Responsibilities
- Evaluate security flaws in web and mobile platforms, assess associated risks, and coordinate fixes with engineering teams.
- Investigate and document emerging threats, vulnerabilities, and countermeasures pertinent to digital health technologies.
- Work closely with engineering and product teams to embed security practices throughout the software development lifecycle, supporting agile methodologies.
- Design and promote efficient solutions for managing advanced application and product security issues.
- Drive the implementation of security standards across the organization, shaping technical and architectural choices.
- Regularly audit and evaluate the security configuration of applications and cloud environments.
- Support development teams in adopting secure coding methods by offering guidance and practical feedback.
- Operate and refine security tools including SAST, DAST, Hashicorp Vault, and other leading application security platforms.
- Take part in joint threat modeling sessions for new features and services to proactively detect and reduce risks.
- Perform security-focused code reviews on applications built with current frameworks and technologies.
- Help plan and carry out focused penetration tests on new functionality, identifying and documenting flaws prior to release.
- Collaborate on IT security projects, working with infrastructure teams to assess controls for device management, endpoint security, access policies, and system hygiene.
- Support cloud security initiatives by working with DevOps and infrastructure teams to evaluate and enhance cloud architecture, policies, and native security controls.
Benefits
- Medical, dental, vision, disability, and life insurance coverage
- High Deductible Health Plan with optional Health Savings Account (HSA)
- Flexible Spending Account (FSA) availability
- Access to mental health coaching and therapy via the company platform
- Flexible Time Off policy
- Company-wide pause days for rest and recovery
- Parental Leave program
- Family Forming Benefit through Carrot
- Family Assistance Benefit via UrbanSitter
- Annual Professional Development stipend
- 401k retirement savings plan
- Financial Planning support through Origin
- Annual Wellness stipend for well-being related expenses
- One-time New Hire stipend for remote work setup
- ModSquad Community: virtual events, ERGs, holiday activities, and team engagement
- Monthly cell phone expense reimbursement
Work Arrangement
Remote (Country)
Other
- This role cannot be performed in Hawaii.
- Candidates without direct security experience but with a background in software development or AWS and a strong interest in security are encouraged to apply.