Padmi
Included Health logo
Included Health

virtual care · primary care

Senior Security Engineer

Remote · United StatesPosted 7 months ago
SecuritySenior
Apply at Included Health

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Design, build, and implement Just-in-Time (JIT) access controls and Privileged Access Management (PAM) workflows to eliminate standing privileged accounts in production.

Conduct platform permission reviews and implement a least-privilege access model for cloud and application roles.

Ensure 100% of production access requests and approvals are captured in audit logs.

Lead the implementation, tuning, and operation of security tools in the CI/CD pipeline, including SAST, DAST, SCA, and secrets scanning.

Develop custom SAST rules to detect specific, high-risk flaw patterns, such as authorization bypasses or insecure PII/PHI handling.

Partner with engineering to deploy IDE plugins and automated PR checks that block sensitive data exposure before deployment.

Conduct manual security code reviews for high-risk features and cryptographic implementations.

Design, build, and maintain automation for the end-to-end vulnerability management lifecycle.

Engineer automated workflows to triage, validate, and assign new vulnerabilities

Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations and compliance checks.

Partner with SecOps to build high-fidelity SIEM correlation rules and automated response playbooks.

Design, implement, and maintain encryption strategies for data at rest and in transit, ensuring PHI is protected in compliance with HIPAA.

Manage the cryptographic key lifecycle and administer key management systems

Design and implement secure cloud network architectures (VPCs, subnets, security groups, NACLs) and network segmentation strategies.

Lead the remediation of cloud security findings

Implement and manage a centralized security control plane

Design and implement Data Loss Prevention (DLP) policies for endpoints and cloud services to protect against sensitive data exfiltration.

Design and enforce security configurations and hardening standards for diverse operating systems (macOS, Windows, Linux) via MDM/UEM platforms.

Manage and tune endpoint security solutions, including EDR/XDR (e.g., CrowdStrike).

Lead threat modeling sessions for new features and conduct secure design reviews of system architectures, applications, and APIs.

Act as an embedded security partner and subject matter expert for product and platform teams, providing technical guidance and mentorship.

Develop and manage security programs for emerging risks, including SaaS security and AI security.

More at Included Health

Related open roles

View all roles