Senior Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in USA
Remote
128K-235K Annually
Senior level
Healthtech
Our mission is to raise the standard of healthcare for everyone.
The Role
Hands-on senior security engineer responsible for designing and automating security controls across cloud and application stacks. Lead implementation of PAM/JIT, vulnerability management, SAST/DAST/SCA integration, security automation (Python/Go/Terraform/Tines), endpoint and DLP protections, cloud network hardening, key management, SIEM correlation, and developer-focused security tooling and reviews to protect PHI and advance security posture.
Summary Generated by Built In
The Senior Security Engineer is a hands-on, high-impact technical role responsible for designing, implementing, and automating robust security controls across our application stack and cloud environments (primarily AWS, with GCP considerations).
 
You will strengthen our end-to-end security posture by proactively identifying and remediating vulnerabilities, developing advanced security solutions across the SDLC through production, and building scalable automation using Python, Go, Terraform, and Tines. Your work will directly contribute to the prevention of unauthorized PHI access and exfiltration, helping us evolve toward a proactive defense model.
 
This is a remote role reporting to the Senior Manager, Security Engineering and plays a critical role in advancing our overall security maturity and resilience.

Responsibilities:

  • Design, build, and implement Just-in-Time (JIT) access controls and Privileged Access Management (PAM) workflows to eliminate standing privileged accounts in production.
  • Conduct platform permission reviews and implement a least-privilege access model for cloud and application roles.
  • Ensure 100% of production access requests and approvals are captured in audit logs.
  • Lead the implementation, tuning, and operation of security tools in the CI/CD pipeline, including SAST, DAST, SCA, and secrets scanning.
  • Develop custom SAST rules to detect specific, high-risk flaw patterns, such as authorization bypasses or insecure PII/PHI handling.
  • Partner with engineering to deploy IDE plugins and automated PR checks that block sensitive data exposure before deployment.
  • Conduct manual security code reviews for high-risk features and cryptographic implementations.
  • Design, build, and maintain automation for the end-to-end vulnerability management lifecycle.
  • Engineer automated workflows to triage, validate, and assign new vulnerabilities
  • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations and compliance checks.
  • Partner with SecOps to build high-fidelity SIEM correlation rules and automated response playbooks.
  • Design, implement, and maintain encryption strategies for data at rest and in transit, ensuring PHI is protected in compliance with HIPAA.
  • Manage the cryptographic key lifecycle and administer key management systems
  • Design and implement secure cloud network architectures (VPCs, subnets, security groups, NACLs) and network segmentation strategies.
  • Lead the remediation of cloud security findings
  • Implement and manage a centralized security control plane
  • Design and implement Data Loss Prevention (DLP) policies for endpoints and cloud services to protect against sensitive data exfiltration.
  • Design and enforce security configurations and hardening standards for diverse operating systems (macOS, Windows, Linux) via MDM/UEM platforms.
  • Manage and tune endpoint security solutions, including EDR/XDR (e.g., CrowdStrike).
  • Lead threat modeling sessions for new features and conduct secure design reviews of system architectures, applications, and APIs.
  • Act as an embedded security partner and subject matter expert for product and platform teams, providing technical guidance and mentorship.
  • Develop and manage security programs for emerging risks, including SaaS security and AI security.

Required Qualifications:

  • 6+ years of experience in security engineering, with hands-on expertise in both application security and cloud security (AWS strongly preferred).
  • Strong proficiency in at least one scripting or programming language (Python or Go preferred) for security automation.
  • Demonstrable experience in two or more of the following core areas: 1) Application & SDLC Security, specifically with SAST, DAST, and SCA tools (e.g., Semgrep, Snyk, Burp Suite) and CI/CD automation; 2) Security Automation & Engineering using SOAR platforms (e.g., Tines) and Terraform; 3) Cloud Security (AWS/GCP) with a focus on designing secure cloud-native services (VPCs, IAM, WAF, CSPM); 4) Identity & Encryption, including JIT access controls, PAM, and cryptographic key lifecycles; or 5) Endpoint & Data Security utilizing EDR/XDR, DLP, and MDM solutions.
  • Experience securing containerized environments (Docker, Kubernetes).
  • Previous experience in healthcare, fintech, or other highly regulated industries
  • Excellent communication skills, with the ability to explain complex security risks to both technical and non-technical stakeholders.

Preferred Qualifications:

  • Experience with mobile application security (iOS/Android).
  • Familiarity with AI security principles and governing LLM usage.
  • Experience building or managing a SaaS security (SSPM) program.
  • Background in software development, DevOps, or Site Reliability Engineering.
  • Experience with incident response, threat hunting, and forensics.
  • Relevant security certifications such as: CISSP, GIAC certifications (GWAPT, GPEN, GCIH), AWS Certified Security – Specialty or GCP Professional Cloud Security Engineer, OSCP, CEH, or other offensive security certifications
  • Contributions to open-source security projects or active participation in the security community

Physical/Cognitive Requirements:

  • Capability to remain seated in a stationary position for prolonged periods.
  • Eye-hand coordination and manual dexterity to operate keyboard, computer and other office-related equipment.
  • Capability to work with leadership, employees, and members in an appropriate manner.

Pay:
 
The United States new hire base salary target ranges for this full-time position are:
 
Zone A: $128,130 - $180,990+ equity + benefits
Zone B: $140,943 - $199,089 + equity + benefits
Zone C: $153,756 - $217,188 + equity + benefits
Zone D: $166,569 - $235,287 + equity + benefits
 
This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones.
 
Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry.
 
Benefits & Perks:
 
In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more:
Remote-first culture
401(k) savings plan through Fidelity
Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
12 weeks of 100% Paid Parental leave
Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
Work-From-Home reimbursement to support team collaboration home office work
 
Your recruiter will share more about the salary range and benefits package for your role during the hiring process.

About Included Health

Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.

-----
Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.

Skills Required

  • 6+ years security engineering experience with application and cloud security (AWS strongly preferred)
  • Proficiency in scripting/programming for security automation (Python or Go preferred)
  • Demonstrable experience in two or more core areas: Application & SDLC Security (SAST/DAST/SCA/CI-CD), Security Automation & Engineering (SOAR/Terraform), Cloud Security (AWS/GCP), Identity & Encryption (JIT/PAM/key lifecycle), or Endpoint & Data Security (EDR/DLP/MDM)
  • Experience securing containerized environments (Docker, Kubernetes)
  • Previous experience in healthcare, fintech, or other highly regulated industries
  • Excellent communication skills to explain complex security risks to technical and non-technical stakeholders
  • Experience with mobile application security (iOS/Android)
  • Familiarity with AI security principles and governing LLM usage
  • Experience building or managing a SaaS security (SSPM) program
  • Background in software development, DevOps, or SRE
  • Experience with incident response, threat hunting, and forensics
  • Relevant security certifications (CISSP, GIAC, AWS/GCP security certs, OSCP, CEH, etc.)
  • Contributions to open-source security projects or active participation in the security community

Included Health Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Included Health and has not been reviewed or approved by Included Health.

  • Healthcare Strength Comprehensive medical, dental, and vision coverage with employer-paid contributions and free access to the company’s own services enhances total rewards. Feedback suggests robust mental health support, telemedicine, and wellness programs strengthen perceived care quality.
  • Parental & Family Support Paid parental leave and family-building benefits, including fertility coverage and financial assistance for adoption and surrogacy, are seen as meaningful supports. Feedback suggests compassionate leave and free family access to care add tangible value for caregivers.
  • Leave & Time Off Breadth Flexible, non‑accrued vacation, generous PTO, paid volunteer time, floating holidays, and sabbaticals are consistently emphasized. Feedback suggests remote‑friendly flexibility and additional rest days during high‑stress periods improve work-life balance.

Included Health Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
2,000 Employees
Year Founded: 2011

What We Do

Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.

Why Work With Us

Here, initiative meets purpose. We have bold aspirations that drive our work. We care in a way that shows in everything we do. At Included Health, you will join a team that is propelled by the opportunity to redefine healthcare for all. It's work worth caring about.

Gallery

Gallery

Similar Jobs

Crexi Logo Crexi

Senior Security Engineer

Real Estate • Sales • Software • PropTech
Easy Apply
Remote or Hybrid
United States
400 Employees
167K-227K Annually

Coupa Logo Coupa

Senior Security Engineer

Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
In-Office or Remote
Los Angeles, CA, USA
3000 Employees
83K-116K Annually

KPA Logo KPA

Senior Security Engineer

Automotive • Greentech • HR Tech • Sales • Software
Easy Apply
Remote or Hybrid
Lafayette, CO, USA
405 Employees
110K-130K Annually

Zscaler Logo Zscaler

Sales Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
7 Locations
8697 Employees
155K-221K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account