Access. Answers. Advocacy. We're raising the standard of healthcare for everyone.
Staff Software Engineer, Cloud Security
Location
United States
Posted
9 days ago
Salary
$174.3K - $320.1K / year
Seniority
Lead
Job Description
Staff Software Engineer, Cloud Security
Included Health
• Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams. • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions. • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response. • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools. • Implement and champion Infrastructure as Code (IaC) principles, **specifically using Terraform,** for programmatic definition, enforcement, and auditing of security configurations. • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering. • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks. • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools. • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams. • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls. • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data. • Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines. • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices. • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows. • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response. • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.
Job Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 5+ years of experience in cloud security, with a strong emphasis on designing, **developing (primarily in Python and Go),** and implementing security solutions in AWS.
- Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management.**
- Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions.**
- Experience with Infrastructure as Code (IaC) with **deep proficiency in writing and maintaining Terraform modules for security.**
- Experience with containerization (Docker, Kubernetes/EKS), including **hands-on experience hardening containerized environments.**
- Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices.
- Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go).
- Experience with cloud security frameworks (especially HIPAA), regulations, and standards.
Benefits
- Remote-first culture
- 401(k) savings plan through Fidelity
- Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
- Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
- 12 weeks of 100% Paid Parental leave
- Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
- Work-From-Home reimbursement to support team collaboration home office work
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Design and implement cloud security controls across AWS and Google Cloud, including multi-account architecture, network segmentation, data protection, and secure-by-default infrastructure patterns. • Build reusable Terraform modules, reference architectures, policy-as-code guardrails, and self-service tooling that make secure implementation easier for engineering teams. • Operate and tune CSPM/CNAPP tooling to identify misconfigurations, exposures, toxic combinations, and coverage gaps across Fullscript’s cloud environments. • Drive remediation of cloud vulnerabilities and misconfigurations, balancing risk, engineering effort, customer impact, and business priorities. • Strengthen IAM, secrets management, key rotation, cloud credentials, machine identities, and just-in-time access patterns across cloud and SaaS environments. • Embed security into CI/CD pipelines through IaC scanning, container image scanning, SBOM generation, artifact protection, and software supply chain controls. • Partner with the SOC and engineering teams on cloud-native detections, logging, runbooks, incident response, post-incident learning, and secure AI/ML workload patterns.
• Lead the design and implementation of security solutions across Fullscript's applications, platforms, and AI-powered systems. • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews. • Drive application security, product security, and vulnerability management initiatives from concept through implementation. • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions. • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions. • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration. • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript's long-term security posture.
Director, Product Management – Customer Security Outcomes
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
• Define and document an aligned vision and strategy for the future of threat detection, risk/exposure, and cyber operations services based on market and customer feedback • Set customer-driven, world-class security operations outcomes and measures across managed investigation, managed response, threat hunting, and advisory services • Partner with Customer Security Operations and Product teams to implement features that deliver industry-leading security outcomes and ensure operational alignment • Represent Zscaler as a customer-facing visionary thought leader, participating in executive customer advisory boards and managing critical incidents and escalations • Collaborate with Product Marketing to establish Zscaler as the industry leader in security operations by setting the standard for understanding and achieving great security outcomes
Epic Analyst Associate, Epic Security Team
Prisma HealthOur Purpose: Inspire health. Serve with compassion. Be the difference.
• Configures programs, screens, pathways, reports, and/or job instructions to meet detailed user specifications. • Supports I/S Epic Analysts in providing technical assistance to customer departments and maintains databases for one or more applications supported by the team. • Works with assigned departments to prioritize development initiatives and activities. • Maintains system hardware and/or software for one or more of the supported applications. • Working with more advanced Analysts, provides analysis of workflow, recommends solutions, and implements application solutions to meet departmental needs. • Coordinates and resolves system problems related to technology used by assigned systems. • Supports internal customers in such functional areas including, but not limited to, nursing, ancillary departments, Physician practice, patient accounting, medical records, finance, human resources, purchasing, sales, and contracts. • Assists in managing system upgrades and other small projects.



