Staff Software Engineer, Cloud Security

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

💵 $174 320 - $320 099 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Included Health

Included Health

1001 - 5000 employés

🏥 Santé

☁️ SaaS

👥 RH Tech

Healthcare • SaaS • HR Tech

Included Health est une entreprise de technologie de la santé qui offre des soins de santé primaires, urgents et comportementaux personnalisés, axés sur les employeurs et les régimes de santé, via une application unique et un réseau de services virtuels et en personne. Elle combine des outils propulsés par l'IA et des équipes de soins humaines pour fournir une coordination des soins 24h/24 et 7j/7, un soutien à la facturation et aux réclamations, des seconds avis par des spécialistes de premier plan, et un soutien en santé mentale, dans le but de réduire les coûts de santé pour les employeurs et d'améliorer l'expérience et l'inclusivité des membres.

Description

• Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams. • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions. • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response. • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools. • Implement and champion Infrastructure as Code (IaC) principles, **specifically using Terraform,** for programmatic definition, enforcement, and auditing of security configurations. • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering. • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks. • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools. • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams. • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls. • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data. • Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines. • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices. • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows. • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response. • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.

🎯 Exigences

• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. • 5+ years of experience in cloud security, with a strong emphasis on designing, **developing (primarily in Python and Go),** and implementing security solutions in AWS. • **Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management.** • **Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions.** • Experience with Infrastructure as Code (IaC) with **deep proficiency in writing and maintaining Terraform modules for security.** • Experience with containerization (Docker, Kubernetes/EKS), including **hands-on experience hardening containerized environments.** • Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices. • Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go). • Experience with cloud security frameworks (especially HIPAA), regulations, and standards.

🏖️ Avantages

• Remote-first culture • 401(k) savings plan through Fidelity • Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance) • Paid Time Off ("PTO") and Discretionary Time Off ("DTO") • 12 weeks of 100% Paid Parental leave • Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies. • Work-From-Home reimbursement to support team collaboration home office work

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Fullscript

201 - 500

🏥 Santé

📦 Logistique

🏭 Fabrication

Staff Security Engineer at Fullscript focusing on application and product security solutions. Leading security initiatives across platforms while collaborating with engineering teams.

🇺🇸 États-Unis – Télétravail

💰 €240 000 000 Private Equity Round en 2021-11

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Zscaler

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🏢 Entreprise

Director of Product Management at Zscaler focusing on customer security outcomes and threat detection strategies. Leverage AI to enhance security operations and drive customer success.

🇺🇸 États-Unis – Télétravail

💵 $199 500 - $285 000 / an

💰 Secondary Market en 2017-11

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

GuideWell Source

1001 - 5000

🏥 Santé

💼 Conseil

⚕️ Assurance santé

Principal Cybersecurity Architect with Florida Blue responsible for technology security strategy and implementation of innovative security technology solutions. Bridging gaps across business areas and project teams while promoting secure-by-design principles.

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

🕒 il y a 1 mois

NVIDIA

10 000+ employés

🏥 Santé

🏭 Fabrication

🤖 Intelligence artificielle

Security Data Engineer building data systems for security analytics at NVIDIA powering AI supercomputing. Designing, architecting, and operating security data pipelines and analytics layers.

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

3Cloud

501 - 1000

💼 Conseil

🏥 Santé

🏭 Fabrication

Principal Architect focusing on Azure security and IAM for enterprise clients. Leading complex engagements while serving as a trusted advisor in cloud, data, and AI governance.

🇺🇸 États-Unis – Télétravail

💵 $158 200 - $227 300 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cloud

Cyber Security