
Security Engineer
Cala Health2 months ago
San Mateo, CA, USAMid Level
Base Salary
$155k - $190k/yr
Responsibilities
- Monitor and manage open-source and third-party dependencies with Software Composition Analysis tools and address supply chain risks.
- Track and prioritize CVEs and collaborate with development teams to automate dependency updates and security scanning in CI/CD pipelines.
- Manage external penetration tests and bug bounty programs, validate findings, and create remediation plans.
- Conduct internal vulnerability scans and architectural risk assessments.
- Own security remediation across infrastructure, networks, and applications, including code and configuration reviews.
- Implement security controls and guardrails such as IAM policies, network segmentation, and secrets management.
- Participate in the incident response team and on-call rotation to detect, contain, and eradicate security incidents.
- Investigate security logs from SIEM, EDR, and cloud providers and conduct post-incident root-cause reviews.
- Design and facilitate security tabletop exercises for technical teams and executive leadership.
- Monitor AWS and GCP configurations through Cloud Security Posture Management to prevent drift and misconfigurations.
- Define and report security metrics such as MTTR and patch compliance.
- Support evidence gathering and control maintenance for SOC 2, ISO 27001, and HIPAA.
- Mentor junior engineers and create targeted security awareness and training content.
Requirements
- At least 3 years of experience in Security Engineering, Application Security, or Incident Response.
- Hands-on experience with modern security tools such as Snyk, Dependabot, Burp Suite, Splunk, and Datadog.
- Strong understanding of OWASP Top 10, CWE, and cloud security best practices.
- Hands-on experience with CI/CD pipelines and build automation tools, including Jenkins, GitHub Actions, or GitLab CI.
- Proficiency in Python and Shell scripting, including Bash.
- Familiarity with Go, JavaScript, TypeScript, or Rust is preferred.
- Experience securing cloud-native environments using Docker and AWS or GCP, including AWS Inspector and GuardDuty, is preferred.
- Experience with GRC platforms such as Vanta is preferred.
- Familiarity with Infrastructure as Code security scanning tools such as Checkov and TFLint is preferred.
- Relevant certifications such as CISSP, CEH, OSCP, GCIH, or AWS Certified Security are preferred.
- Familiarity with bug bounty services such as BugCroud is preferred.
- Experience securing cloud-connected IoT devices, including provisioning, key rotation, and OTA update security, is preferred.
- Applicants must be authorized to work in the United States or eligible for a sponsorship path supported by Cala Health.
Benefits
- Remote work, with a hybrid option for employees local to the San Mateo, California headquarters.
- Full-time, exempt employment.
- Access to tools, training, and mentoring.
- U.S. work authorization is required, or eligibility for a sponsorship path Cala Health can support.
Tech Stack
AWSBashDatadogDockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformJavaScriptJenkinsPythonRustSplunkTypeScript
Categories
About Cala Health
Cala Health develops non-invasive, prescription wearable neuromodulation devices for people with essential tremor; its Cala kIQ wrist-worn therapy delivers individualized peripheral nerve stimulation. The company sells regulated medical devices through clinicians to patients, with additional programs in neurology, cardiology, and psychiatry in development. Founded in 2014 and headquartered in San Mateo, California, Cala Health is privately held.