Responsibilities:
- Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access
- Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams.
- Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions.
- Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response.
- Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools.
- Implement and champion Infrastructure as Code (IaC) principles, specifically using Terraform, for programmatic definition, enforcement, and auditing of security configurations.
- Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering.
- Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks.
- Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools.
- Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams.
- Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls.
- Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data.
- Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines.
- Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices.
- Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows.
- Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response.
- Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.
Qualifications:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 5+ years of experience in cloud security, with a strong emphasis on designing, developing (primarily in Python and Go), and implementing security solutions in AWS.
- Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management.
- Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions.
- Experience with Infrastructure as Code (IaC) with deep proficiency in writing and maintaining Terraform modules for security.
- Experience with containerization (Docker, Kubernetes/EKS), including hands-on experience hardening containerized environments.
- Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices.
- Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go).
- Experience with cloud security frameworks (especially HIPAA), regulations, and standards.
Skills Required
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
- 5+ years of experience in cloud security with emphasis on designing, developing, and implementing security solutions in AWS.
- Proven hands-on software development experience in Python and Go for security automation and tooling.
- Demonstrable experience designing and implementing authorization and access control frameworks (RBAC, ABAC, policy-as-code) and JIT access solutions.
- Deep proficiency writing and maintaining Terraform modules for security (IaC).
- Experience with containerization (Docker) and Kubernetes/EKS, including hands-on container security hardening.
- Experience integrating SDLC security and securing CI/CD pipelines.
- Experience with security logging, monitoring, and alerting tools (SIEM, AWS CloudTrail, CloudWatch, GuardDuty) and scripting against their APIs.
- Experience with cloud security frameworks, regulations, and standards, especially HIPAA.
- Familiarity with Ruby.
- Experience working with GCP and remediating legacy cloud environments.
Included Health Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Included Health and has not been reviewed or approved by Included Health.
-
Healthcare Strength — Comprehensive medical, dental, and vision coverage with employer-paid contributions and free access to the company’s own services enhances total rewards. Feedback suggests robust mental health support, telemedicine, and wellness programs strengthen perceived care quality.
-
Parental & Family Support — Paid parental leave and family-building benefits, including fertility coverage and financial assistance for adoption and surrogacy, are seen as meaningful supports. Feedback suggests compassionate leave and free family access to care add tangible value for caregivers.
-
Leave & Time Off Breadth — Flexible, non‑accrued vacation, generous PTO, paid volunteer time, floating holidays, and sabbaticals are consistently emphasized. Feedback suggests remote‑friendly flexibility and additional rest days during high‑stress periods improve work-life balance.
Included Health Insights
What We Do
Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.
Why Work With Us
Here, initiative meets purpose. We have bold aspirations that drive our work. We care in a way that shows in everything we do. At Included Health, you will join a team that is propelled by the opportunity to redefine healthcare for all. It's work worth caring about.
Gallery








