Senior Security Engineer
Included Health8 months ago
Base Salary
$128k - $181k/yr
Responsibilities
- Design and implement just-in-time access controls, privileged access management workflows, least-privilege models, and auditable production access processes.
- Lead security tooling across the software development lifecycle, including SAST, DAST, SCA, secrets scanning, IDE plugins, and automated pull-request checks.
- Create custom SAST rules and conduct manual security reviews for high-risk features and cryptographic implementations.
- Build automation for vulnerability triage, validation, assignment, lifecycle management, security operations, and compliance checks using Python or Go.
- Partner with SecOps on SIEM correlation rules and automated response playbooks.
- Design encryption strategies, manage cryptographic key lifecycles, and administer key management systems to protect PHI under HIPAA.
- Design secure cloud network architectures, segmentation strategies, and centralized security control planes, and lead remediation of cloud security findings.
- Implement DLP policies and enforce security hardening standards across macOS, Windows, and Linux through MDM or UEM platforms.
- Manage and tune endpoint security solutions such as EDR and XDR.
- Lead threat modeling and secure design reviews for features, architectures, applications, and APIs.
- Serve as an embedded security partner and subject matter expert for product and platform teams, providing technical guidance and mentorship.
- Develop security programs for emerging risks, including SaaS security and AI security.
Requirements
- At least 6 years of security engineering experience with hands-on application security and cloud security expertise, preferably in AWS.
- Strong proficiency in Python or Go for security automation.
- Demonstrated experience in at least two core areas including application and SDLC security, security automation, cloud security, identity and encryption, or endpoint and data security.
- Experience with SAST, DAST, SCA, CI/CD automation, SOAR platforms, Terraform, AWS or GCP security, IAM, WAF, CSPM, JIT access, PAM, cryptographic key lifecycles, EDR/XDR, DLP, or MDM solutions.
- Experience securing Docker and Kubernetes environments.
- Experience in healthcare, fintech, or another highly regulated industry.
- Ability to communicate complex security risks to technical and non-technical stakeholders.
- Preferred experience with iOS and Android application security.
- Familiarity with AI security principles and governing LLM usage.
- Experience building or managing a SaaS security or SSPM program.
- Background in software development, DevOps, or Site Reliability Engineering.
- Experience with incident response, threat hunting, and forensics.
- Relevant certifications such as CISSP, GIAC certifications, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, OSCP, CEH, or other offensive security certifications is preferred.
- Open-source security contributions or active security community participation is preferred.
Benefits
- Remote-first culture
- 401(k) savings plan through Fidelity
- Medical, vision, dental, and disability insurance options
- Paid Time Off and Discretionary Time Off
- 12 weeks of 100% paid parental leave
- Family-building and compassionate leave, including fertility coverage and up to $25,000 for surrogacy or adoption
- Work-from-home reimbursement
Tech Stack
Categories
About Included Health
Included Health delivers personalized, all-in-one healthcare to millions of people nationwide. We provide healthcare access, answers, and advocacy through a modern experience designed to treat people better—mind, body, and wallet. It’s all included: - virtual and in-person care - system-wide navigation and care coordination - 24/7 support for every clinical and administrative needs Our members experience better care, better outcomes, more healthy days, and lower overall costs.