Included Health

Senior Security Engineer

Included Health

Apply
2 months ago
Remote, United States
Senior
H1B Sponsor

Base Salary

$128k - $181k/yr

Responsibilities

  • Design and implement Just-in-Time access controls and Privileged Access Management workflows.
  • Conduct platform permission reviews and implement a least-privilege access model.
  • Ensure all production access requests and approvals are captured in audit logs.
  • Lead the implementation and operation of security tools in the CI/CD pipeline.
  • Develop custom SAST rules for detecting high-risk flaw patterns.
  • Partner with engineering to deploy IDE plugins and automated PR checks.
  • Conduct manual security code reviews for high-risk features.
  • Design and maintain automation for the vulnerability management lifecycle.
  • Engineer automated workflows to triage and validate new vulnerabilities.
  • Develop security automation scripts and tools in Python or Go.
  • Collaborate with SecOps to build SIEM correlation rules and response playbooks.
  • Design and implement encryption strategies for data protection.
  • Manage the cryptographic key lifecycle and key management systems.
  • Design secure cloud network architectures and network segmentation strategies.
  • Lead remediation of cloud security findings.
  • Implement and manage a centralized security control plane.
  • Design and enforce security configurations for diverse operating systems.
  • Manage and tune endpoint security solutions.
  • Lead threat modeling sessions and secure design reviews.
  • Act as a security partner and subject matter expert for product teams.
  • Develop security programs for emerging risks.

Requirements

  • 6+ years of experience in security engineering with expertise in application and cloud security.
  • Strong proficiency in Python or Go for security automation.
  • Experience with SAST, DAST, and SCA tools and CI/CD automation.
  • Experience in cloud security, particularly AWS or GCP.
  • Knowledge of identity and encryption management.
  • Experience securing containerized environments like Docker and Kubernetes.
  • Previous experience in highly regulated industries such as healthcare or fintech.
  • Excellent communication skills for explaining security risks to stakeholders.

Benefits

  • Remote-first culture.
  • 401(k) savings plan through Fidelity.
  • Comprehensive medical, vision, and dental coverage.
  • Paid Time Off and Discretionary Time Off.
  • 12 weeks of 100% Paid Parental leave.
  • Family Building & Compassionate Leave benefits.
  • Work-From-Home reimbursement.

Tech Stack

AWSDockerGoGoogle Cloud PlatformKubernetesPythonTerraform

Categories

Security