Included Health logo
Included Health

Access. Answers. Advocacy. We're raising the standard of healthcare for everyone.

Staff Software Engineer, Cloud Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

9 days ago

Salary

$174.3K - $320.1K / year

Seniority

Lead

Job Description

Staff Software Engineer, Cloud Security

Included Health

• Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams. • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions. • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response. • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools. • Implement and champion Infrastructure as Code (IaC) principles, **specifically using Terraform,** for programmatic definition, enforcement, and auditing of security configurations. • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering. • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks. • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools. • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams. • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls. • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data. • Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines. • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices. • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows. • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response. • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.

Job Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of experience in cloud security, with a strong emphasis on designing, **developing (primarily in Python and Go),** and implementing security solutions in AWS.
  • Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management.**
  • Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions.**
  • Experience with Infrastructure as Code (IaC) with **deep proficiency in writing and maintaining Terraform modules for security.**
  • Experience with containerization (Docker, Kubernetes/EKS), including **hands-on experience hardening containerized environments.**
  • Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices.
  • Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go).
  • Experience with cloud security frameworks (especially HIPAA), regulations, and standards.

Benefits

  • Remote-first culture
  • 401(k) savings plan through Fidelity
  • Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
  • Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
  • 12 weeks of 100% Paid Parental leave
  • Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
  • Work-From-Home reimbursement to support team collaboration home office work

Related Categories

Related Job Pages

More Security Engineer Jobs

Fullscript logo

Cloud Security Engineer

Fullscript

Dispense your way | Currently hiring across North America!

Full TimeRemoteTeam 201-500Since 2016H1B No Sponsor

• Design and implement cloud security controls across AWS and Google Cloud, including multi-account architecture, network segmentation, data protection, and secure-by-default infrastructure patterns. • Build reusable Terraform modules, reference architectures, policy-as-code guardrails, and self-service tooling that make secure implementation easier for engineering teams. • Operate and tune CSPM/CNAPP tooling to identify misconfigurations, exposures, toxic combinations, and coverage gaps across Fullscript’s cloud environments. • Drive remediation of cloud vulnerabilities and misconfigurations, balancing risk, engineering effort, customer impact, and business priorities. • Strengthen IAM, secrets management, key rotation, cloud credentials, machine identities, and just-in-time access patterns across cloud and SaaS environments. • Embed security into CI/CD pipelines through IaC scanning, container image scanning, SBOM generation, artifact protection, and software supply chain controls. • Partner with the SOC and engineering teams on cloud-native detections, logging, runbooks, incident response, post-incident learning, and secure AI/ML workload patterns.

Canada
$100K - $110K / year
Fullscript logo

Staff Security Engineer

Fullscript

Dispense your way | Currently hiring across North America!

Full TimeRemoteTeam 201-500Since 2016H1B No Sponsor

• Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems. • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews. • Drive application security, product security, and vulnerability management initiatives from concept through implementation. • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions. • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions. • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration. • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.

Texas
Zscaler logo

Director, Product Management – Customer Security Outcomes

Zscaler

Zscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th

Full TimeRemoteTeam 8,697Since 2007

• Define and document an aligned vision and strategy for the future of threat detection, risk/exposure, and cyber operations services based on market and customer feedback • Set customer-driven, world-class security operations outcomes and measures across managed investigation, managed response, threat hunting, and advisory services • Partner with Customer Security Operations and Product teams to implement features that deliver industry-leading security outcomes and ensure operational alignment • Represent Zscaler as a customer-facing visionary thought leader, participating in executive customer advisory boards and managing critical incidents and escalations • Collaborate with Product Marketing to establish Zscaler as the industry leader in security operations by setting the standard for understanding and achieving great security outcomes

United States
$199.5K - $285K / year
Prisma Health logo

Epic Analyst Associate, Epic Security Team

Prisma Health

Our Purpose: Inspire health. Serve with compassion. Be the difference.

Full TimeRemoteTeam 10,001+H1B Sponsor

• Configures programs, screens, pathways, reports, and/or job instructions to meet detailed user specifications. • Supports I/S Epic Analysts in providing technical assistance to customer departments and maintains databases for one or more applications supported by the team. • Works with assigned departments to prioritize development initiatives and activities. • Maintains system hardware and/or software for one or more of the supported applications. • Working with more advanced Analysts, provides analysis of workflow, recommends solutions, and implements application solutions to meet departmental needs. • Coordinates and resolves system problems related to technology used by assigned systems. • Supports internal customers in such functional areas including, but not limited to, nursing, ancillary departments, Physician practice, patient accounting, medical records, finance, human resources, purchasing, sales, and contracts. • Assists in managing system upgrades and other small projects.

South Carolina
Job Closed