Senior Security Operations Engineer

9 hours, 28 minutes ago
Full-time
Senior
DevOps and Infrastructure
Included Health

Included Health

Included Health is a healthcare company that provides cost-saving solutions for employers and health plans. They offer virtual care and navigation services, connecting millions with board-certified doctors and specialists for comprehensive and convenie...

Insurance
1K-5K
$106M raised

Description

  • Lead investigation, containment, remediation, and root cause analysis for DLP and suspected data exfiltration incidents.
  • Deploy, configure, and continuously tune DLP controls across endpoints, network egress, SaaS applications, and cloud storage.
  • Develop and maintain data classifications, DLP policies, and detection rules for PHI, PII, PCI, and other sensitive data.
  • Build automated response playbooks and workflows to enrich, triage, and respond to alerts.
  • Proactively hunt for anomalous data movement, including unusual destinations, channels, and volumes.
  • Define and track DLP metrics such as coverage, detection quality, MTTD, MTTR, and false-positive rates.
  • Communicate DLP performance and improvement initiatives to security leadership and cross-functional stakeholders.
  • Contribute to incident response and vulnerability management activities related to data protection.

Requirements

  • 5+ years of hands-on experience in security operations, incident response, or security engineering, with emphasis on data protection and DLP.
  • Production experience deploying, tuning, and operating endpoint, network, SaaS, and/or cloud DLP tools.
  • Experience with CASB or comparable SaaS security controls.
  • Experience integrating DLP signals into SIEM/SOAR workflows, including platforms such as CrowdStrike, Splunk, or Sentinel.
  • Advanced scripting and automation skills using tools such as Python, PowerShell, KQL, or SQL.
  • Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data.
  • Ability to balance security, usability, and regulatory or client requirements when developing controls.

Benefits

  • Remote-first culture.
  • Base salary ranges from $128,130–$235,287 depending on geographic zone, plus equity and benefits.
  • 401(k) savings plan through Fidelity.
  • Medical, vision, dental, and disability coverage with multiple plan options.
  • Paid Time Off and Discretionary Time Off.
  • 12 weeks of fully paid parental leave.
  • Family-building benefits, including fertility coverage and up to $25,000 for surrogacy or adoption.
  • Work-from-home reimbursement and comprehensive family and compassionate leave support.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Zero Trust Engineer (R-00205)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Zero Trust Engineers to implement enterprise Zero Trust use cases across prioritized Department of Veterans Affairs information systems and guide them through planning, validation, testing, and operational transition.

Azure Cybersecurity
8 hours, 58 minutes ago

Pillar Lead: Device & Endpoint Specialist (R-00212)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking a Device & Endpoint Specialist to lead the Devices pillar of enterprise Zero Trust architecture, supporting implementation and integrating device posture and security signals into access decisions.

CrowdStrike Cybersecurity
9 hours, 13 minutes ago

Pillar Lead: Indentity Architect (R-00210)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking an Identity Architect to lead the Identity pillar for VA Zero Trust initiatives by defining reusable identity architecture, access models, and integration patterns across enterprise systems.

Active Directory
9 hours, 28 minutes ago

SIEM and Data Management Engineer – Managed Security

AHEAD 1K-5K IT Services

AHEAD is seeking a SIEM and Data Management Engineer to manage and improve the security data pipelines supporting its cloud-based Managed Security operations, with primary responsibility for Palo Alto Cortex XSIAM.

IDS Python SIEM
9 hours, 43 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers