Senior Security Engineer
Included Health
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role overview
Senior Security Engineer (hands-on)
Design, implement, and automate security controls across the application stack and cloud environments—primarily AWS (with GCP considerations). Drive proactive vulnerability remediation and strengthen end-to-end security with a focus on preventing unauthorized access and exfiltration of PHI.
Responsibilities
- Implement Just-in-Time (JIT) access and Privileged Access Management (PAM) workflows to eliminate standing privileged accounts.
- Conduct platform permission reviews and enforce least-privilege access for cloud and application roles.
- Ensure 100% of production access requests/approvals are captured in audit logs.
- Lead security tool implementation, tuning, and operations in CI/CD, including:
- SAST, DAST, SCA, and secrets scanning
- Develop custom SAST rules for high-risk patterns (e.g., authorization bypasses, insecure PII/PHI handling).
- Partner with engineering to deploy IDE plugins and automated PR checks to block sensitive data exposure before deployment.
- Perform manual security code reviews for high-risk features and cryptographic implementations.
- Build and maintain automation for the vulnerability management lifecycle:
- Triage, validate, and assign new vulnerabilities.
- Develop security automation scripts/tools/services in Python or Go.
- Work with SecOps to create SIEM correlation rules and automated response playbooks.
- Design and maintain encryption strategies (data at rest and in transit) to protect PHI in HIPAA compliance.
- Manage cryptographic key lifecycles and key management systems.
- Design secure cloud network architectures and segmentation (VPCs, subnets, security groups, NACLs).
- Lead remediation of cloud security findings.
- Implement and manage a centralized security control plane.
- Design and enforce Data Loss Prevention (DLP) for endpoints and cloud services to prevent sensitive data exfiltration.
- Enforce system and endpoint hardening standards via MDM/UEM across macOS, Windows, Linux.
- Manage and tune endpoint security, including EDR/XDR (e.g., CrowdStrike).
- Lead threat modeling and conduct secure design reviews for system architectures, applications, and APIs.
- Act as an embedded security SME for product/platform teams; provide technical guidance and mentorship.
- Develop security programs for emerging risks (e.g., SaaS security, AI security).
Requirements
- 6+ years of security engineering experience with hands-on expertise in both application security and cloud security (AWS strongly preferred).
- Strong proficiency in at least one language for security automation: Python or Go preferred.
- Demonstrated experience in two or more core areas:
- Application & SDLC Security: SAST, DAST, SCA (e.g., Semgrep, Snyk, Burp Suite) and CI/CD automation.
- Security Automation & Engineering using SOAR platforms (e.g., Tines) and Terraform.
- Cloud Security (AWS/GCP): secure cloud-native services (e.g., VPC, IAM, WAF, CSPM).
- Identity & Encryption (cut off in provided text).
About Included Health
Included Health is a healthcare technology company focused on improving access to care. The company builds and operates applications that handle sensitive health information, requiring strong security practices and compliance. This role supports the organization’s security engineering and proactive defense approach across cloud and application stacks.
Scraped 4/7/2026