Remote job
Staff Security Engineer
Job details
About this role
Role overview A telehealth infrastructure company that delivers white-labeled virtual care at scale is hiring a Staff Security Engineer to own and mature the security of the workforce systems the organization depends on every day, with a primary focus on endpoint and email security. This is a hands-on, generalist role with deep engineering ownership in those two domains, setting the technical bar across the company and its subsidiaries. The position sits within a Security Architecture & Engineering function that builds the security platform, partnering closely with Security Operations to ensure tooling serves downstream consumers.
Responsibilities - Engineer and harden security controls for the macOS and Windows fleet, including MDM, disk encryption, patch compliance, and local admin controls, while keeping clinician and operator workflows intact - Design MDM and MAM policies that protect company and PHI data on managed and BYOD devices, covering app protection, conditional access, and selective wipe - Deploy and operate an enterprise browser to secure SaaS and web access, including data controls, session policies, and extension management - Apply and continuously measure CIS Benchmark baselines across the endpoint fleet, tracking drift, managing documented exceptions, and producing audit-ready evidence - Own email security for the Google Workspace environment, including SPF, DKIM, DMARC enforcement, phishing and BEC defenses, attachment and link protection, and PHI-aware DLP - Write security standards, configuration baselines, and runbooks that others can follow independently, and automate repetitive work through scripting
Requirements - 8+ years of security engineering experience with a track record of owning outcomes end to end, including deep hands-on expertise in endpoint and email security - Experience deploying and operating MDM/MAM platforms (such as Kandji, Jamf, or Intune) plus email security and enterprise browser platforms - Hands-on experience implementing CIS Benchmarks and measuring compliance at fleet scale - Exposure to network security (ZTNA/VPN, DNS filtering, segmentation, or firewall policy) and working knowledge of cloud security fundamentals, preferably AWS - Familiarity with DevSecOps practices such as infrastructure as code, CI/CD security, and secrets management, plus scripting ability in Python, Bash, PowerShell, or similar - Experience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence, with clear written communication skills
Nice to have - Healthcare or health tech experience, especially environments handling PHI - Experience with Okta or another enterprise identity provider - Background supporting multi-entity organizations with subsidiaries or acquisitions - Relevant certifications such as GIAC, CISSP, OSCP, or cloud security credentials
Benefits and work setup - Competitive compensation - Medical, dental, and vision coverage - Flexible Spending and Health Savings Accounts - Generous PTO with hybrid-work flexibility - 401(k) with company match - Life insurance, pet insurance, and additional benefits