Overview
The team is in search of a Staff Security Engineer to join the team. This role will have ownership on designing and implementing scalable security solutions. You will play a key role in architecting, deploying, and maintaining security infrastructure while enabling the business to innovate securely.
WHAT YOU’LL DO:
- Architect and implement security solutions that scale with the company’s growth, focusing on automation, resilience, and developer & user-friendly security. Build out proofs of concept, tools, and/or platforms to address security problems at scale.
- Build tools with an emphasis on self-service, automation, and performance that identify and mitigate application security risks and flaws.
- Eliminate classes of security problems by shifting the detection and preventions left into the developer workflow. Provide architectural, design, and threat-based guidance to software development teams to improve security maturity before code is created.
- Work with SecOps to enhance our ability to detect threats early and respond effectively.
- Partner with our DevOps team to assess infrastructure security and propose improved security solutions.
- Partner with cross-functional teams to ensure security maturity work is being prioritized and addressed in ways both timely and durable.
- Ensure security controls align with HIPAA framework without impeding development and productivity velocity.
WHAT YOU’LL NEED:
- 5+ years of experience in a Staff Security Engineer role.
- You take ownership and proactively design solutions that eliminate security bottlenecks while enabling innovation.
- You minimize manual work through scripting, APIs, and infrastructure as code.
- Strong knowledge of cloud security (AWS, Azure), identity management, application security, modern security frameworks (ie OWASP, NIST) and HIPAA regulatory experience.
- Diverse experience with application security tooling and processes that include code review, SAST, penetration testing, and risk management. High proficiency with source code management tools and security features of each(e.g., Github, Bitbucket)
- Proficiency in at least one programming language (Python, Go, or similar) and experience integrating security into DevOps CI/CD pipelines.
- Ability to assess risk, anticipate attack vectors, and proactively mitigate threats through layered security.
- Ability to work cross-functionally with engineering, IT, compliance, and leadership to drive security initiatives forward