Job Closed

This listing is no longer active.

Aledade logo
Aledade

Self-described as "a new company with an old-fashioned goal," Aledade aims to put healthcare control back into the hands of doctors. Headquartered in Bethesda, Maryland, the compan

Senior Security Engineer II - AI

Location

United States

Posted

77 days ago

Salary

0

Seniority

Senior

Job Description

Senior Security Engineer II - AI

Aledade

The Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape. We are flexible with respect to geographic location, and the ideal candidate will be comfortable working remotely/work from home within the U.S. or from our headquarters office in Bethesda, MD. Primary Duties: - Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities - Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders - Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues - Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures - Mentoring and coaching more junior engineers or analysts Minimum Qualifications: - BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree - 6+ years of experience in securing and deploying applications within Cloud Native environments - 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes Preferred Knowledge, Skills, and/or Abilities: Application Security - Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc, direct experience preferred. - Experience architecting, developing, and deploying large-scale distributed systems at scale. - Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools. - Proven experience conducting code reviews, and threat modeling. - Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc. - Proficient in coding languages such as Python, R, C++, Javascript. - Extensive experience working in AWS/Azure/GCP software development environment.. - Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc. - In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them. - In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices. - Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go). - 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value - Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred. Physical Requirements - Must be able to sit for prolonged periods of time Who We Are: Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place. What Does This Mean for You? At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission. In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members: Flexible work schedules and the ability to work remotely are available for many roles Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners Robust time-off plan (21 days of PTO in your first year) Two paid volunteer days and 11 paid holidays 12 weeks paid parental leave for all new parents Six weeks paid sabbatical after six years of service Educational Assistant Program and Clinical Employee Reimbursement Program 401(k) with up to 4% match Stock options And much more! At Aledade, we don’t just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation. Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at https://www.aledade.com/privacy-policy-applicants

Job Requirements

  • BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree.
  • 6+ years of experience in securing and deploying applications within Cloud Native environments.
  • 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes.
  • Application Security.
  • Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc., direct experience preferred.
  • Experience architecting, developing, and deploying large-scale distributed systems at scale.
  • Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.
  • Proven experience conducting code reviews, and threat modeling.
  • Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc.
  • Proficient in coding languages such as Python, R, C++, Javascript.
  • Extensive experience working in AWS/Azure/GCP software development environment.
  • Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc.
  • In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them.
  • In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices.
  • Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go).
  • 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value.
  • Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred.

Benefits

  • Flexible work schedules and the ability to work remotely are available for many roles.
  • Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners.
  • Robust time-off plan (21 days of PTO in your first year).
  • Two paid volunteer days and 11 paid holidays.
  • 12 weeks paid parental leave for all new parents.
  • Six weeks paid sabbatical after six years of service.
  • Educational Assistant Program and Clinical Employee Reimbursement Program.
  • 401(k) with up to 4% match.
  • Stock options.
  • And much more!

Related Categories

Related Job Pages

More Security Engineer Jobs

Smartsheet logo

Software Engineer II, FedRamp (Remote Eligible)

Smartsheet

Founded in 2005, Smartsheet offers collaborative work management and process automation to empower greater enterprise productivity. A leading cloud-based platfo

For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday. Automation is the key to creating highly reliable and secure large-scale software systems. Are you ready to launch your career by engineering solutions rather than simply fixing problems? We are looking for a Software Engineer II to join our global Secure Platform Operations team. This is a unique opportunity for an early-career engineer to work at the intersection of infrastructure, automation, and security. You will be mentored by senior leaders to help build a platform that is resilient and secure by design. In this role, you will learn to treat security and reliability as software engineering challenges. You will grow into a key contributor who ensures our production environment is scalable, defensible, and highly reliable. What You Will Do - Lead architecture interviews with stakeholders to ensure all critical control areas throughout the architecture are designed to meet FedRamp program requirements. - Develop architecture briefing documents to inform the Government FedRAMP program manager and internal stakeholders with FedRAMP program requirements, technical capabilities, and any concerns noted from the material review - Support Continuous Monitoring activities including but not limited to items such as reviewing annual package submissions, reviewing and scoping significant change proposals, reviewing risk acceptance documents, etc. - Interpret FedRAMP and other agency requirements and provide internal teams guidance regarding expectations, technical requirements, and processes. - Stay informed of updated FedRAMP guidance, industry best practices, emerging technologies, and Government cybersecurity directives, and provide recommendations to internal stakeholders regarding impacts. - Learn and Build Secure Infrastructure: Under the guidance of senior engineers, you will assist in designing and maintaining secure infrastructure in our multi-cloud environment (AWS) using Infrastructure as Code (Terraform). - Automate Security & Workflows: You will write code (Python, Go, or Bash) to automate manual tasks, threat detection, and vulnerability management processes. - Secure the Pipeline: You will help integrate security tools (SAST, DAST, SCA) into our CI/CD pipelines, ensuring developers receive fast, actionable feedback on their code. - Support Container Operations: You will gain hands-on experience managing and securing our container orchestration platform (Kubernetes/EKS) and self-hosted GitLab Runners. - Collaborate and Grow: You will participate in code reviews, technical discussions, and blameless post-mortems to learn operational excellence and security best practices. What You Have: - US Person Status: Must be a U.S. Citizen, U.S. National to meet federal compliance requirements. - Education: A BS or MS in Computer Science, Engineering, or a related field (or equivalent capability). - Security: 3+ years of experience in IT Security, with at least two years of hands-on technical experience as a System Architect or Security Engineer. - FedRAMP: Two years of experience supporting FedRAMP programs, including familiarity with continuous monitoring, package reviews or significant change processes. - Foundational Coding Skills: Proficiency in at least one modern programming or scripting language, such as Python, Java, or Bash with a willingness to expand that skillset. - Cloud Foundation: Working knowledge of cloud concepts (AWS preferred) with a preferred experience in Infrastructure as Code (Terraform). - Security Mindset: Solid understanding of security concepts (e.g., OWASP Top 10), with a strong interest in the cybersecurity landscape. - Problem Solving: A critical thinker who enjoys troubleshooting complex technical problems methodically, asks good questions, and knows when to dig in independently versus bringing others in. - Communication: Excellent verbal and written communication skills and a collaborative spirit. Able to explain technical concepts to both engineering peers and non-technical stakeholders. Nice to Have - Hands-on experience in DevOps, SRE, or Software Engineering. - Experience with Linux/Unix command line. - Practical exposure to Docker, Kubernetes, or CI/CD pipelines (GitLab or GitHub). - Familiar with core networking concepts (HTTP, DNS, TCP/IP). Current US Perks & Benefits: - Medical/vision and dental coverage options for full-time employees - 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay) - Monthly stipend to support your work and productivity - Flexible Time Away Program, plus Sick Time Off - US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans - US employees receive 12 paid holidays per year - Up to 24 weeks of Parental Leave - Personal paid Volunteer Day to support our community - Opportunities for professional growth and development including access to Udemy online courses - Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account - Teleworking options from any registered location in the U.S. (role specific) Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity. US Base Salary Pay Range $125,000—$175,000 USD Get to Know Us: At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together. Equal Opportunity Employer: Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know. #LI-Remote

United States
$125K - $175K / year
Smartsheet logo

Sr. SEII, Secure Platform Operations (Remote Eligible)

Smartsheet

Founded in 2005, Smartsheet offers collaborative work management and process automation to empower greater enterprise productivity. A leading cloud-based platfo

For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday. Automation is the key to creating highly reliable and secure large-scale software systems. Are you someone who engineers solutions to problems rather than simply fixing the same thing over and over again? Can you protect Smartsheet against attackers? We are looking for a Senior Software Engineer with passion for security and platform engineering (which combines elements of development, site reliability, devops, and security), to join our global Secure Platform Operations team. In this critical role, you will be a leader in maturing our security and reliability posture by treating both as software engineering challenges, as well as system-wide optimization for Smartsheet engineering including supporting migrations and modernizations for feature teams to the platform. You will architect, automate, and operate a highly reliable, scalable, and defensible production environment with a great developer experience, directly impacting our ability to deliver a world-class service to our customers 24/7. This is a unique opportunity to truly apply Platform Engineering concepts and technologies, working at the intersection of infrastructure, automation, security, and developer experience to build a platform that is resilient, secure, and easy to use and maintain. What You Will Do: - Engineer Secure and Resilient Infrastructure: Design, build, maintain, and improve secure, scalable, and highly available infrastructure in our multi-cloud environment (primarily AWS) using Infrastructure as Code (IaC) principles with tools like Terraform, Kubernetes, and Helm. - Automate Proactive Security: Engineer and automate threat detection, incident response, and vulnerability management processes. You will build the tools and workflows that allow us to respond to threats at machine speed. - Secure the Software Development Lifecycle: Architect and secure our CI/CD pipelines, integrating automated security tooling (SAST, DAST, SCA) to provide developers with fast, actionable feedback. - Master Container Security: Manage, operate, and secure our container orchestration platform (Kubernetes), implementing best practices for container security from the registry to runtime, including knowledge of hardening requirements such as CIS Benchmarks or DISA STIG. - Lead Incident Response: Act as a technical lead during security and reliability incidents, driving resolution and conducting blameless post-mortems to engineer preventative solutions. - Drive Automated Compliance: Implement and automate technical controls to ensure continuous compliance with frameworks such as FedRAMP, SOC 2, and ISO 27001. - Mentor and Lead: Serve as a subject matter expert for security and reliability, mentoring other engineers and championing a culture of operational excellence and security ownership across the organization. What You Have: - 8+ years of progressive experience in technology, with at least 5 years in a hands-on senior role such as Site Reliability Engineering, or DevOps. - A BS or MS in Computer Science, Engineering, or a related field, or equivalent industry experience. - Expert-level proficiency in at least one major cloud provider, preferably AWS, with deep knowledge of core infrastructure and security services. - Expert-level proficiency with Infrastructure as Code, particularly Terraform. - Expert-level proficiency in a scripting or programming language such as Python, Go, or Ruby, with a proven history of building automation and custom tooling. - Deep experience with containerization and orchestration technologies (Kubernetes), including securing containerized environments. - Proficiency with the modern security operations toolchain, including SIEM, EDR, and vulnerability scanning technologies. - Experience integrating security tools (SAST, DAST, SCA) into CI/CD pipelines. - A critical thinker with a proven ability to troubleshoot complex problems in high-pressure production environments. - Excellent verbal and written communication skills and a collaborative spirit. This will include fluency in English. - Must be a U.S. Citizen or a U.S. National to meet federal compliance requirements Nice to Have: - Advanced industry certifications such as CISSP, CISM, OSCP, or cloud-specific security certifications. - Experience with compliance frameworks like FedRAMP, ISO27001, SOC2. Current US Perks & Benefits: - Medical/vision and dental coverage options for full-time employees - 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay) - Monthly stipend to support your work and productivity - Flexible Time Away Program, plus Sick Time Off - US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans - US employees receive 12 paid holidays per year - Up to 24 weeks of Parental Leave - Personal paid Volunteer Day to support our community - Opportunities for professional growth and development including access to Udemy online courses - Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account - Teleworking options from any registered location in the U.S. (role specific) Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity. US Base Salary Pay Range $175,000—$245,000 USD Get to Know Us: At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together. Equal Opportunity Employer: Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know. #LI-Remote

United States
$175K - $245K / year
Job Closed
DoorDash logo

Senior Security Engineer, Red Team

DoorDash

DoorDash is a food delivery service and app operating in more than 300 major cities throughout the United States and Canada. Using DoorDash, customers can order food from restauran

• Conduct threat intelligence-informed adversary emulations to simulate real-world cyber attacks • Identify security improvement opportunities in the DoorDash environment • Collaborate with cross-functional teams to assess the security posture of DoorDash’s critical assets and products • Execute full-scope Red Team operations against valuable objectives in the company • Provide feedback for efforts upholding customer trust

California
$159.8K - $235K / year
OtherRemoteTeam 10,001+H1B No Sponsor

• Execute and support the enterprise physical security technology strategy across GE Vernova locations globally. • Lead and support the deployment of new physical security technologies and the continuous improvement of existing systems and platforms. • Ensure physical security systems comply with applicable local, regional, and global regulatory and compliance requirements. • Support the digitization and modernization of security platforms including access control, video surveillance, intrusion detection, identity management, and AI-enabled analytics. • Apply AI and computer vision technologies responsibly to enhance detection, situational awareness, and operational efficiency while adhering to governance and privacy expectations. • Develop, maintain, and improve project, program, and operational management trackers, dashboards, and reporting tools. • Develop and maintain technical security documentation including standards, requirements, technical guidance, SOPs, and approved manufacturer lists in alignment with the GE Vernova EHSS Management System. • Serve as a technical Subject Matter Expert for physical security technologies, providing guidance and support to Regional Security Directors and site leadership. • Partner with Regional Security, Project Management, Digital Technology, and Sourcing to design security systems, identify gaps, and recommend site hardening and risk mitigation measures. • Represent GE Vernova Security in technical engagements with security OEMs, system integrators, and technology partners. • Support sourcing activities including technical evaluations, Master Service Agreement reviews, and supplier performance assessments. • Review project RFPs and conduct technical risk assessments to evaluate solution viability, scalability, and lifecycle risk. • Conduct technical vendor vetting and manufacturer approval processes aligned with enterprise standards and cybersecurity expectations.

United States