Staff Cloud Security Engineer

1 hour, 47 minutes ago
Full-time
Lead
DevOps and Infrastructure
Included Health

Included Health

Included Health is a healthcare company that provides cost-saving solutions for employers and health plans. They offer virtual care and navigation services, connecting millions with board-certified doctors and specialists for comprehensive and convenie...

Insurance
1K-5K
$106M raised

Description

  • Design, develop, and implement cloud authorization frameworks for roles, resource restrictions, task-based access, and granular engineering permissions.
  • Lead the implementation of Just-In-Time (JIT) access controls for production systems, secrets, and data.
  • Collaborate with engineering teams to connect data classification signals to access control decisions.
  • Build and maintain security automation tools, scripts, and services in Python or Go for operations, vulnerability management, compliance, and incident response.
  • Develop clean, testable security code and custom integrations, with Terraform-based infrastructure automation and auditing.
  • Contribute to centralized security controls such as an engineering-owned WAF for rate limiting, IP blocking, input validation, and request filtering.
  • Partner with teams to secure the development toolchain and reduce supply chain risk across generators, linters, browser extensions, CLI tools, and IDE plugins.
  • Define and enforce container security hardening standards for least privilege, reduced tooling, and limited internet access.
  • Remediate legacy cloud environments, especially in GCP, by inventorying and improving security controls.
  • Conduct security assessments, threat modeling, incident response support, and maintain documentation for architectures, automation, and playbooks.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of cloud security experience, with strong emphasis on AWS.
  • Hands-on software development experience in Python and Go for security automation, tooling, or infrastructure management.
  • Proven experience designing authorization and access control frameworks, including RBAC, ABAC, policy-as-code, and JIT access.
  • Deep experience with Infrastructure as Code, especially Terraform modules for security.
  • Experience with containerization technologies such as Docker and Kubernetes/EKS, including container hardening.
  • Experience integrating security into SDLC and CI/CD pipelines, and applying secure software development practices.
  • Experience with security logging, monitoring, and alerting tools such as SIEM, AWS CloudTrail, CloudWatch, and GuardDuty.
  • Experience with cloud security frameworks, especially HIPAA, and relevant regulations and standards.
  • Familiarity with Ruby is a plus.

Benefits

  • Base salary range of $174,320-$320,099 depending on geographic zone, plus equity and benefits.
  • Remote-first culture.
  • 401(k) savings plan through Fidelity.
  • Comprehensive medical, vision, and dental coverage, including disability insurance options.
  • Paid Time Off (PTO) and Discretionary Time Off (DTO).
  • 12 weeks of 100% paid parental leave.
  • Family building and compassionate leave, including fertility coverage and up to $25,000 for surrogacy/adoption support.
  • Work-from-home reimbursement to support home office collaboration.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer II (Engineering & Tooling), Remote

Aledade 1K-5K Health Care Providers & Services

Aledade is hiring a Senior Security Engineer II to design and operate security tooling and infrastructure protections for a remote, cloud-focused environment supporting its healthcare platform.

Ansible Argo CD AWS Azure Bash Buildkite Chef CrowdStrike Cybersecurity Datadog DevSecOps Docker GCP Helm HIPAA Jenkins Kubernetes Network Security PowerShell Python SIEM Splunk Terraform
17 minutes ago

Blockchain Security Engineer (Smart Contract Auditing)

Binance 5K-10K Capital Markets

Binance is hiring a Blockchain Security Engineer to perform smart contract auditing and on-chain security analysis across wallets, blockchains, and related blockchain products in a remote role based in Taipei/Asia.

Blockchain Encryption Git Go Python Rust VS Code
32 minutes ago

Staff Threat Research Engineer

Sysdig 251-1K IT Services

Sysdig is hiring a Staff Threat Research Engineer to research cloud-based attacks and drive threat detection and security solutions for containers, Kubernetes, and cloud environments.

Cybersecurity Kubernetes Linux Penetration Testing
47 minutes ago

Senior Technical Lead for Systems Security

Pingwind 51-250 Internet Software & Services

PingWind is hiring a remote Senior Technical Lead for Systems Security to assess and strengthen security compliance for federal systems, with the main objective of ensuring required controls are met and risks are identified and mitigated.

Cybersecurity
47 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers