6 months ago
Remote, United StatesStaff+
Base Salary
$220k - $240k/yr
Responsibilities
- Lead security architecture and design reviews for applications, infrastructure, and integrations.
- Conduct and coordinate penetration testing, threat modeling, and security reviews for critical services, features, and third-party integrations.
- Design and implement security automation in CI/CD pipelines to enforce secure coding practices and infrastructure policies.
- Partner with infrastructure and DevOps teams to secure AWS platforms and improve identity, network, and workload security.
- Build security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals.
- Identify systemic weaknesses and design controls that defend against broad classes of attacks.
- Support developers with secure architecture guidance, code reviews, and security enablement.
- Lead incident response investigations and improve processes for identifying, analyzing, and mitigating security incidents.
- Own and evolve the bug bounty program, vulnerability triage, response processes, and vulnerability management workflows.
- Develop security standards, playbooks, and training programs for engineering teams.
- Help define the security roadmap and prioritize initiatives that improve risk posture and operational efficiency.
Requirements
- Deep understanding of application security, cloud security, modern threat landscapes, OWASP Top 10, and MITRE ATT&CK.
- Strong software engineering background with production-grade coding or automation experience in Python, TypeScript, or similar.
- Hands-on experience securing AWS cloud-native infrastructure, including IAM, networking, and containerized workloads.
- Experience building or integrating DevSecOps pipelines with SAST, DAST, infrastructure-as-code scanning, and container security tooling.
- Experience designing security telemetry pipelines using SIEM platforms, observability systems, or data lakes.
- Experience with penetration testing, threat modeling, or architectural security reviews.
- Ability to collaborate with engineering, DevOps, and product teams to drive secure design decisions.
- Excellent communication skills for explaining complex security risks and trade-offs to technical and non-technical stakeholders.
- Strong understanding of SaaS architectures, distributed systems, and internet-facing platforms.
- Experience developing security frameworks aligned with CIS benchmarks, NIST, SOC2, PCI, or HIPAA requirements.
- Experience building security detections, threat intelligence pipelines, or runtime protection mechanisms.
- Hands-on experience with Kubernetes, container security, and infrastructure-as-code using Terraform and Ansible.
Benefits
- Platinum medical, dental, and vision coverage.
- Free life insurance, including long-term and short-term disability coverage.
- Unlimited PTO, uncapped vacation days, and paid holidays.
- Maternity and paternity family leave.
- Assured contributes 3% to a 401(k), even if the employee does not contribute.
- Remote work with lunch twice per week, a monthly phone stipend, and other home-office perks.
- Health FSAs and HSAs.
- Team events and offsites for the remote team.
Tech Stack
Categories
About Assured
Assured builds an AI-driven claims intelligence platform used by insurers to ingest, evaluate, and process claims. Its products include self-service claim filing, data enrichment, fraud detection, and ML-guided decisioning, delivered as enterprise software to large carriers. Founded in 2019 and headquartered in Palo Alto, the privately held company focuses on improving insurers’ claims operations and analytics.
