Staff Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Security Engineer (Security): Designing, building, deploying, and operating security controls across AWS, Azure, corporate networks, and endpoints with an accent on SIEM/EDR engineering, identity and access management, and incident response readiness. Focus on implementing measurable technical controls, tuning detections and automation (SOAR), and driving vulnerability remediation to closure in a regulated healthcare environment.
Location: Remote (US)
Salary: $125,241.00 - $187,862.00 (base)
Company
is an AI-first healthcare technology company focused on preventing inaccurate payments and reducing waste in the healthcare ecosystem.
What you will do
- Design, build, deploy, and operate security controls and tooling across AWS, Azure, corporate networks, and endpoints.
- Engineer and maintain SIEM detections (log onboarding, parsing, correlation rules) and develop SOAR playbooks to reduce response times.
- Administer and optimize EDR capabilities, including sensor deployment, policy tuning, threat-hunting support, and endpoint hardening.
- Implement IAM capabilities including SSO, MFA, conditional access, PIM/PAM, and role lifecycle automation.
- Lead security incidents with containment tooling, forensics readiness, response runbooks, and post-incident reviews.
- Run vulnerability management (scanning, risk-based prioritization) and enforce baseline security configuration standards via infrastructure-as-code/policy-as-code.
Requirements
- Must be legally authorized to work in the U.S. Visa sponsorship and other immigration support are not available.
- Minimum 7 years of hands-on security engineering and/or security operations experience.
- Minimum 3 years engineering and operating security controls within AWS and Microsoft Azure.
- Experience implementing security controls across cloud and endpoint environments (IAM, EDR, SIEM, DLP, network security, vulnerability management).
- Ability to translate security architecture principles into implemented, measurable technical controls.
Nice to have
- Security certifications such as CISSP, CCSP, GIAC, or AWS/Azure security specialty certifications.
- Experience with Microsoft Entra ID (conditional access, PIM, identity governance).
- Experience with EDR platforms (e.g., CrowdStrike Falcon) and SIEM detection-as-code practices.
- Scripting/automation skills (Python, PowerShell) and infrastructure-as-code tooling (e.g., Terraform).
- Experience with DevSecOps, container/Kubernetes security, CI/CD pipeline security, and securing SaaS/IaaS/PaaS workloads.
- Healthcare/regulatory security experience (HIPAA or similar).
Culture & Benefits
- Remote work with a U.S. authorization requirement.
- Base salary range provided for this full-time role.
- Security roadmap ownership with collaboration across technology and business teams.
- On-call rotation for security escalations.
Hiring process
- Interviews focused on security engineering depth (cloud security, SIEM/EDR, IAM, incident response) and practical experience.
- Discussion of security architecture alignment, detection/automation approach, and incident readiness.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →