At Included Health, security is central to the trust our members, customers, partners, and care teams place in us. We protect sensitive health information and the systems that support our products by building security into architecture, engineering practices, and day-to-day operations.
Our Security Engineering team works closely with platform engineering and product teams to build practical, scalable security controls, especially focused on our infrastructure-as-code. We focus on reducing risk through automation, secure-by-default patterns, strong technical partnerships, and controls that teams can operate in real production environments.
As a Cloud Engineer on the Security team, you’ll help mature Included Health’s cloud security posture across primarily AWS environments, with consideration for GCP. You’ll design, implement, and automate controls that protect product infrastructure and help prevent unauthorized Protected Health Information (PHI) exfiltration.
This is a full-time, remote role reporting to the Senior Manager, Security Engineering. We are open to considering candidates at both the Senior and Staff levels.
The role requires hands-on technical execution as well as the ability to influence infrastructure, DevOps, engineering, and product teams.
What You'll Do
- Design and automate cloud security controls across Identity & Access Management (IAM), authorization, Just-in-Time access, data access, and platform access.
- Improve AWS and GCP security posture through Terraform guardrails, risk roadmaps, legacy remediation, and secure infrastructure patterns.
- Build security tooling in Python, Go, and Lambda for vulnerability management, alerting, PHI logging, and cloud security workflows.
- Secure containers, workloads, and CI/CD pipelines through practical controls teams can operate in production.
- Partner with infrastructure, DevOps, engineering, and product teams on sensitive-data handling, incident response, and secure platform initiatives.
- Document controls, standards, automation, and playbooks that help teams adopt secure workflows.
Who You Are
You are a practical, hands-on cloud security engineer who can bring structure to ambiguous risks or control gaps without waiting for perfect clarity. You clarify the desired outcome, trust boundaries, stakeholders, constraints, and available facts, then make a reasonable first move and adapt as you learn.
You are comfortable going deep in code, cloud APIs, logs, identity policies, network traffic, CI/CD pipelines, and infrastructure configuration. You use evidence to test hypotheses and turn findings into durable fixes, reusable automation, clear documentation, or repeatable processes.
You build trust through preparation, responsiveness, direct communication, technical credibility, and follow-through. You listen to operational realities, explaining risks and tradeoffs clearly, and work with teams toward practical controls they can operate in production.
You take ownership through the full loop: coordination, escalation, validation, closure, and knowledge sharing. You know when to investigate independently, when to involve the right expertise, and when broader organizational alignment is needed.
What You Bring
- 5+ years of hands-on cloud security experience, with deep AWS expertise and familiarity with GCP.
- Strong technical depth across cloud infrastructure, identity, authorization, networking, containers, CI/CD, logging, monitoring, and security operations.
- Experience building security automation and infrastructure tooling in Python, Go, Terraform, and cloud-native services.
- Experience designing and operating access controls, including RBAC, ABAC, policy-as-code, granular engineering access, and Just-in-Time access.
- Familiarity applying cloud security frameworks, HIPAA requirements, and related standards to production environments.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
The United States new hire base salary target ranges for this full-time position are:
- Zone A: $130,050–$249,930 + equity + benefits
- Zone B: $143,055–$274,923 + equity + benefits
- Zone C: $156,060–$299,616 + equity + benefits
- Zone D: $169,065–$324,909 + equity + benefits
Skills Required
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
- 5+ years of experience in cloud security, with emphasis on designing and implementing solutions in AWS.
- Proven hands-on software development experience in Python and Go for security automation and tooling.
- Experience designing and implementing authorization and access control frameworks (RBAC, ABAC, policy-as-code) and JIT access solutions.
- Deep proficiency writing and maintaining Terraform modules for security (Infrastructure as Code).
- Hands-on experience hardening containerized environments (Docker, Kubernetes/EKS).
- Experience with SDLC security and integrating security into CI/CD pipelines.
- Experience with security logging, monitoring, and alerting tools (SIEM, AWS CloudTrail, CloudWatch, GuardDuty) and scripting against their APIs.
- Familiarity with HIPAA, cloud security frameworks, regulations, and compliance requirements.
- Familiarity with Ruby.
- Experience remediating and improving security controls in GCP legacy environments.
Included Health Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Included Health and has not been reviewed or approved by Included Health.
-
Healthcare Strength — Comprehensive medical, dental, and vision coverage with employer-paid contributions and free access to the company’s own services enhances total rewards. Feedback suggests robust mental health support, telemedicine, and wellness programs strengthen perceived care quality.
-
Parental & Family Support — Paid parental leave and family-building benefits, including fertility coverage and financial assistance for adoption and surrogacy, are seen as meaningful supports. Feedback suggests compassionate leave and free family access to care add tangible value for caregivers.
-
Leave & Time Off Breadth — Flexible, non‑accrued vacation, generous PTO, paid volunteer time, floating holidays, and sabbaticals are consistently emphasized. Feedback suggests remote‑friendly flexibility and additional rest days during high‑stress periods improve work-life balance.
Included Health Insights
What We Do
Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.
Why Work With Us
Here, initiative meets purpose. We have bold aspirations that drive our work. We care in a way that shows in everything we do. At Included Health, you will join a team that is propelled by the opportunity to redefine healthcare for all. It's work worth caring about.
Gallery


.png)





