A better way to get your employees to high-quality doctors.
Staff Security Engineer
Location
United States
Posted
58 days ago
Salary
$239K - $275K / year
Seniority
Senior
Job Description
Staff Security Engineer
Garner Health
Garner’s mission is to transform the healthcare economy, delivering high-quality and affordable care for all. We are fundamentally reimagining how healthcare works in the U.S. by partnering with employers to redesign healthcare benefits using clear incentives and powerful, data-driven insights. Our approach guides employees to higher-quality, lower-cost care, creating a system that works better for everyone. Patients achieve better health outcomes, employers spend healthcare dollars more effectively, and physicians are rewarded for delivering exceptional care rather than performing more procedures. Garner is one of the fastest-growing healthcare technology companies in the country. Our products are trusted by the most sophisticated employers and providers in the industry, and we are building a team of talented, mission-driven individuals who are motivated to make a meaningful impact on healthcare at scale. About the role: We are seeking an exceptional Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and ensuring our security posture scales alongside our rapid customer growth. You will be responsible for defining the security standards that protect sensitive healthcare data, ensuring our systems are resilient against evolving threats while maintaining high engineering velocity. Where you will work: Garner is headquartered in NYC, but this position is available for individuals who are comfortable with remote work and occasional travel to HQ. What you will do: - Lead technical security design: Own the technical design and review process for security-critical systems, ensuring all new features meet Garner's high standards for data protection and resilience - Master complex domains: Maintain and apply a mastery of one or more technical security domains (e.g., Cloud Security, AppSec, or Data) to solve the most complex business and technical challenges - Course-correct technical direction: Identify when technical paths are inefficient or insufficient and proactively redirect efforts to capture higher ROI for the firm - Architect automated defenses: Create and implement advanced tools and automation that increase the efficacy of security monitoring and incident response - Translate ambiguity into execution: Take broad, complex security objectives and break them down into well-defined deliverables and architectural requirements for the broader engineering team - Mentor through technical rigor: Raise the bar for the engineering function by providing high-level feedback during code and design reviews, fostering a culture of security-first development The ideal candidate has: - Exceptional Technical Judgment: Proven ability to make high-stakes technical decisions that result in positive long-term outcomes for the company's security posture - Strategic Problem-Solving: Effectively leverages context and data to analyze root causes and prioritize security initiatives that offer the greatest impact on risk reduction - Influential Stakeholder Management: Builds strong relationships across the organization, conveying complex security risks in a clear and compelling manner to both technical and non-technical partners - Drive for Innovation: Continuously identifies and implements creative solutions to pay down technical debt and improve the efficiency of our security infrastructure - Reliability Under Pressure: Handles complex escalations and security incidents with discipline, ensuring rigorous analysis and comprehensive resolution without jumping to conclusions - A desire to be a part of a high-performing, mission-driven team that operates with intense urgency, a strong sense of individual accountability, and a commitment to authentic feedback - Startup experience Technologies we use: - Python, Kubernetes, Snowflake, AWS, Terraform Wiz, Cyberhaven This is a unique opportunity to join a fast-growing company in a transformative role, helping shape the future of healthcare. Compensation Transparency:The target salary range for this position is $239,000-$275,000. Individual compensation for this role will depend on various factors, including qualifications, skills, and applicable laws. In addition to base compensation, this role is eligible to participate in our equity incentive and competitive benefits plans, including but not limited to: flexible PTO, Medical/Dental/Vision plan options, 401(k), Teladoc Health and more. Fraud and Security Notice: Please be aware of recent job scam attempts. Our recruiters use getgarner.com and garnerhealth.com email domains exclusively. If you have been contacted by someone claiming to be a Garner recruiter or a hiring manager from a different domain about a potential job, please report it to law enforcement here and to candidateprotection@garnerhealth.com. Equal Employment Opportunity:Garner Health is proud to be an Equal Employment Opportunity employer and values diversity in the workplace. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Garner Health is committed to providing accommodations for qualified individuals with disabilities in our recruiting process. If you need assistance or an accommodation due to a disability, you may contact us at talent@garnerhealth.com.
Benefits
- 401(K), Commuter benefits, Company equity, Company-sponsored outings, Dental insurance, Disability insurance, Family medical leave, Flexible work schedule, Generous parental leave, Company-sponsored happy hours, Health insurance, Open door policy, Life insurance, Open office floor plan, Lunch and learns, Remote work program, Sabbatical, Free snacks and drinks, Team based strategic planning, OKR operational model, Vision insurance, Some meals provided, Hiring practices that promote diversity, Hybrid work model, In-person all-hands meetings, In-person revenue kickoff, Pay transparency, Flexible time off
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Maintaining the overarching operational security posture and managing the day-to-day security operations of your assigned Information System (IS); • Developing, reviewing, and maintaining security and authorization documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs); • Performing vulnerability/risk assessment analyses to support assessment and authorization (A&A); • Ensuring the implementation and maintenance of security controls in accordance with the SSP and the organization's security policies, standards, and procedures; • Supporting security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF). • Providing configuration management (CM) for IS security software, hardware, and firmware, and leading Change Control Board (CCB) meetings; and, • Providing guidance and security expertise to program leadership.
Role Description Databricks is hiring an L5 Enterprise Security Engineer to expand Enterprise Security coverage across a rapidly evolving enterprise environment. This role will focus on securing enterprise applications, cross-system integrations, data flows, and emerging AI-adjacent use cases. The scope includes modern access patterns such as MCP, integration, and trust boundary security, and broader security engineering support across enterprise platforms and services. This engineer will help identify risk, define practical security requirements, and improve security outcomes through strong technical judgment and cross-functional partnership. This role sits at the intersection of enterprise architecture, security engineering, and business enablement. The engineer will: - Review new technologies, integrations, and workflows with an emphasis on secure design, authentication and authorization, data handling, logging, third-party connectivity, API and token security, and operational resilience. - Partner closely with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support scalable adoption of secure patterns. - Help shape how Enterprise Security supports SaaS, internal platforms, automation, and AI-connected systems as the environment continues to grow in complexity. Qualifications - 7+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field. - Experience conducting security design or architecture reviews for enterprise applications, SaaS platforms, integrations, or internally developed systems. - Strong understanding of authentication, authorization, SSO, federation, SCIM, API security, token handling, secrets management, and least privilege design. - Experience assessing data flows, third-party integrations, trust boundaries, logging and monitoring, and security controls across interconnected systems. - Ability to evaluate risk in modern enterprise environments, including automation platforms, AI-adjacent workflows, and emerging integration patterns such as MCP. - Strong written and verbal communication skills, including the ability to translate technical risk into clear requirements and actionable guidance. - Experience driving security outcomes through engineering judgment, influence, and scalable process improvement. - Familiarity with cloud platforms, enterprise identity systems, and core control domains such as audit logging, encryption, access control, data retention, and incident response. Requirements - Strengthen security practices across enterprise application and integration reviews by identifying key risks early, improving requirement quality, and helping teams address security issues earlier in the lifecycle. - Strengthen Enterprise Security’s capability to assess and guide AI-adjacent security, MCP and integration security, and cross-system data flow risk, while improving the consistency and scale of security reviews. Benefits - At Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region, please visit mybenefitsnow.com/databricks .
Data Security Services Compliance Manager
EntrustEntrust Corporation is a software development company on a mission to keep the world moving safely by enabling trusted experiences for payments, identities, and digital infrastruct
• Ensure Entrusts Public Key Infrastructure Certificate Authority (PKI CA) products meet applicable compliance frameworks, customer contractual requirements, and emerging standards across multiple communities of trust. • Provide support as needed to ensure that other DSS products remain in compliance with the applicable frameworks, regulatory requirements and customer contractual requirements for each. • Escalate compliance issues that arise in production service environments to the Entrust Policy Management Authority (EPMA) while maintaining on-going ownership of the issues and supporting PA/EPMA direction through issue resolution. • Facilitate external auditor engagements, organize required compliance evidence, schedule required resources, submit required reports, and manage audit timelines. • Closely monitor and advise product and development teams on regulatory priorities and emerging PKI use cases from multiple communities of trust (e.g., financial services, healthcare, government). • Feedback and monitor requirements and/or requirements change for each community of trust to the internal teams, ensuring alignment with Entrust’s compliance strategy. • Represent Entrust and take the lead on standards body engagement, as directed. • Make recommendations and follow-up to mitigate compliance risks and drive continuous improvement. • Oversee and drive the end-to-end operational security compliance and audit programs for WTCA and other applicable frameworks. • Review and make recommendations on operational procedures to ensure they efficiently and effectively comply with all relevant requirements. • Contribute applicable metrics to product compliance scorecards. • Facilitate timely identification, communication, and recommended resolution of compliance risks. • Serve as the internal and customer-facing subject matter expert on compliance frameworks (including WTCA and others). • Advise customers and internal stakeholders on best practices, compliance, and audit processes across multiple standards.
AI Security Consultant, Strategic Advisory Services
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
• Contribute to service engagements focused on securing AI systems and applying AI tools • Assess, develop, and modernize cybersecurity programs to enhance security posture • Perform technical analysis to identify and secure AI workloads • Perform threat modeling to evaluate the risk posed by new tools and architectures • Identify and develop use cases for automation and "agentification" of security workflows • Produce high-quality written and verbal reports, presentations, recommendations, and findings




