Pomelo Care is a healthcare organization that exists to help families have healthy babies. Specifically, the company provides 24/7 pregnancy and newborn care by
Staff Security Engineer
Location
United States
Posted
1 day ago
Salary
$220K - $260K / year
Seniority
Lead
Job Description
Staff Security Engineer
Pomelo Care
Role Description Security at Pomelo is an engineering problem. This role owns the execution side — the controls, automation, and code that actually reduce risk — with a lot of latitude to decide what matters and ship it. A separate compliance team owns policy and audit; you build the things that make us safer. - Own security problems end to end: navigate ambiguity to decide what matters, build it, ship it independently. - Find the real risks and build the most direct controls that take them off the table. - Build secure-by-default libraries, guardrails, and tooling so dozens of engineers can move fast without footguns. - Define and implement strict least-privilege guardrails across all services to safeguard sensitive patient information and health metrics. - Harden developer machines to minimize the risk of supply chain attacks and Whatever Comes Next from AI. - Partner with compliance to turn control objectives into real controls, and help focus effort on the requirements that genuinely reduce risk and unlock new commercial opportunities (HITRUST, health plan requirements, etc.). Qualifications - You have a strong track record of making organizations measurably safer. That track record is risks you've closed, not tickets you've opened. - You can tell signal from noise, and you spend your time on the risks that actually move the needle. - You're a builder first: 7+ years of software engineering with production-grade code under your belt (Kotlin, Java, Python, Go, C# or similar). - You have real security depth — threat modeling, identity and auth flows, the OWASP Top 10, cloud and supply-chain security. - When something's wrong, your instinct is to understand the actual threat and build the most direct fix — not to go shopping for a product that claims to handle it. - You're looking for room to own more over time — and you're the type to take it, not wait for it. Requirements - Have built in healthcare and understand HIPAA and HITRUST — and how to satisfy them without drowning engineering in process. - Have experience with Google Cloud Platform and a modern product stack. - Have built internal developer platforms or secure-by-default tooling that other engineers actually adopted. - Have worked in a fast-paced, product-oriented startup. Benefits - Comprehensive Health, Dental, and Vision coverage for employees and their families - High deductible Health Plans with Health Savings Account (HSA) options - Flexible Spending Account (FSA) - Equity grant participation - 401(k) program - Competitive vacation policy - 16 weeks paid parental leave - Fully remote work flexibility (within the US) Compensation The expected base salary range offered for this role is $220,000-$260,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications. Potential Fraud Warning Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information. Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com. If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at careers@pomelocare.com to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Engineer II, Software Assurance, Product Security
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
• Help us protect CrowdStrike and its customers from the most advanced threats by assessing, designing, and implementing security controls and systems associated with all aspects of the software supply chain. • CrowdStrike's Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike's products. • As a Security Engineer II, you will focus on securing our open-source footprint and upstream dependencies. • You will perform technical security assessments of GitHub organizations and open-source integrations, monitor for malicious packages, create tooling for known gaps, and create automations to make operations more efficient. • Additionally, you will collaborate on cross-cutting projects to further harden internal and public-facing source code repositories against active and emerging threats.
Role Description Compliance ist für dich kein Selbstzweck. Vielmehr möchtest du Strukturen entwickeln, die Vertrauen schaffen und gleichzeitig schnelle Entscheidungen ermöglichen. Du verstehst Informationssicherheit als Wettbewerbsvorteil und Governance als Fundament für nachhaltiges Wachstum. Du denkst strategisch, arbeitest pragmatisch und verlierst auch bei komplexen regulatorischen Anforderungen nie den Blick für das Wesentliche. Auditoren überzeugst du mit belastbaren Nachweisen, interne Teams mit sinnvollen Lösungen und unsere Kunden mit Professionalität und Kompetenz. Wir sind ISO 27001- und TISAX-zertifiziert und entwickeln unsere Assurance-Landschaft konsequent weiter. Der Aufbau eines internen Kontrollsystems nach ISAE 3402 / IDW PS 951 läuft bereits, SOC 2 Type II ist der nächste große Meilenstein. Genau hier kommst du ins Spiel. Deine Mission: - Du übernimmst die fachliche Verantwortung für Compliance und Information Security bei instellix und entwickelst unsere Governance-Landschaft konsequent weiter. - Gemeinsam mit unserer Informationssicherheitsbeauftragten stellst du sicher, dass unsere Sicherheits- und Compliance-Standards nicht nur Audits bestehen, sondern unseren Kunden jeden Tag Vertrauen geben. - Dabei arbeitest du eng mit Engineering, Product, People, Finance und der Geschäftsführung zusammen und sorgst dafür, dass Compliance als Enabler verstanden wird – nicht als Hindernis. Was gehört dazu? - Du entwickelst unser Compliance-Programm strategisch weiter und übernimmst die fachliche Verantwortung für unseren Compliance- und Information-Security-Bereich. - Du verantwortest die kontinuierliche Weiterentwicklung unseres Informationssicherheitsmanagementsystems nach ISO 27001:2022 – von Management Reviews über Zielplanung bis hin zu Überwachungs- und Rezertifizierungsaudits. - Du baust unser internes Kontrollsystem nach ISAE 3402 / IDW PS 951 weiter aus, etablierst belastbare Nachweis- und Evidenzprozesse und koordinierst die Zusammenarbeit mit Wirtschaftsprüfern. - Du führst unser SOC-2-Programm ein und steuerst sämtliche Aktivitäten von der System Description bis zur erfolgreichen Type-II-Prüfung. - Du entwickelst unsere Security Governance kontinuierlich weiter – von Richtlinien über Vendor-Management bis hin zu organisatorischen und technischen Sicherheitsmaßnahmen. - Du beobachtest regulatorische Entwicklungen wie NIS2, EU AI Act oder neue Compliance-Anforderungen und übersetzt sie in praktikable Maßnahmen für unser Unternehmen. - Du unterstützt unseren Vertrieb bei Enterprise-Kunden, beantwortest Security-Fragebögen, begleitest Kundenaudits und bist kompetente Ansprechperson für alle Security- und Compliance-Themen. - Du übernimmst als Senior Verantwortung über deine eigenen Aufgaben hinaus. Du hinterfragst bestehende Prozesse, entwickelst Strukturen weiter und bist Sparringspartner für Management und Fachbereiche. Qualifications - Du verfügst über mindestens fünf Jahre Berufserfahrung im Bereich Information Security Governance, IT-Compliance oder IT-Audit – beispielsweise in einer Wirtschaftsprüfungsgesellschaft, einer Beratung oder einem SaaS-Unternehmen. - Du hast praktische Erfahrung mit mindestens zwei relevanten Frameworks wie ISO 27001, ISAE 3402 / IDW PS 951, SOC 2 oder TISAX und idealerweise bereits Kontrollsysteme aufgebaut oder Audits verantwortlich begleitet. - Du verfügst über ein solides technisches Verständnis und kannst mit Engineering-Teams auf Augenhöhe über Cloud-Architekturen, Zugriffskonzepte, Change Management oder Verschlüsselung sprechen. - Du kommunizierst sicher mit Auditoren, Wirtschaftsprüfern, Enterprise-Kunden und internen Stakeholdern und schaffst es, komplexe Anforderungen verständlich zu vermitteln. - Du arbeitest strukturiert, eigenverantwortlich und lösungsorientiert. Statt Prozesse lediglich zu verwalten, entwickelst du sie aktiv weiter. - Du verstehst Compliance als Business Enabler. Dein Anspruch ist es, Anforderungen so umzusetzen, dass sie Sicherheit schaffen, ohne unnötige Bürokratie zu erzeugen. - Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift runden dein Profil ab. Requirements - Zertifizierungen wie CISA, CISM oder ISO 27001 Lead Implementer bzw. Lead Auditor sind ein Plus, kein Muss. - Erfahrung mit Compliance-Automatisierungslösungen wie Vanta oder Drata. - Kenntnisse zu GoBD, Datenschutz, NIS2 oder dem EU AI Act. Benefits - Gestaltung statt Verwaltung – Du übernimmst eine neu geschaffene Schlüsselrolle mit direkter Berichtslinie an die Geschäftsführung und großem Gestaltungsspielraum. - Starkes Fundament – Du baust nicht bei null auf. Ein zertifiziertes ISMS, etablierte Prozesse, eine klare Roadmap und eine erfahrene Informationssicherheitsbeauftragte bilden die Basis für deine Arbeit. - Innovatives Produkt – Du arbeitest mit an unserer SaaS-Plattform instellix, die den stark wachsenden Markt für Subscription Management, Billing, Payment und Accounting nachhaltig verändert. - Kollegiale Kultur – Unsere Zusammenarbeit basiert auf Vertrauen, Eigenverantwortung, Verbindlichkeit und dem gemeinsamen Anspruch, die beste Lösung zu finden. - Work-Life-Balance – Mit 100 % Remote-Arbeit innerhalb Deutschlands sowie flexiblen Arbeitszeiten ohne Kernzeiten kannst du Beruf und Privatleben optimal verbinden. - Teamevents – Obwohl wir deutschlandweit verteilt arbeiten, kommen wir regelmäßig zusammen. Ob Sommerfest, Offsites oder Weihnachtsfeier – wir investieren bewusst in persönliche Begegnungen. - Freiraum – Du erhältst die Freiheit, Ideen einzubringen, Verantwortung zu übernehmen und nachhaltige Veränderungen umzusetzen. Next Steps Wenn du Compliance nicht als Selbstzweck, sondern als strategischen Erfolgsfaktor verstehst und Lust hast, den nächsten Reifegrad unserer Governance-Landschaft aktiv mitzugestalten, freuen wir uns auf deine Bewerbung. Sende uns deinen Lebenslauf, relevante Zeugnisse sowie – wenn du möchtest – ein Anschreiben. Teile uns außerdem deine Verfügbarkeit und deine Gehaltsvorstellung mit. Wir freuen uns darauf, dich kennenzulernen.
Role Description We're looking for a highly motivated Staff Security Engineer to join our DevSecOps team and help build and operate the security foundation of Nue's platform and engineering systems. This is not a policy or analyst role. We want someone who is hands-on, writes code, automates security controls, improves infrastructure, hardens systems, and helps engineers ship safely at speed. You'll work at the intersection of software engineering, cloud infrastructure, security operations, and developer enablement. You'll partner closely with Product Engineering, Platform, and DevSecOps teams to reduce real risk through practical engineering. If you're passionate about securing cloud-native systems, building internal tooling, improving detection and response, and making security a force multiplier for engineering, this is the role for you. Responsibilities - Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows. - Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions. - Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery. - Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes. - Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement. - Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps. - Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems. - Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk. - Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices. - Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through. - Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets. Qualifications - Bachelor's degree in Computer Science, Engineering, or equivalent practical experience. - 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments. - 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles. - Strong hands-on experience securing cloud-native environments on AWS. - Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash. - Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows. - Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design. - Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms. - Practical experience with security monitoring, detection engineering, alert tuning, and incident response. - Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection. - Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness. - Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment. - Comfortable working in a fast-paced startup environment with a small, high-impact team. - Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck.
Information Security Officer
PROMOS consultBereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!
Role Description - Gestaltung, Weiterentwicklung und Verbesserung von Informationssicherheit in einem Unternehmen - Analyse von Risiken und Entwicklung pragmatischer Lösungen zur Erhöhung des Sicherheitsniveaus - Erstellung von Richtlinien, Standards und Sicherheitskonzepten - Beratung von Kolleginnen und Kollegen sowie Zusammenarbeit mit unterschiedlichen Fachbereichen - Begleitung von Projekten und Veränderungen aus Sicht der Informationssicherheit - Durchführung von Audits, Reviews und Sicherheitsbewertungen - Vermittlung von Sicherheitswissen durch Schulungen und Awareness-Maßnahmen - Beobachtung neuer gesetzlicher, regulatorischer und technologischer Entwicklungen im Bereich Informationssicherheit Qualifications - Studium oder vergleichbare Qualifikation im Bereich Informationssicherheit, IT, Wirtschaftsinformatik, Informatik oder einem ähnlichen Fachgebiet - Erste praktische Erfahrungen im Bereich Informationssicherheitsmanagement (ISMS) - Interesse an Informationssicherheitsstandards wie ISO 27001 und ISO 27002 - Gutes technisches Grundverständnis von IT-Systemen und Prozessen - Interesse an Themen wie Datenschutz, Compliance, NIS2 und regulatorischen Anforderungen - Strukturiert, zuverlässig und eigenverantwortlich arbeitend - Freude an der Kommunikation mit unterschiedlichen Ansprechpartnern und Wissen zu vermitteln - Wunsch nach kontinuierlicher fachlicher und persönlicher Weiterentwicklung Benefits - Flexible Arbeitszeiten und die Möglichkeit, wo du möchtest zu arbeiten: in unseren Büroräumen, im Home-Office oder mobil in und außerhalb Deutschlands - 30 Tage Urlaub, eine 39 Stunden-Woche bei Vollzeit oder individuelle Teilzeitmodelle - Faires und branchenorientiertes Gehalt, das deiner Erfahrung und Qualifikation entspricht - Ausgewogenes Programm rund um health@PROMOS, wie z.B. Urban Sports-Mitgliedschaft, JobRad, monatliche Gesundheitsangebote und Zuschuss zur Arbeitsplatzbrille - Regelmäßige Teamevents sowie jährliche Sommer- und Weihnachtsfeste - Weitere Benefits, die PROMOS zum Great Place to Work machen Company Description Bereits 1998 gegründet, zählt PROMOS consult zu den führenden Beratungs- und Systemhäusern, das Softwarelösungen speziell für die Wohnungs-, Bau- und Immobilienwirtschaft entwickelt. Seit vielen Jahren sind wir innovativ und arbeiten am Puls der Zeit. Das Portfolio setzt sich aus einem breiten Spektrum an Tools für das professionelle Immobilienmanagement zusammen – von der App über digitale Workflows in SAP® bis zum Full-Service im Rechenzentrum. Neugierig? Dann werde Teil unserer Vision von einer digitalisierten Zukunft!

