About the Role

Title: Security Engineer

Location: Remote

Job Description:

Garner’s mission is to transform the healthcare economy, delivering high quality and affordable care for all. By helping employers restructure their healthcare benefit to provide clear incentives and data-driven insights, we direct employees to higher quality and lower cost healthcare providers. The result is that patients get better health outcomes while doctors are rewarded for practicing well, not performing more procedures. We are backed by top-tier venture capital firms, are growing rapidly and looking to expand our team.

We are seeking a skilled and motivated Security Engineer to join our dynamic team. As a Security Engineer, you will play a crucial role in safeguarding our organization’s digital assets, ensuring the integrity and confidentiality of our systems and data. You will be responsible for the implementation and operations of security tooling with your existing IAC/platform skills, maintaining security controls, and responding to security incidents and breaches. This role offers an exciting opportunity to work with cutting-edge technology and improve the overall security posture of our organization.

Responsibilities:

  1. Security Engineering: Design, implement, and operate security tooling and services in cloud (including IAC related components) and on-premises ecosystems including, but not limited to, AWS and GCP, Snowflake, Wiz, Okta.
  2. Incident Detection and Response: Monitor security landscape for suspicious activity, investigate potential security incidents, and coordinate incident response efforts to mitigate threats and minimize their impact.
  3. Vulnerability Management: Assist regular vulnerability assessments and penetration tests, analyze results, and collaborate with relevant teams to prioritize and remediate security vulnerabilities in a timely manner.
  4. Security Compliance: Ensure compliance with relevant security standards, regulations, and best practices (e.g., HITRUST, SOC 2, ISO 27001) through continuous monitoring, auditing, and enforcement of security policies and procedures.
  5. Security Awareness and Training: Develop and deliver security awareness training programs for employees, educate stakeholders on security best practices, and promote a culture of security awareness throughout the organization.
  6. Security Incident Documentation and Reporting: Document security incidents, their resolution, and lessons learned for future reference. Prepare and present regular reports on security metrics, incidents, and trends to management and relevant stakeholders.
  7. Security Tool Evaluation and Integration: Research, evaluate, and recommend new security technologies, tools, and processes to enhance the organization’s security posture and capabilities. Integrate new security solutions into existing infrastructure as needed.
  8. Collaboration and Communication: Work closely with cross-functional teams, including IT, engineering, and compliance, to align security initiatives with business objectives, identify security requirements, and ensure the effective implementation of security controls.

Required Qualifications

  1. Is able to work autonomously while collaborating with cross-functional teams, can successfully manage multiple projects simultaneously, and effectively communicate technical information to non-technical stakeholders.
  2. In-depth knowledge of auditing cloud infrastructure for security risks, creating solutions that defend against those risks, and designing processes that provide systemic prevention against the risks.
  3. Strong understanding of common application and infrastructure security vulnerabilities and attack vectors as well as techniques for their detection, prevention, and mitigation.
  4. Strong understanding of and proven ability with Terraform in a cloud environment.
  5. Strong understanding of cloud IAM principles and best practices.
  6. Experience with using a SIEM to detect indicators of compromise, identifying the impact, and generating incident reports.
  7. Independent ability to write scripts or automated tooling.
  8. Understanding of network security principles, protocols, and technologies.

Desired Qualifications:

  1. Bachelor’s degree in Computer Science, Information Security, or a related field. Advanced degree or relevant certifications (e.g., CISSP, CEH, GIAC) is a plus.
  2. Recent experience in the following tech stack:
    1. AWS and its security tools: CloudTrail, GuardDuty, Control Tower, and Identity Center 
    2. Wiz
    3. DataDog SIEM
    4. Socket.dev (or other SCA tools like Trivy)
    5. Snowflake
    6. Kubernetes / container security 
  3. Experience with threat modeling cloud-native applications (NodeJS and Python) and data pipelines. 
  4. Experience with writing scripts or automation in any of the following languages: Bash, JavaScript, Python, or Golang.
  5. Experience with IAC related tooling, such as Terraform or Pulumi.
  6. Experience with deploying and managing Data Loss Prevention (DLP) tools in a regulated environment.
  7. Proven experience (4+ years) in a security engineering role, preferably in a fast-paced environment such as a technology company or HealthTech company.

APPLY HERE