Technology driven care with a human touch. Anytime. Anywhere.
Security Engineer
Location
California
Posted
97 days ago
Salary
$0
Seniority
Senior
Job Description
Security Engineer
Uprise Health
We are a digital mental health company that cares for the total person with the same passion we have for our friends, family, and community. We are committed to: Honesty & Transparency Integrity & Respect Simplicity Urgency Win & Celebrate Winning! Essential Duties and Responsibilities: We’re looking for a creative and experienced security professional to design, implement, and monitor technical controls in our environment. This position requires strong knowledge of security vulnerabilities, networking, and cloud infrastructure design. You’ll need to use both defensive and offensive techniques to test and progressively harden our infrastructure, as well as monitor and respond to real world concerns. Job Requirements:
Job Requirements
- Monitor cloud based security infrastructure, SASE/ZTNA environments. Provide design guidance.
- Develop automation for routine security tasks.
- Assess vulnerabilities across machines, networks, and self developed assets, and take lead in addressing vulnerabilities along with system administration and engineering teams.
- Conduct white/grey box penetration testing against Uprise Health’s applications.
- Perform scripting to enhance technical controls for physical and cloud, and network assets.
- Represent the security team with internal and external stakeholders.
- Help guide IT in the implementation of identity and access strategies.
- Advise software development teams on secure cloud infrastructure, analyze static analysis test results and advise engineering on best practices.
- Continually evaluate core infrastructure for constant improvement of security posture.
- Respond to detections or other reported events.
- Essential Education and Experience:
- Thorough understanding of OWASP, CVSS, MITRE ATT&CK and attack lifecycles.
- Experience assessing cloud services.
- Be able to think offensively and to apply lessons of that thinking to protect our environments.
- Experience analyzing network and host-based security events.
- BS in computer science, engineering, or related discipline.
- 5+ years of experience in Cyber Security.
- Ability to script in PowerShell, Python, or Bash.
- Knowledge across platforms (Windows, OSX, Linux).
- 3+ years Experience in cloud technology.
- Working Environment:
- The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- While performing the duties of this job, the employee regularly works near office equipment (telephone, computer) and other employees. The employee works in normal office conditions where there is no physical discomfort due to temperature, dust, noise, etc. Verbal and written communication, telephone usage, filing, sitting, typing, driving, reading and carrying required to perform the essential functions of this job.
- Uprise Health is an equal opportunity employer. In accordance with anti-discrimination law, Uprise Health prohibits discrimination and harassment of any type and affords equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law. Uprise Health conforms to the spirit as well as to the letter of all applicable laws and regulations.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Plan and engineer the integration of a wide variety of cybersecurity and IT tools into Wraithwatch’s core artificial intelligence engine. • Ensure AI engine has access to common data models and function execution models across disparate sets of IT and security tools. • Provide cybersecurity subject matter expertise, oversight, and optimization into autonomous reasoning and analysis performed by Wraithwatch system. • Own Wraithwatch’s internal corporate cybersecurity posture across our company endpoints, cloud systems, build pipelines, and AI subsystems.
Director, Privacy & Security, Legal
SentinelOneSecure your enterprise with the autonomous cybersecurity platform. Endpoint. Cloud. Identity. XDR. Now.
• Develop and execute a global legal strategy for privacy and data security that aligns with SentinelOne’s rapid growth and product innovation. • Work cross-functionally across the organization, supporting the Commercial team on the privacy aspects of both inbound and outbound work while collaborating closely with the Legal Product team. • Provide expert guidance on a wide range of privacy, security, and compliance matters, ensuring that legal requirements are integrated seamlessly into our technical operations. • Lead the legal side of incident management and response, providing strategic advice and legal guidance on all types of incidents to ensure the company navigates complex security events with precision and speed.
__Own The Role:__112Cyber (formerly SP6 Cyber Risk & Compliance) is looking for a Compliance SME wanting to take the next step in their career! In this role, you will assist organizations in solidifying and strengthening their security posture while also conducting assessments for those pursuing certification. Joining our Compliance team, you will see your impact across the company as you take ownership over customer projects and advising our platform team on the different compliance rules. From there, you will be supporting Defense Industrial Base (DiB) companies to ensure they are CMMC and/or NIST 800-171 compliant. You will accomplish this through providing pre-audit readiness and GAP assessments, plans of action and milestones (POA&M) support, Compliance as a Service (CaaS), and official C3PAO assessments. __**How You’ll Drive Success:**____Advisory Services__ - Leading cybersecurity gap assessments aligned with NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC). - Supporting the day-to-day activities of engagements for external clients, as a contributing member of 112Cyber’s customer-facing Cyber Risk & Compliance practice. - Assist external customers in their FedRAMP, DFARS 7012, CMMC, and NIST 800-171 compliance initiatives. - Applying cyber compliance / risk management knowledge, control principles and technical knowledge across cyber risk and compliance engagements. - Consulting with end clients to gather requirements and understand our clients' key business and security challenges. Working with team members to advise on practical and cost-effective solutions to help mitigate our clients’ cybersecurity risks and challenges. - In depth knowledge of relevant security regulatory compliance requirements and translating those into business processes and security controls to enhance and support client’s compliance and audit capabilities. - Articulating and defending IT controls testing approach and performing test of design and operating effectiveness. - Develop and deliver training to internal teams and customers. - Establishing and maintaining effective working relationships with colleagues, existing clients, and prospective client organizations. - Supporting the ASCERA product team and advising them on NIST continuous monitoring software. __C3PAO Assessments__ - Conducting formal assessments of organizations’ cybersecurity practices using the CMMC assessment process (CAP). - Collaborate with client organizations to plan assessments, develop assessment schedules, and ensure readiness - Assess the effectiveness of security practices and ensure they align with the CMMC practices and processes. - Interview key personnel within the organization to understand how cybersecurity practices are implemented and maintained. - Evaluate sufficiency and adequacy of evidence to verify implementation. - Maintain an objective and unbiased stance during the assessment process, ensuring that conclusions are based on facts and evidence. - Ensure that all documentation is properly prepared for submission to eMASS if the organization is seeking certification.
Senior Software Engineer – OpenShift Infrastructure, Security Compliance
Red HatThe leading provider of enterprise open source solutions.
• Develop tooling to generate and automate regulatory benchmark guidance • AI driven tooling (MCP servers/toolsets) that integrates with IDEs (Claude Code/Cursor) • Understanding Compliance Operator resources, like CustomRules and Profiles • Implementing checks using multiple scanning technologies, like OpenSCAP and CEL expressions • Developing and maintaining operators that improve OpenShift security posture • Contribute to industry benchmark regulatory bodies where applicable (CIS)




