Remote job
Security Engineer
Job details
About this role
Role overview
A healthcare technology organization developing non-invasive prescription therapies for chronic neurological conditions is hiring a Security Engineer to safeguard digital assets, infrastructure, and applications. The role blends hands-on technical defense with strategic thinking, spanning vulnerability management, incident response, penetration testing oversight, and security culture building across engineering teams. The position reports to the Staff DevOps Engineer and supports a remote-first workforce with optional hybrid work near a San Mateo, CA headquarters.
Responsibilities
- Monitor and manage open-source and third-party dependencies through Software Composition Analysis tools, track CVEs, and integrate security scanning into CI/CD pipelines. - Coordinate external penetration tests and bug bounty programs, validate findings, and translate complex vulnerabilities into actionable remediation plans for engineering teams. - Drive security remediation across infrastructure, networks, and applications, providing code and configuration review guidance and implementing controls such as IAM policies, network segmentation, and secrets management. - Serve on the Incident Response team in an on-call rotation, investigate anomalies in SIEM, EDR, and cloud logs, and lead post-incident reviews with documented lessons learned. - Design and facilitate security tabletop exercises for technical teams and executive leadership, simulating realistic threat scenarios to test response plans and surface gaps. - Maintain cloud security posture across AWS/GCP environments, define KPIs such as Mean Time to Remediate and patch compliance, and support evidence gathering for SOC 2, ISO 27001, and HIPAA-aligned controls.
Requirements
- Bachelor's degree in Computer Science, Software Engineering, or a related technical field. - Three or more years of experience in security engineering, application security, or incident response. - Hands-on experience with modern security tooling such as Snyk, Dependabot, Burp Suite, Splunk, or Datadog. - Strong understanding of the OWASP Top 10, CWE, and cloud security best practices. - Experience integrating security scanning into CI/CD pipelines using Jenkins, GitHub Actions, or GitLab CI. - Proficiency in Python and Bash scripting for security automation and custom tooling development.
Nice to have
- Familiarity with additional languages such as Go, JavaScript/TypeScript, or Rust for deeper code reviews and custom tooling. - Experience securing cloud-native environments with Docker and AWS/GCP, including native tools like AWS Inspector and GuardDuty. - Hands-on use of GRC platforms, Infrastructure as Code security scanning tools, or bug bounty services. - Relevant certifications such as CISSP, CEH, OSCP, GCIH, or AWS Certified Security. - Background working with connected IoT devices, including provisioning, key rotation, and OTA update security.
Benefits and work setup
- Full-time, exempt position with a pay range of $155,000 to $190,000, adjusted for experience, skills, market benchmarks, internal equity, and candidate location. - Remote-first with optional hybrid work for candidates local to the San Mateo, CA headquarters. - Authorization to work in the United States is required; visa sponsorship may be considered on a case-by-case basis.