Job Closed

This listing is no longer active.

Aledade, Inc. logo
Aledade, Inc.

With Primary Care. For Primary Care.

Security Engineer II – GRC

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 501-1,000Since 2014H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

131 days ago

Salary

0

Seniority

Senior

Bachelor Degree3 yrs expEnglishCyber Security

Job Description

Security Engineer II – GRC

Aledade, Inc.

• Manage the end-to-end lifecycle of inbound security questionnaires from partner physician practices. Ensure responses are technically accurate, timely, and reflect our latest security posture. • Lead security evaluations for Aledade’s vendors. Analyze SOC2 reports, penetration test results, and self-assessments to ensure our supply chain meets our rigorous healthcare security standards. • Maintain and optimize our security response repository. You’ll ensure our "Source of Truth" is updated as our infrastructure evolves • Identify bottlenecks in the assessment workflow and implement scalable solutions, such as self-service "Trust Centers" for partners, to reduce the manual overhead of the GRC function.

Job Requirements

  • 3 - 5 years of experience in Governance, Risk, and Compliance, Information Security or related fields.
  • Practical experience working with SOC2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
  • Demonstrated experience preparing organizations for external audits and regulatory certifications.
  • Hands-on experience with GRC platforms (e.g., Vanta, OneTrust, Archer, or similar).

Benefits

  • Flexible work schedules and the ability to work remotely are available for many roles
  • Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
  • Robust time-off plan (21 days of PTO in your first year)
  • Two paid volunteer days and 11 paid holidays
  • 12 weeks paid parental leave for all new parents
  • Six weeks paid sabbatical after six years of service
  • Educational Assistant Program and Clinical Employee Reimbursement Program
  • 401(k) with up to 4% match
  • Stock options
  • And much more!

Related Categories

Related Job Pages

More Security Engineer Jobs

Human Interest logo

Security Engineer II

Human Interest

Affordable, full-service 401(k) plans for SMBs.

Security Engineer131 days ago
OtherRemoteTeam 501-1,000Since 2015H1B Sponsor

• Build practical controls to improve the effectiveness and robustness of our engineering team • Foster a DevSecOps culture through education, automation, and tooling. • Secure our SDLC process through automation • Implement checks in pipeline • Perform security reviews of application code • Take part in team on call rotation for security events and monitoring alerts • Advocate and educate security best practices • Create tooling and automation to efficiently respond to security events • Partner with stakeholders to respond and mitigate security threats

United States
$160K - $185K / year
OtherRemoteTeam 5,001-10,000H1B Sponsor

• managing the full-cycle sales process through qualification, needs analysis, product demonstration, Proof of concept (PoC), negotiation and close • being accountable for your sales target and overachieving on that sales target • building customer relationships and qualifying opportunities such that the sales forecast is accurate • working closely with a Sales Engineer and ensuring their time is used optimally

Illinois
$245K - $441K / year
Job Closed

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Charlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will be the subject matter expert on application and cloud infrastructure security, guiding the business in building secure, scalable and HIPAA-compliant software solutions. Responsibilities - Lead application security program including SAST/DAST integration, security code reviews and developer training. - Perform threat modeling and architecture reviews to identify potential security risks early in design phases. - Integrate security tooling and automate security processes into CI/CD and DevOps pipelines. - Manage application and cloud security vulnerability management program including configuration of scanning tools, validation and prioritization of findings, and remediation of risks. - Review and document new third-party integrations with Charlie Health applications and cloud infrastructure. - Perform internal penetration testing and manage third-party penetration tests. - Work with teams to build and enforce secure SDLC controls in a fast-paced agile environment. - Develop cloud security configuration baselines and monitor for gaps. - Document business continuity and disaster recovery procedures for cloud infrastructure environment. - Participate in security incident response activities related to Charlie Health applications and infrastructure systems. - Help define metrics and KPIs that demonstrate the effectiveness of the application and cloud security programs. Qualifications - 10+ years of experience in application security, secure software development, cloud security or related roles. - Bachelor’s degree in Computer Science or related field, or equivalent experience. - Proficiency in secure coding practices and languages such as Typescript, Node, Python, Java, C++ or similar. - Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler). - Knowledge of container security concepts, including container image scanning, secure image pipelines, and common misconfigurations in containerized environments. - Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc. - Experience implementing security in CI/CD pipelines such as GitHub Action and agile development workflows. - Familiarity with AWS cloud platform and AWS security best practices. - Familiarity with management and deployment of SAST, DAST, and SCA tooling. - Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications. - Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences. Preferred Qualifications - Experience with HIPAA and securing applications in healthcare, or other regulated, environments. - OSCP, OSWE, AWS Security or other relevant security certifications. - Experience securing custom software collaboratively on a team. - Experience with Wiz or similar CNAPP tools. - Knowledge of AI/ML security best practices. - Familiarity with Infrastructure as Code (IaC). - Knowledge of security standards such as SOC2, ISO 27001/2, NIST 800-53, HITRUST, or HIPAA Security Rule. Benefits - Comprehensive benefits to all full-time, exempt employees. - Total target base compensation for this role will be between $180,000 and $240,000 per year. - Pay will be determined on an individualized basis and will be impacted by location, experience, expertise, internal pay equity, and other relevant business considerations. - Cash compensation is only part of the total compensation package, which may include stock options and other Charlie Health-sponsored benefits.

United States
$180K - $240K / year
Job Closed
ProArch logo

Security Specialist

ProArch

Consulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.

Security Engineer132 days ago
OtherRemoteTeam 201-500H1B Sponsor

• Initial setup and deployment of security solutions and operational technology security measures. • Creating and delivering detailed reports and maintaining technical documentation. • Conducting security training sessions and assessments to enhance security awareness and identify vulnerabilities. • Provide expert advice, guidance, and ad-hoc consulting services to address specific security needs. • Ongoing configuration, maintenance, and management of security solutions and systems. • Delivering presentations, conducting proof-of-concepts, and engaging with the public through various platforms. • Focuses on enhancing and optimizing security programs and processes. • Implementation & Management of Microsoft Security Solutions, Security Information & Event Management (SIEM), and Extended Detection & Response (XDR) security architecture. • Solution research & design, emerging technology evaluation. • Solution configuration management. • Ticket Queue management and supporting customers through ticket ownership. • Account & permission management, provisioning, governance for security solutions. • Microsoft or other 3rd party vendor Security workshops. • Incident Response investigation, writing, delivery, as appropriate.

New York
Job Closed