Lead Cloud Security Engineer

1upHealth Remote

Company

1upHealth

Location

Remote

Type

Full Time

Job Description

As the Lead Cloud Security Engineer on the 1upHealth Product Security team, you will help harden our overall security on our architecture and software platform.  The security engineer will be joining our sec-ops team, working through any security issue that comes up internally or with a customer.  As a HIPAA compliant company, we strive to protect all of our customers' data in the cloud and are always improving our security and the security culture within the organization. 


In this role, you’ll get to:

  • Lead engineers to securely architect services across the organization (design reviews, threat modeling, security testing)

  • Harden our environments against online threats and data loss to reduce and mitigate risks

  • Create new security defensive tools and integrations to elevate security across the organization

  • Mentor other engineers on the team and in the organization

  • Share your passion for security and shape our security culture across the organization

  • Participate in our incident response and vulnerability remediation efforts

  • Audit logs and events to ensure compliance with our SOC2 information security policy

  • Work in a team oriented, collaborative environment

 

We are looking for people who have:

  • Experience working with cloud environments and services

  • Prior work experience in an application security role

  • Advanced knowledge of security concepts (browser security model, cryptography, network security, etc) based on relevant courses, self-learning or past internships

  • Familiarity with identifying and protecting against web application and web service security vulnerabilities including those found in the OWASP API / Web App Top 10s and CWE Top 25

  • Relevant development experience in some of these technologies: Java, JavaScript / NodeJS / TypeScript, Python, Terraform, WAFs

  • Ability to work in an Agile Scrum environment

  • B.S. / M.S. in Computer Science, Electrical Engineering or related experience

  • Expertise with security tools such as static analysis, runtime analysis, black-box testing, etc.(Burp Suite, OWASP ZAP, Snyk, Metasploit, Tenable, Lacework)

 

You may also have:

  • Contributions to the security community such as research, public CVEs, bug-bounty recognitions, open-source projects, and blogs or publications.

  • Attacker mindset: Passion for breaking all things unbreakable, experience as a white-hat engineer

  • CISSP or other security certifications

  • HIPAA / GDPR / HITRUST experience


About 1upHealth
At 1upHealth, our mission is to unlock health data and improve industry outcomes. As leaders in FHIR® interoperability, our platform makes it easier for partners to access, integrate, aggregate, and share data across a variety of systems. 1upHealth is building a data ecosystem to promote the digital transformation of the industry and encourage insight-driven healthcare.
 
We are proud to announce that we have been named 2022 Best Places to Work in the Small Company and Best Paying Company categories by Built In Boston.
 
Benefits
100% Paid BCBS Medical and Dental Insurance for Employees
Vision Insurance
Unlimited PTO
Equity
401(k)
Home Office Stipend
Commuter Stipend
Wellness Reimbursement
Parental Leave (16 weeks for birthing parents, 6 weeks for non-birthing parents)
Company Meetings with Free Lunch
Apply Now

Date Posted

06/22/2023

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Director of Pricing - Garner Health

Views in the last 30 days - 0

Garner Health is a rapidly growing company backed by toptier venture capital firms Their mission is to transform the healthcare economy by delivering ...

View Details

Director, Product, Customer, and Lifecycle Marketing - Garner Health

Views in the last 30 days - 0

Garner Health is seeking an experienced Product Marketing Leader to join their team The ideal candidate will lead the product marketing efforts focusi...

View Details

Linux Support Engineer - Voltage Park

Views in the last 30 days - 0

Voltage Park is seeking a Linux Support Engineer for a fulltime remote position The ideal candidate will have command line level Linux sys administrat...

View Details

Data Analyst - Agero

Views in the last 30 days - 0

Agero a leading B2B whitelabel provider of digital driver assistance services is revolutionizing the vehicle ownership experience through datadriven t...

View Details

Director, Product (Remote) - Dscout

Views in the last 30 days - 0

Dscout is a leading company in experience research technology offering a platform for major companies to gain insights into user needs and behaviors T...

View Details

Technical Architect - CDW

Views in the last 30 days - 0

CDW offers a rewarding career opportunity for a Technical Architect with expertise in ServiceNow The role involves delighting customers by collaborati...

View Details