Security Engineer - Commercial Infrastructure Engineering
Company
Nuna Inc.
Location
Silicon Valley CA
Type
Full Time
Job Description
At Nuna, our mission is to make high-quality healthcare affordable and accessible for everyone. We are dedicated to tackling one of our nation’s biggest problems with ingenuity, creativity, and a keen moral compass.
Nuna is committed to simple principles: a rigorous understanding of data, modern technology, and most importantly, compassion and care for our fellow human. We want to know what really works, what doesn't—and why.
Nuna partners with healthcare payers, including government agencies and health plans, to turn data into learnings and information into meaning.
The Nuna Security team is responsible for protecting the confidentiality, integrity, and availability of all healthcare data, client information, intellectual property, and employee data entrusted to our organization. The Nuna Security Team covers the gamut of security across the corporate and production environments. We secure the web applications, the product infrastructure, and the corporate infrastructure. We work closely with the Compliance Team to ensure that we are meeting security standards and providing our customers with the utmost assurance that we will keep their data safe. We stay ahead of the constantly evolving threat landscape by building and maintaining automated solutions, fostering a security-aware culture across teams, and constantly challenging assumptions. We flourish with our ability to participate and give back to the healthcare industry and security community through leadership, education, and code.
YOUR IMPACTAs a Senior Security Engineer, you will protect the data of tens of millions of Americans by working closely with our distributed compliance, privacy, and engineering teams to audit and harden our products and internal tooling.
YOUR OPPORTUNITIES- Help Nuna achieve HITRUST accreditation by collaborating with our Compliance, Infrastructure, and Development teams
- Lead the development of a Vulnerability Management Program, define remediation workflows, and automate reports on a regular cadence
- Collaborate with engineering and product partners to build threat models and design controls to ensure that our nation-scale healthcare data is protected.
- Partner with other teams to identify and evaluate risk and provide recommendations for mitigation and remediation.
- Encourage adoption of security methodologies and architecture changes throughout the company via evangelism and education.
- Lead the design and development of security capabilities such as static analysis, threat modeling, security requirements enforcement, and security linting as part of a CI/CD development process.
- Mentor and educate other security engineers about best practices, scalable security tooling, secure AWS development, etc.
- Experience and understanding of security audits and accreditations
- Experience building out security scanning and remediation programs
- 5+ years of security experience with a clear understanding of industry best practices and a shown ability to respond to evolving risks.
- Shown leadership, organization, and communication skills. Possessing the ability to effectively prioritize tasks across multiple partners.
- Capable of analyzing requirements, designing system-level threat models, and defining and running resultant security requirements.
- Proficient at configuring and hardening Linux and ancillary services using cloud orchestration and infrastructure-as-code.
- Proficient with authentication and authorization technologies such as Active Directory, LDAP, and SSO/SAML.
- Proficient with log analysis and auditing platforms such as Splunk.
- Proficient with Python or related scripting languages with experience applying fundamental computer science & software engineering practices.
- Experience with healthcare and government regulatory requirements.
- Willingness to conduct research, write white papers, and present technical content at local events and conferences.
- AWS cloud environment: EC2, S3, RDS, ELB, ECS, ECR, AWS VPCs and networking
- Operating systems: Linux, OS X and Windows
- Languages: Python, Go, Bash (knowledge of Java and Javascript a plus)
- Cloud orchestration framework: Packer, Puppet, Terraform
- Metrics and reporting: Splunk, AWS Config, AWS SNS, AWS CloudWatch, Prometheus
- Coordination & collaboration tools: Jira, Confluence, Slack, GSuite, Git
We take into account an individual’s qualifications, skillset, and experience in determining final salary. This role is eligible for health insurance, life insurance, retirement benefits, participation in the company’s equity program, paid time off, including vacation and sick leave. The expected salary range for this position is $151,000 to $180,000. The actual offer will be at the company’s sole discretion and determined by relevant business considerations, including the final candidate’s qualifications, years of experience, and skillset.
Nuna is an Equal Employment Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetics and/or veteran status.
Date Posted
01/07/2023
Views
7
Similar Jobs
Software Engineer, Data Platform (Lead) - Benchling
Views in the last 30 days - 0
Benchling a leading biotechnology company is seeking a Senior Software Engineer to design and implement scalable multitenant services and APIs The rol...
View DetailsSenior Product Manager, Enterprise - Atlassian
Views in the last 30 days - 0
Loom a video communication platform for asynchronous work is seeking a Senior Product Manager for its Enterprise team The role involves defining strat...
View DetailsSenior Product Manager, Dev Solutions - Atlassian
Views in the last 30 days - 0
Atlassian offers a remote position for a Product Manager in the Dev Solutions team The role involves collaborating with crossfunctional teams to lead ...
View DetailsTreasury Management Officer - Technology and Disruptive Commerce - JPMorganChase
Views in the last 30 days - 0
The job posting is for a Treasury Management Officer in Commercial Banking The role involves generating new treasury management business maintaining c...
View DetailsRelationship Executive, Middle Market Banking - Executive Director - JPMorganChase
Views in the last 30 days - 0
The job description is for a Relationship Executive role in the Middle Market Banking team The role involves building and retaining profitable relatio...
View DetailsSenior Account Sales Representative - Spectrum
Views in the last 30 days - 0
The job involves selling products and services to customers in assigned nonbulk multidwelling units through doortodoor solicitation lobby events and b...
View Details