Job Closed
This listing is no longer active.
Empowering data-driven healthcare for payers, providers, pharmacies, and life sciences organizations.
Staff Security Engineer – Level 6
Location
United States
Posted
141 days ago
Salary
$151.8K - $185K / year
Seniority
Lead
Job Description
Staff Security Engineer – Level 6
Inovalon
• Lead the strategic implementation of security standards in alignment with security policies. • Provide technical expertise and direction for the selection and implementation of a diverse suite of product security controls and countermeasures. • Provide technical leadership to recommend appropriate information security frameworks, requirements, direction, and system recommendations. • Stay abreast of security best practices and technologies, and foster the growth of team members by providing, training, guidance, and mentoring. • Design, develop, and maintain SOAR playbooks and automated response workflows to improve detection, triage, and containment across endpoint, network, identity, and cloud environments. • Integrate and optimize SIEM, EDR, vulnerability management, identity, and ticketing platforms (e.g., Rapid7, CrowdStrike, ServiceNow, Azure, email security) to enable end-to-end automated incident response. • Engineer and tune security detections, enrichment pipelines, and correlation logic to reduce false positives and improve MTTD/MTTR through automation and orchestration. • Develop and maintain automation scripts and APIs to support SOC operations, including automated containment (isolate host, disable account, block IP/domain), enrichment (threat intel, asset context), and reporting. • Build and maintain SOC automation use cases such as phishing response, suspicious login triage, malware containment, vulnerability prioritization, and insider-risk monitoring. • Collaborate with SOC analysts, threat hunters, and engineering teams to identify manual processes and convert them into automated workflows, increasing SOC efficiency and consistency. • Maintain and optimize SOAR platform health, integrations, and playbook performance, including version control, documentation, and continuous improvement lifecycle. • Create and deliver automation metrics and dashboards (automation coverage, time saved, incident response time reduction, false-positive reduction) for SOC leadership and executive reporting. • Work with leadership, customers, and stakeholders in both IT and Information Security to develop requirements based on a changing threat landscape and new digital capabilities. • Build security into product delivery pipeline (DevSecOps) using scripting. • Perform architecture reviews, identify security risks, recommend, and implement mitigations. • Research, recommend, and implement effective security controls for cloud-native services. • Discover and implement untapped functionality from security tools and services. • Work autonomously and proactively seek out opportunities to build security capabilities across our platforms. • Automate security throughout the development lifecycle (DevSecOps) by enabling security tools, technologies, and best practices for agile development. • Document security and compliance issues. • Present findings to clients, including technical teams and executive leadership, providing clear explanations of vulnerabilities, the potential impact on the business, and recommended mitigation strategies. • Adhere to all confidentiality, HIPAA, regulatory, and other such policies, procedures, and requirements as outlined within Employer’s Operating Policies and Procedures in all ways and at all times with respect to any aspect of the data handled or services rendered in the scope of work. • Maintain compliance with Inovalon’s policies, procedures and mission statement, and fulfill those responsibilities and/or duties that may be reasonably provided by Inovalon for the purpose of achieving operational and financial success.
Job Requirements
- A minimum of years of experience in software and security engineering.
- 5+ years of experience in one of these programming languages such as JavaScript, Python, Golang and PowerShell etc.
- 5+ years’ experience in building security test automation utilities (security as a code) and environments.
- 5+ years’ experience with cloud native technologies (Azure, AWS, GCP) and secure configurations.
- 3+ years’ experience in security system administration (installation, configuration, upgrade, and support).
- 3+ years of experience in application security architecture and risk assessments.
- Experience with OWASP TOP 10, NIST CSF, and MITRE ATT&K frameworks.
- One or more of the certifications: CISSP, CEH, OSCP.
- Preferred: AWS Cloud certifications.
- Cloud Security and Governance, Risk, and Compliance GRC, Thick Client Thin Client VAPT Knowledge/Hands on about DevSecOps/DevOps Knowledgeable about Data Protection.
Benefits
- health insurance
- life insurance
- company-paid disability
- 401k
- 18+ days of paid time off
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Own multiple Security Engineering assignments working with Ping Identity products, processes, and tooling • Assist in proposing, developing, and improving Secure Software Development Lifecycle (SSDLC) practices alongside global, high-performance product engineering teams • Work with the product teams to perform security design/code reviews and vulnerability assessment and management in an agile environment • Perform application security tasks including threat modeling, developer code reviews, consulting, static code analysis, dynamic runtime fuzzing, building custom tools, and automation and exploit development • Assist the Federal presales, support, and customer success teams responding to prospect, customer, and field questions related to product and industry security • Engage with third-party security consultants for independent security assessments, bug bounties, and penetration testing of the product
Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. At Coinbase, security isn't just a priority. It's the foundation of everything we do. In the fast-evolving world of digital currency, where trust is paramount, security breaches can mean the difference between success and failure. That's why we've made security a cornerstone of our mission, setting the standard for protecting millions of customers and billions of dollars in assets. As a Blockchain Security Engineer on the Decentralized Financial Security Team, you will work closely with engineers, technical product managers and senior leadership on designing secure products from the ground up. You will be responsible for performing secure design reviews, threat modeling, vendor reviews, working with vendors, and secure code reviews for upcoming Coinbase products or features that will be used by millions of customers. You will have an opportunity to work on the latest technology and provide leadership visibility of the current risk posture. You’ll also have an opportunity to pitch, lead and participate in cross-functional initiatives that uplevel the security of all Coinbase products and services. What you’ll be doing (ie. job duties): To be completed by all business teams except Eng. - Perform design reviews, threat modeling and code reviews of upcoming features and products. - Identify top product risk areas and lead risk-reduction initiatives with cross-functional teams. - Improve and/or automate existing processes to increase efficiency, utilizing agentic/AI tooling. - Create monitoring solutions to ensure identified risks remain at acceptable levels for Coinbase. - Participate in the team on-call rotation to support engineering teams through timely design consultations, vulnerability analysis, bug fix verification, etc. - Publish blogs and give talks (internal and external) on newfound vulnerabilities, incident investigations, unique integration risks, and related topics What we look for in you (ie. job requirements): To be completed by all business teams except Eng. - Strong understanding of blockchains (particularly EVM chains) and highly “crypto forward” - Expertise in blockchain technology and foundational knowledge in security principles - 2+ years of threat modeling/design review experience - Strong communication skills with the ability to translate technical security requirements and risks into terms that anyone can understand. - High ownership and drive, including the ability to work independently and unblock yourself. - Experience with using AI/agentic tooling (Claude Code, Cursor, GPT Codex, etc.) - Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality. Nice to haves: - MS or PhD in Computer Science or related field. - Experience in at least one of: Snowflake, Databricks, Dune - Experience automating manual processes or carrying out process improvements. - Experience in Blockchain, Exchange, or Decentralized Exchange Security. Job ID: P76318 #LI-Remote Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $152,405—$179,300 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal Opportunity Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and Applicants Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI Disclosure For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com
• Research and develop offensive agentic capabilities that become core Sybil features • Hunt for real vulnerabilities across a range of target environments and translate what you find into repeatable, automated techniques • Build and ship end-to-end customer-facing features: from research spike to production deployment • Design and implement LLM-powered tooling that extends Sybil's reach and depth across attack surfaces • Identify gaps in our offensive coverage and propose technical initiatives to close them, without waiting to be asked • Contribute to technical design discussions, review your teammates' work, and hold a high bar for what we ship • Operate with ownership: you define the problem, build the solution, and see it through
• Own and continuously elevate our ISMS in accordance with ISO 27001, SOC 2 Type 2, GDPR, and emerging AI governance standards • Manage the full lifecycle of security audits, certifications, and internal controls • Guide enterprise prospects and clients through InfoSec and compliance conversations • Own our security whitepapers and InfoSec collateral • Partner with Legal and Compliance to define security policies • Manage day-to-day compliance operations • Work with Solution Architects and DevOps to translate security requirements into scalable practices • Collaborate with Engineering and business teams




