Staff Cloud Security Engineer
Included Health11 months ago
Base Salary
$161k - $296k/yr
Responsibilities
- Design and implement cloud authorization frameworks covering roles, resource restrictions, task-based access, and granular engineering access.
- Lead implementation of just-in-time access controls for production systems, secrets, and data.
- Develop Python and Go security automation, integrations, tools, and services for security operations, vulnerability management, compliance, and incident response.
- Implement and audit security configurations with Terraform and Infrastructure as Code.
- Build centralized controls such as an engineering-owned Web Application Firewall and secure webhook-testing mechanisms.
- Establish secure development-toolchain practices and container-hardening standards to reduce supply-chain and infrastructure risks.
- Remediate legacy GCP environments and implement granular data-access controls for sensitive data.
- Partner with infrastructure, engineering, DevOps, and product teams to integrate automated security controls into systems, architectures, and CI/CD pipelines.
- Conduct security assessments and threat modeling, support incident response, and document security architectures, controls, automation, and playbooks.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- At least five years of cloud security experience, especially designing and implementing AWS security solutions.
- Hands-on software development experience in Python and Go for security automation, tools, and infrastructure management.
- Experience designing authorization and access-control frameworks, including RBAC, ABAC, policy-as-code, and JIT access solutions.
- Deep proficiency writing and maintaining Terraform modules for security-focused Infrastructure as Code.
- Experience with Docker and Kubernetes/EKS, including hardening containerized environments.
- Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices.
- Experience with security logging, monitoring, alerting, SIEM, AWS CloudTrail, CloudWatch, GuardDuty, and scripting against security APIs.
- Experience with cloud security frameworks, especially HIPAA, regulations, and standards.
- Familiarity with Ruby is a plus.
Benefits
- Remote-first role
- 401(k) savings plan through Fidelity
- Medical, vision, dental, and disability insurance options
- Paid Time Off and Discretionary Time Off
- 12 weeks of fully paid parental leave
- Family-building and compassionate leave benefits, including fertility coverage and up to $25,000 for surrogacy or adoption
- Work-from-home reimbursement
Categories
About Included Health
Included Health delivers personalized, all-in-one healthcare to millions of people nationwide. We provide healthcare access, answers, and advocacy through a modern experience designed to treat people better—mind, body, and wallet. It’s all included: - virtual and in-person care - system-wide navigation and care coordination - 24/7 support for every clinical and administrative needs Our members experience better care, better outcomes, more healthy days, and lower overall costs.