
Security Engineer
Cala Health5 hours ago
San Mateo, CA, USAMid Level
H1B Sponsor
Base Salary
$155k - $190k/yr
Responsibilities
- Monitor and manage open-source and third-party dependencies with Software Composition Analysis tools and address supply chain risks.
- Track and prioritize CVEs and collaborate with development teams to automate dependency updates and security scanning in CI/CD pipelines.
- Manage external penetration tests and bug bounty programs, validate findings, and create remediation plans.
- Conduct internal vulnerability scans and architectural risk assessments.
- Own security remediation across infrastructure, networks, and applications, including code and configuration reviews.
- Implement security controls and guardrails such as IAM policies, network segmentation, and secrets management.
- Participate in the incident response team and on-call rotation to detect, contain, and eradicate security incidents.
- Investigate security logs from SIEM, EDR, and cloud providers and conduct post-incident root-cause reviews.
- Design and facilitate security tabletop exercises for technical teams and executive leadership.
- Monitor AWS and GCP configurations through Cloud Security Posture Management to prevent drift and misconfigurations.
- Define and report security metrics such as MTTR and patch compliance.
- Support evidence gathering and control maintenance for SOC 2, ISO 27001, and HIPAA.
- Mentor junior engineers and create targeted security awareness and training content.
Requirements
- At least 3 years of experience in Security Engineering, Application Security, or Incident Response.
- Hands-on experience with modern security tools such as Snyk, Dependabot, Burp Suite, Splunk, and Datadog.
- Strong understanding of OWASP Top 10, CWE, and cloud security best practices.
- Hands-on experience with CI/CD pipelines and build automation tools, including Jenkins, GitHub Actions, or GitLab CI.
- Proficiency in Python and Shell scripting, including Bash.
- Familiarity with Go, JavaScript, TypeScript, or Rust is preferred.
- Experience securing cloud-native environments using Docker and AWS or GCP, including AWS Inspector and GuardDuty, is preferred.
- Experience with GRC platforms such as Vanta is preferred.
- Familiarity with Infrastructure as Code security scanning tools such as Checkov and TFLint is preferred.
- Relevant certifications such as CISSP, CEH, OSCP, GCIH, or AWS Certified Security are preferred.
- Familiarity with bug bounty services such as BugCroud is preferred.
- Experience securing cloud-connected IoT devices, including provisioning, key rotation, and OTA update security, is preferred.
- Applicants must be authorized to work in the United States or eligible for a sponsorship path supported by Cala Health.
Benefits
- Remote work, with a hybrid option for employees local to the San Mateo, California headquarters.
- Full-time, exempt employment.
- Access to tools, training, and mentoring.
- U.S. work authorization is required, or eligibility for a sponsorship path Cala Health can support.
Tech Stack
AWSBashDatadogDockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaScriptJenkinsPythonRustSplunkTypeScript
About Cala Health
Cala Health is a bioelectronic medicine company transforming the standard of care for chronic disease. The company’s wearable neuromodulation therapies merge innovations in neuroscience and technology to deliver individualized peripheral nerve stimulation. The first indication for Cala Health’s wearable therapy is essential tremor, a disease experienced by more than seven million people and characterized by severe hand tremors. New therapies are under development in neurology, cardiology, and psychiatry. The company is headquartered in the San Francisco Bay Area and backed by leading investors in both healthcare and technology.