Senior Security Engineer
Included Health
2 months ago
Remote, United States
Senior
H1B Sponsor
Base Salary
$128k - $181k/yr
Responsibilities
- Design and implement Just-in-Time access controls and Privileged Access Management workflows.
- Conduct platform permission reviews and implement a least-privilege access model.
- Ensure all production access requests and approvals are captured in audit logs.
- Lead the implementation and operation of security tools in the CI/CD pipeline.
- Develop custom SAST rules for detecting high-risk flaw patterns.
- Partner with engineering to deploy IDE plugins and automated PR checks.
- Conduct manual security code reviews for high-risk features.
- Design and maintain automation for the vulnerability management lifecycle.
- Engineer automated workflows to triage and validate new vulnerabilities.
- Develop security automation scripts and tools in Python or Go.
- Collaborate with SecOps to build SIEM correlation rules and response playbooks.
- Design and implement encryption strategies for data protection.
- Manage the cryptographic key lifecycle and key management systems.
- Design secure cloud network architectures and network segmentation strategies.
- Lead remediation of cloud security findings.
- Implement and manage a centralized security control plane.
- Design and enforce security configurations for diverse operating systems.
- Manage and tune endpoint security solutions.
- Lead threat modeling sessions and secure design reviews.
- Act as a security partner and subject matter expert for product teams.
- Develop security programs for emerging risks.
Requirements
- 6+ years of experience in security engineering with expertise in application and cloud security.
- Strong proficiency in Python or Go for security automation.
- Experience with SAST, DAST, and SCA tools and CI/CD automation.
- Experience in cloud security, particularly AWS or GCP.
- Knowledge of identity and encryption management.
- Experience securing containerized environments like Docker and Kubernetes.
- Previous experience in highly regulated industries such as healthcare or fintech.
- Excellent communication skills for explaining security risks to stakeholders.
Benefits
- Remote-first culture.
- 401(k) savings plan through Fidelity.
- Comprehensive medical, vision, and dental coverage.
- Paid Time Off and Discretionary Time Off.
- 12 weeks of 100% Paid Parental leave.
- Family Building & Compassionate Leave benefits.
- Work-From-Home reimbursement.
Tech Stack
AWSDockerGoGoogle Cloud PlatformKubernetesPythonTerraform
Categories
Security