Staff Cloud Security Engineer

3 weeks, 5 days ago
Full-time
Lead
DevOps and Infrastructure
Included Health

Included Health

Included Health is a healthcare company that provides cost-saving solutions for employers and health plans. They offer virtual care and navigation services, connecting millions with board-certified doctors and specialists for comprehensive and convenie...

Insurance
1K-5K
$106M raised

Description

  • Design, develop, and implement cloud authorization frameworks for roles, resource restrictions, task-based access, and granular engineering permissions.
  • Lead the implementation of Just-In-Time (JIT) access controls for production systems, secrets, and data.
  • Collaborate with engineering teams to connect data classification signals to access control decisions.
  • Build and maintain security automation tools, scripts, and services in Python or Go for operations, vulnerability management, compliance, and incident response.
  • Develop clean, testable security code and custom integrations, with Terraform-based infrastructure automation and auditing.
  • Contribute to centralized security controls such as an engineering-owned WAF for rate limiting, IP blocking, input validation, and request filtering.
  • Partner with teams to secure the development toolchain and reduce supply chain risk across generators, linters, browser extensions, CLI tools, and IDE plugins.
  • Define and enforce container security hardening standards for least privilege, reduced tooling, and limited internet access.
  • Remediate legacy cloud environments, especially in GCP, by inventorying and improving security controls.
  • Conduct security assessments, threat modeling, incident response support, and maintain documentation for architectures, automation, and playbooks.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of cloud security experience, with strong emphasis on AWS.
  • Hands-on software development experience in Python and Go for security automation, tooling, or infrastructure management.
  • Proven experience designing authorization and access control frameworks, including RBAC, ABAC, policy-as-code, and JIT access.
  • Deep experience with Infrastructure as Code, especially Terraform modules for security.
  • Experience with containerization technologies such as Docker and Kubernetes/EKS, including container hardening.
  • Experience integrating security into SDLC and CI/CD pipelines, and applying secure software development practices.
  • Experience with security logging, monitoring, and alerting tools such as SIEM, AWS CloudTrail, CloudWatch, and GuardDuty.
  • Experience with cloud security frameworks, especially HIPAA, and relevant regulations and standards.
  • Familiarity with Ruby is a plus.

Benefits

  • Base salary range of $174,320-$320,099 depending on geographic zone, plus equity and benefits.
  • Remote-first culture.
  • 401(k) savings plan through Fidelity.
  • Comprehensive medical, vision, and dental coverage, including disability insurance options.
  • Paid Time Off (PTO) and Discretionary Time Off (DTO).
  • 12 weeks of 100% paid parental leave.
  • Family building and compassionate leave, including fertility coverage and up to $25,000 for surrogacy/adoption support.
  • Work-from-home reimbursement to support home office collaboration.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cloud Enablement Engineer [Remote-US]

Quanata 201-500 information technology & services

Quanata is hiring a Cloud Enablement Engineer to support AWS-centered developer platforms and cloud infrastructure that help engineering teams deliver software reliably and efficiently.

AWS Bash CI/CD GCP GitHub GitLab Go Kubernetes Pulumi Python Serverless Terraform
2 minutes ago

Staff Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is seeking a Staff Security Engineer to build and maintain identity and access management controls that protect the systems used to develop its defense technology products.

AWS AWS CDK Azure CI/CD GCP Go OAuth OpenID Connect Rust SAML Terraform
32 minutes ago

Operational Technology (OT ) Security Administrator - Factory Systems

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring an Operational Technology (OT) Cybersecurity Specialist to secure factory and industrial control environments supporting its advanced defense technology products.

Linux
47 minutes ago

Security Engineer

HubSpot 5K-10K Media

HubSpot is seeking a Security Engineer to evaluate, deploy, troubleshoot, and maintain security tools that protect the organization’s infrastructure and support its broader security operations.

AWS Azure Bash CrowdStrike Cybersecurity GCP PowerShell Python SIEM
47 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers