Apply

Senior Security Engineer

Posted 14 days agoViewed

View full description

💎 Seniority level: Senior, 5+ years

📍 Location: United States

💸 Salary: 180000.0 - 230000.0 USD per year

🔍 Industry: Healthcare

🏢 Company: SmarterDx👥 101-250💰 $50,000,000 Series B about 1 year agoArtificial Intelligence (AI)HospitalInformation TechnologyHealth Care

🗣️ Languages: English

⏳ Experience: 5+ years

🪄 Skills: AWSPythonCloud ComputingKubernetesCI/CDDevOpsTerraformComplianceNetworking

Requirements:
  • 5+ years of security engineering experience with a strong focus on AWS and cloud-native infrastructure.
  • Backend coding experience, preferably in Python
  • In-depth knowledge of SOC 2 and HIPAA frameworks, including audit processes.
  • Understanding of VPC architecture, subnetting, security groups, and cloud networking fundamentals.
  • Hands-on experience with security tools such as Wiz, Snyk, GuardDuty, and AWS Config.
  • Expertise in logging and observability within distributed systems (e.g., CloudTrail, VPC Flow Logs).
  • Proficiency with Terraform and infrastructure-as-code best practices.
  • Experience with Kubernetes (EKS), Helm, and container security.
  • Strong communication skills for collaboration with technical and non-technical teams.
Responsibilities:
  • Secure and harden our AWS infrastructure, including IAM, networking, and workload visibility.
  • Implement and refine Authentication and Authorization in our Python codebase
  • Implement secure Kubernetes patterns on EKS, such as RBAC, pod security policies, and Helm-based deployments.
  • Operate and fine-tune security tools like Wiz, Snyk, GuardDuty, and AWS Config.
  • Collaborate with Engineering and Compliance to automate evidence collection and enforce policy-as-code.
  • Address complex security questionnaires from hospitals and enterprise customers.
  • Work with DevOps on Terraform-based infrastructure and secure CI/CD practices.
  • Enhance detection, alerting, and observability across cloud and containerized workloads.
  • Participate in architecture reviews, threat modeling, and security incident response.
  • Promote a culture where security is a shared responsibility across teams.
Apply

Related Jobs

Apply

📍 United States

🔍 Information Security

🏢 Company: GuidePoint Security

  • 5+ years of experience in security engineering, with a primary focus on SIEM platforms.
  • Hands-on experience with at least two of the following SIEM platforms: Splunk, Elastic, Microsoft Sentinel, Google SecOps, CrowdStrike NG-SIEM, LogScale
  • 2+ years of experience with Cribl or similar observability pipeline tools (e.g., Logstash, Fluentd, Kafka).
  • Strong knowledge of log formats, data normalization, and event correlation.
  • Familiarity with detection engineering, threat modeling, and MITRE ATT&CK framework.
  • Proficiency with scripting (e.g., Python, PowerShell, Bash) and regular expressions.
  • Deep understanding of logging from cloud (AWS, Azure, GCP) and on-prem environments.
  • Architect, implement, and maintain SIEM solutions
  • Design and manage log ingestion pipelines using tools such as Cribl Stream, Edge, or Search
  • Optimize data routing, enrichment, and filtering to improve SIEM efficiency and cost control.
  • Collaborate with cybersecurity, DevOps, and cloud infrastructure teams to integrate log sources and telemetry data.
  • Develop custom parsers, dashboards, correlation rules, and alerting logic for security analytics and threat detection.
  • Maintain and enhance system reliability, scalability, and performance of logging infrastructure.
  • Provide expertise and guidance on log normalization, storage strategy, and data retention policies.
  • Lead incident response investigations and assist with root cause analysis leveraging SIEM insights.
  • Mentor junior engineers and contribute to strategic security monitoring initiatives.

AWSPythonBashCloud ComputingCybersecurityGCPKubernetesAzureLinuxDevOpsJSONScripting

Posted 3 days ago
Apply
Apply

📍 United States

💸 105225.0 - 168360.0 USD per year

🏢 Company: Axon👥 1001-5000💰 $246,000,000 Post-IPO Equity almost 7 years agoGovTechElectronicsHardwareSoftware

  • 5-7 years of relevant experience
  • A fundamental understanding of how modern, distributed cloud-based applications function
  • Fluency in development languages like Python or Golang, and shell scripting (bash/powershell)
  • Deep familiarity with Git and collaborative workflows like GitHub or GitLab
  • Demonstrated experience in security best practices, or an interest in building and expanding that knowledge
  • Experience responding to and investigating information security events and incidents
  • Experience working with cloud-based APIs and infrastructure
  • Strong problem solving skills, including the ability to analyze complex information to discover root cause
  • Strong written and verbal communication skills
  • Design, develop, implement, and maintain automated tooling to improve Axon’s ability to detect and respond to security events
  • Participate in an on-call rotation to investigate and remediate escalated security events, serving as a final point of escalation for complex issues beyond routine alerts
  • Evaluate and integrate new security tools and technologies into the SOC
  • Set a high technical bar for the team
  • Mentor more junior team members
  • Partner with teams throughout the company to help design and build scalable solutions that improve Axon’s security posture
  • Engineer and implement automated solutions to address current security attack methods and detection techniques
  • Be the lead climber for complex tasks and projects
  • Follow best practices for software development, including version control, testing, continuous integration and deployment, and documentation
  • Provide input to the overall Information Security Program for enhancing the information security strategy when necessary
  • Stay current on security industry trends, attack techniques, mitigation techniques, and security technologies by attending conferences, networking with peers, and other educational opportunities

AWSPythonBashCloud ComputingCybersecurityGitAPI testingGoCI/CDRESTful APIsLinuxDevOpsJSONScripting

Posted 7 days ago
Apply
Apply

📍 United States

🧭 Full-Time

💸 157675.0 - 212000.0 USD per year

🔍 Enterprise Security

🏢 Company: Samsara👥 1001-5000💰 Secondary Market over 4 years ago🫂 Last layoff about 5 years agoCloud Data ServicesBusiness IntelligenceInternet of ThingsSaaSSoftware

  • 8+ years of relevant experience with demonstrated impact and influence across a large part of an organization, with 5+ years in an Enterprise Security specific role.
  • Deep expertise in enterprise security engineering best practices.
  • Strong scripting skills with Python, including experience building tools and automations.
  • Demonstrated experience building, integrating, and maintaining enterprise security tools.
  • Strong familiarity with common security problems and the ability to independently judge their severity and impact on the business.
  • Hands-on experience with automation tools (e.g., Tines, AWS Lambda) and common security platforms (e.g., Crowdstrike, Zscaler, Wiz).
  • Track record of delivering large scope, impactful work across multiple quarters and collaborating effectively across teams.
  • Own and drive execution of multiple key enterprise security systems, ensuring they are well-integrated, documented, and effectively support Samsara’s security goals.
  • Write clear, concise documentation and runbooks for enterprise security workflows.
  • Collaborate with partners across Engineering, IT, and Security to ensure proper implementation of security tools and policies.
  • Occasionally assist the Security Operations team during security investigations, acting as a technical subject matter expert within your domain.
  • Partner with engineering teams to triage and support remediation of vulnerabilities and misconfigurations in systems and applications.
  • Mentor engineers in the Security team to grow their domain knowledge, tool-specific skills, and communication abilities.
  • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices.

AWSPythonCybersecurityCI/CDLinuxTerraformScripting

Posted 7 days ago
Apply
Apply

📍 United States

🔍 Information Security

🏢 Company: GuidePoint Security

  • 8+ years of experience in security engineering, with strong emphasis on endpoint, cloud-native and SaaS environments.
  • In-depth knowledge of operating systems including Linux, Windows, Mac and network protocols TCP/IP, DNS, SMTP, HTTP/S and SSH.
  • Experience with IAM, including federated identity, RBAC, lifecycle management, and cloud-native policy design.
  • Familiarity with identity protocols and standards including SAML, OIDC, OAuth2, and SCIM.
  • Proven track record implementing data protection controls in production.
  • Solid understanding of cloud security architecture, network segmentation, endpoint hardening, and service exposure minimization.
  • Hands-on experience with EDR, SIEM vulnerability management, and cloud security posture management (CSPM).
  • Demonstrated experience supporting incident detection, event triage, investigation, and response workflows.
  • Strong understanding of modern security frameworks (NIST, CIS Controls, ISO 27001, SOC 2).
  • Excellent communication and collaboration skills, including the ability to work across functions and communicate risks effectively.
  • Architect and implement security controls across cloud platforms, endpoints, and SaaS applications.
  • Implement and monitor data protection technologies including DLP, Labeling, Scanning, etc. across SaaS and Cloud.
  • Define and enforce trust boundaries across cloud networks, applications, and endpoints — with a focus on segmentation, identity isolation, and minimal privilege.
  • Lead the collaboration with IT on the design and monitoring of comprehensive Identity and Access Management (IAM) programs, including role-based access control Identity federation, SSO, SAML, OIDC, and SCIM integrations.
  • Drive automation for security processes and control enforcement using Python and modern infrastructure-as-code tools.
  • Support threat hunting, event triage and incident response by analyzing security events and telemetry from detection tools.
  • Define and implement secure configuration baselines for cloud services, endpoints, and user environments.
  • Contribute to security architecture reviews and support secure-by-design patterns for new systems.
  • Support audit readiness, compliance assessments (e.g., SOC 2, ISO 27001), and risk management activities.
  • Document playbooks, configurations, architecture diagrams, and process flows.
  • Mentor peers and cross-functional teams on security risks, best practices, and secure architecture principles.

AWSPythonCloud ComputingCybersecurityOAuthLinuxDevOpsTerraformScripting

Posted 9 days ago
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Healthcare

🏢 Company: Rad AI👥 101-250💰 $60,000,000 Series C 4 months agoArtificial Intelligence (AI)Enterprise SoftwareHealth Care

  • 4+ years of experience in Application Security.
  • 2+ years of experience in DevSecOps or Cloud Security.
  • Demonstrated knowledge of security frameworks and standards (e.g., OWASP ASVS, NIST SSDF, AWS Well-Architected Framework).
  • Experience with security tools and technologies (e.g., Kubernetes, Snyk, Wiz, GitHub Actions, AWS GuardDuty).
  • Integrate and manage security tools across CI/CD pipelines (SAST, SCA, IaC, container scanning) to ensure issues are caught early, before they impact production.
  • Perform code and system security assessments, then partner with developers to triage and remediate vulnerabilities quickly and effectively.
  • Conduct architectural reviews to uncover design-level risks, clearly documenting threats and mitigation strategies that shape secure system designs.
  • Champion secure coding practices through education and engagement, helping teams adopt a security-first mindset in their workflows.
  • Contribute to security policies, design standards, and development guidelines that raise the security bar across the company.
  • Continuously assess and strengthen our AWS cloud environments (and other cloud platforms) to reduce risk and increase resilience.
  • Proactively detect and remediate misconfigurations in IAM, networking, encryption, and workloads to minimize exposure and reduce risk.
  • Collaborate with DevOps to secure infrastructure-as-code by implementing automated policy enforcement and cloud security benchmarks.
  • Monitor and respond to alerts from security tools (IDS/IPS, SIEM, EDR), helping us to detect threats early and enable fast, informed responses.
  • Develop and maintain incident response plans, playbooks, and tooling to ensure swift and coordinated responses to security events.
  • Drive security-focused projects from start to finish, including tool rollouts, vulnerability remediation efforts, and cloud hardening initiatives.

AWSCloud ComputingCybersecurityKubernetesCI/CDRESTful APIsLinuxDevOpsTerraformMicroservicesComplianceJSONScripting

Posted 24 days ago
Apply
Apply
🔥 Senior Security Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

💸 110000.0 - 130000.0 USD per year

🔍 Healthcare Information Technology

  • 5+ years of experience in product or infrastructure security-related software engineering roles
  • Proficiency in a programming language, testing practices, and thorough documentation
  • Expertise with multiple technologies in the Bluesight Security System and our infrastructure as required: Cloud-based IaaS Systems - AWS required, Vulnerability Mgmt. and Scanning (such as Nessus, OpenVAS)SIEM and logging technology (such as Splunk, Elastic, LogRhythm, SolarWinds)Enterprise VPN (such as Cisco AnyConnect, Fortinet VPN, Palo Alto Global Protect)Host-based security tools (such as Sophos, ClamAV, Wazuh/OSSEC, Tripwire)
  • Experience developing, implementing, and monitoring internal practices for SOC2, HIPAA or ISO information security compliance standards
  • Ability to represent Bluesight’s security posture and the maturity of our operations to customers
  • Subject matter expertise in security best practices and the ability to quickly make correct risk assessments that prioritize the overall benefit to the company
  • Track record of building self-service and high-quality tools with a customer-driven mindset
  • A desire to share your expertise through documentation and mentorship
  • A desire to work with individuals with diverse security ideas and priorities
  • Autonomy and proactivity around driving work to completion in the face of ambiguity
  • Build and manage, well-architected and relevant cloud-based data classification and threat detection systems for assessing and resolving risk vectors
  • Partner with internal product teams to implement a secure-by-default design into their own products
  • Perform security audits and risk assessments, identify vulnerabilities, and create plans and preventative measures to protect against threats.
  • Assist with responses to customer questions, questionnaires, and contract issues regarding compliance and security.
  • Conduct reviews, train employees and advise on matters related to security and compliance across Bluesight
  • Lead security incident response teams and partner with Bluesight engineering teams to understand and resolve incidents that arise
  • Promote a culture of operational excellence by monitoring our systems and code, and being on-call to support the health of our services
  • Design security policies and procedures that will keep pace with the rapid growth of Bluesight
  • Document your work and decision-making processes, and lead presentations and discussions in a way that is easy for others to understand
  • Uphold a culture of collaboration, transparency, creativity, inclusion, and making data-driven decisions

AWSPythonAWS EKSBashCloud ComputingCybersecurityElasticSearchMicrosoft Active DirectoryAmazon Web ServicesAPI testingData StructuresCommunication SkillsCollaborationCI/CDProblem SolvingRESTful APIsLinuxDevOpsTerraformDocumentationComplianceTrainingRisk ManagementScriptingData analytics

Posted about 1 month ago
Apply
Apply

📍 United States

🔍 Software Development

  • Hands-on experience in modern DevOps environments
  • Experience building and implementing apps in a production-like environment
  • Python, PowerShell, or other scripting languages
  • Software composition analysis / software bill of materials
  • Cloud platforms and automation tools (i.e. Terraform, Ansible, Chef, Puppet)
  • Container and platform technology
  • Design, building, and automating new components of our application security program
  • Leverage expertise in AppDev, secure software development, scripting and data analytics to automatically collect, normalize and analyze intelligence artifacts, as well as to automate the generation of an assessment product supporting different intelligence requirements
  • Partnering with stakeholders across the security group and major technology teams

PythonSoftware DevelopmentCloud ComputingCybersecurityCommunication SkillsCI/CDRESTful APIsDevOpsTerraformAnsibleScripting

Posted about 1 month ago
Apply
Apply

📍 United States

🧭 Full-Time

💸 198000.0 - 267950.0 USD per year

🔍 Software Development

🏢 Company: Headway👥 201-500💰 $125,000,000 Series C over 1 year agoMental Health Care

  • Have 0 → 1 security experience: You have 5+ years experience in security and/or software engineering roles on startup or growth stage teams with a demonstrated history of working on detections & response security-related projects.
  • Strong technical depth and breadth: You have technical experience with building secure platforms and products at a deep level. You want to understand security systems and improve their efficiency and scalability.
  • Strong cross-functional experience: You love partnering with other teams to help both teams achieve their goals.
  • Thrive in ambiguity: You love tackling ambiguous problems in a fast-paced environment with an optimistic and energizing attitude.
  • Innovation at Scale: You seek opportunities to lead the industry in implementing the latest security and privacy technologies.
  • Results driven: You care deeply about creating impact and driving results for Headway’s business.
  • Mission driven: You are motivated by Headway’s mission, increasing access to high quality mental health care.
  • Build foundational detection and response infrastructure: build the services and tooling that will enable proactive security risk and anomaly detections
  • Develop and improve automated detections: prioritize security event infrastructure and detections processes to enable react in real-time
  • Enable analysis of security events from all sources (e.g. cloud infrastructure, SaaS IdP, logs) and identify gaps in coverage: prioritize the highest value signals and potential tradeoffs in priorities of both production and corporate services
  • Partner with Trust and Engineering teams to identify risk signals -  Collaborate with Trust and Engineering teams to recognize and flag potential risk signals during all stages of Headway event’s lifecycle.
  • Assist in ongoing security operations: You will be part of the security and privacy team and have responsibilities to assist in incident response, vulnerability management, penetration testing, security reviews, and other operational tasks to ensure that our security program is operating at a world-class level.

AWSDockerPostgreSQLPythonCloud ComputingCybersecurityKafkaSnowflakeTypeScriptFastAPIReactCI/CDRESTful APIsDevOps

Posted about 1 month ago
Apply
Apply

📍 Canada, Mexico, United States

🏢 Company: Jobgether👥 11-50💰 $1,493,585 Seed about 2 years agoInternet

  • 4-5 years of hands-on experience in detection and response, with expertise in enterprise SaaS environments.
  • Proven experience in building and optimizing log ingestion and normalization pipelines.
  • Expertise in Detection as Code using Python and SQL.
  • Subject matter expertise in endpoint security and/or cloud security, including AWS, Azure, and GCP.
  • Strong knowledge of Mac, Linux, and Windows operating systems.
  • Experience with Kubernetes is a plus.
  • Demonstrated ability to collaborate with multiple teams in security roles and contribute to incident response efforts.
  • Background in Information Security, Computer Science, Forensics, or equivalent work experience.
  • Lead detection and incident response efforts, including monitoring, threat detection, investigation, and automation of response playbooks.
  • Design and optimize log pipelines, ensuring consistency across EDR, SIEM, SOAR, and other security tools to enhance threat detection.
  • Automate security infrastructure and processes using Terraform, Kubernetes, and scripting to improve efficiency and scalability.
  • Ensure compliance with data retention policies and support audits to maintain regulatory standards.
  • Collaborate with product security, infrastructure, and IT teams to mature the detection engineering program and strengthen overall security.
  • Participate in on-call rotations and contribute to cross-team security initiatives.

AWSPythonSQLCloud ComputingGCPKubernetesMac OS XAzureLinuxTerraformScripting

Posted about 1 month ago
Apply
Apply

📍 Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, or Washington, D.C.

🧭 Full-Time

💸 144000.0 - 189000.0 USD per year

🔍 Health Insurance

🏢 Company: Oscar Health👥 1001-5000💰 $140,000,000 Private over 4 years ago🫂 Last layoff about 5 years agoHealth InsuranceInsurTechInsuranceHealth Care

  • 3+ years experience in security engineering or technical related role, focused on security operations
  • Deep understanding of security concepts, including network security, endpoint security, vulnerability management, and incident response.
  • Hands on experience with security information and event management (SIEM) systems.
  • Experience with security automation and orchestration tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash).
  • Design, implement, and maintain security monitoring and detection systems, including SIEM, SOAR, and XDR platforms.
  • Develop and implement security automation workflows to improve security operations and incident response processes.
  • Enhance security visibility by implementing robust logging and alerting mechanisms across the environment.
  • Identify and improve security vulnerabilities and misconfigurations.
  • Lead incident response efforts, including containment, eradication, and postincident analysis.
  • Collaborate with other teams to integrate security best practices into their workflows.
  • Research emerging security technologies and threats.
  • Mentor junior security engineers.
  • Contribute to the development and maintenance of security policies and procedures.
  • Participate in on-call rotation for security incidents.
  • Compliance with all applicable laws and regulations.
  • Other duties as assigned.

AWSPythonCloud ComputingCybersecurityGCPAzureCommunication SkillsAnalytical SkillsProblem SolvingMentoringLinuxComplianceTeamworkScripting

Posted 3 months ago
Apply