and complete the project
  • Understands ways to catch wily threat actors
  • Possesses the fine art of crafting useful, actionable, high signal alerts
  • Proficiency in automating detection and response processes through API calls, webhook creation, etc.
  • Willingness and ability to participate in the response to critical incidents as needed.
  • Evaluating potential detection techniques and tools and using them to create useful, actionable, high signal alerts.
  • Developing automation and improving existing tooling and alerting to minimize alert fatigue and maximize effective incident response.
  • Collaborating will be key as you will work closely with IT, Engineering, Support and other teams across the company.
  • You will play a vital role in managing security incidents, from assembling the response team to organizing and leading blameless retrospectives. You'll also help develop clear response processes for various types of incidents and playbooks for various alerts generated by our tools.

AWSDockerPythonCloud ComputingCybersecurityKubernetesAPI testingREST APICommunication SkillsAnalytical SkillsCollaborationCI/CDProblem SolvingLinuxDevOpsTerraformWritten communicationComplianceExcellent communication skillsAdaptabilityTeamworkTroubleshootingActive listeningJSONRisk ManagementStrategic thinkingScripting

Posted about 1 month ago
Apply
Apply

πŸ“ Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, or Washington, D.C.

🧭 Full-Time

πŸ’Έ 144000.0 - 189000.0 USD per year

πŸ” Health Insurance

🏒 Company: Oscar HealthπŸ‘₯ 1001-5000πŸ’° $140,000,000 Private over 4 years agoπŸ«‚ Last layoff almost 5 years agoHealth InsuranceInsurTechInsuranceHealth Care

  • 3+ years experience in security engineering or technical related role, focused on security operations
  • Deep understanding of security concepts, including network security, endpoint security, vulnerability management, and incident response.
  • Hands on experience with security information and event management (SIEM) systems.
  • Experience with security automation and orchestration tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
  • Design, implement, and maintain security monitoring and detection systems, including SIEM, SOAR, and XDR platforms.
  • Develop and implement security automation workflows to improve security operations and incident response processes.
  • Enhance security visibility by implementing robust logging and alerting mechanisms across the environment.
  • Identify and improve security vulnerabilities and misconfigurations.
  • Lead incident response efforts, including containment, eradication, and postincident analysis.
  • Collaborate with other teams to integrate security best practices into their workflows.
  • Research emerging security technologies and threats.
  • Mentor junior security engineers.
  • Contribute to the development and maintenance of security policies and procedures.
  • Participate in on-call rotation for security incidents.
  • Compliance with all applicable laws and regulations.
  • Other duties as assigned.

AWSPythonCloud ComputingCybersecurityGCPAzureCommunication SkillsAnalytical SkillsProblem SolvingMentoringLinuxComplianceTeamworkScripting

Posted about 1 month ago
Apply
Apply
πŸ”₯ Senior Security Engineer
Posted about 1 month ago

πŸ“ United States

🧭 Full-Time

πŸ’Έ 109305.0 - 136631.0 USD per year

πŸ” FinTech

🏒 Company: joinroot

  • At least three years of experience in application security, security engineering, or cloud security. This includes a strong understanding of cloud security principles in AWS, GCP, or Azure, with hands-on experience securing cloud-based applications and infrastructure (e.g., IAM, network security, logging/monitoring).
  • Proven ability to identify, assess, and mitigate security risks at scale in modern software development environments.
  • Ability to translate security best practices into engineering requirements, especially as they relate to application security.
  • Strong understanding of the OWASP Top Ten and SAMM framework for measuring and improving application security maturity.
  • Experience performing threat modeling, particularly in an Agile development environment.
  • Experience maintaining SAST and/or SCA tools, including the maintenance and tuning of detections.
  • Proficiency in scripting and automation using programming languages such as Python or Ruby.
  • Experience embedding security solutions into DevOps processes and pipelines and leveraging automation to enforce security policies.
  • Familiarity with common attack vectors, industry best practices, and risk mitigation strategies.
  • Experience working with compliance frameworks (e.g., SOC 2, PCI-DSS, NIST, ISO 27001).
  • Strong analytical abilities and excellent communication skills, enabling you to effectively influence both technical and non-technical stakeholders.
  • Willingness to participate in an on-call rotation to address critical security incidents and ensure timely response.
  • Proactively identify, assess, and remediate security vulnerabilities across cloud infrastructure, applications, and internal systems.
  • Drive projects that safeguard Root’s products, infrastructure, and customer data.
  • Lead threat modeling sessions, security reviews, and architectural assessments to bolster our product security.
  • Collaborate with engineering and DevOps teams to integrate security best practices throughout the software development lifecycle (SDLC) and cloud operations.
  • Implement and refine security monitoring, detection, and response capabilities across our technology ecosystem.
  • Provide technical leadership and mentorship to engineering teams on secure coding, vulnerability management, and risk assessment.
  • Work alongside compliance and risk teams to align security initiatives with regulatory requirements (e.g., SOC 2, PCI-DSS, NIST, OWASP).
  • Develop and deploy automation tools and processes that streamline security operations and reduce friction for development teams.
  • Keep current with emerging threats, vulnerabilities, and industry trends to continuously evolve Root’s security program.

AWSDockerPythonSQLCloud ComputingCybersecurityGCPKubernetesLDAPAzureCI/CDRESTful APIsLinuxDevOpsTerraformComplianceNetworkingJSONRisk ManagementAnsibleScripting

Posted about 1 month ago
Apply