Lead Security Engineer

Security EngineerSecurity EngineerFull TimeRemote

Location

United States

Posted

40 days ago

Salary

$180K - $240K / year

Type ScriptNode.jsPythonJavaC++Burp SuiteOWASP ZAPFiddlerContainer SecurityDockerKubernetesXSSCSRFSqliSession ManagementGit Hub ActionsCi/cdAWSSASTDASTSCAAuth0OktaHITRUSTSOC 2ISO 27001NIST 800 53HIPAA

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

Charlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will be the subject matter expert on application and cloud infrastructure security, guiding the business in building secure, scalable and HIPAA-compliant software solutions.

Responsibilities

  • Lead application security program including SAST/DAST integration, security code reviews and developer training.
  • Perform threat modeling and architecture reviews to identify potential security risks early in design phases.
  • Integrate security tooling and automate security processes into CI/CD and DevOps pipelines.
  • Manage application and cloud security vulnerability management program including configuration of scanning tools, validation and prioritization of findings, and remediation of risks.
  • Review and document new third-party integrations with Charlie Health applications and cloud infrastructure.
  • Perform internal penetration testing and manage third-party penetration tests.
  • Work with teams to build and enforce secure SDLC controls in a fast-paced agile environment.
  • Develop cloud security configuration baselines and monitor for gaps.
  • Document business continuity and disaster recovery procedures for cloud infrastructure environment.
  • Participate in security incident response activities related to Charlie Health applications and infrastructure systems.
  • Help define metrics and KPIs that demonstrate the effectiveness of the application and cloud security programs.

Qualifications

  • 10+ years of experience in application security, secure software development, cloud security or related roles.
  • Bachelor’s degree in Computer Science or related field, or equivalent experience.
  • Proficiency in secure coding practices and languages such as Typescript, Node, Python, Java, C++ or similar.
  • Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler).
  • Knowledge of container security concepts, including container image scanning, secure image pipelines, and common misconfigurations in containerized environments.
  • Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc.
  • Experience implementing security in CI/CD pipelines such as GitHub Action and agile development workflows.
  • Familiarity with AWS cloud platform and AWS security best practices.
  • Familiarity with management and deployment of SAST, DAST, and SCA tooling.
  • Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications.
  • Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences.

Preferred Qualifications

  • Experience with HIPAA and securing applications in healthcare, or other regulated, environments.
  • OSCP, OSWE, AWS Security or other relevant security certifications.
  • Experience securing custom software collaboratively on a team.
  • Experience with Wiz or similar CNAPP tools.
  • Knowledge of AI/ML security best practices.
  • Familiarity with Infrastructure as Code (IaC).
  • Knowledge of security standards such as SOC2, ISO 27001/2, NIST 800-53, HITRUST, or HIPAA Security Rule.

Benefits

  • Comprehensive benefits to all full-time, exempt employees.
  • Total target base compensation for this role will be between $180,000 and $240,000 per year.
  • Pay will be determined on an individualized basis and will be impacted by location, experience, expertise, internal pay equity, and other relevant business considerations.
  • Cash compensation is only part of the total compensation package, which may include stock options and other Charlie Health-sponsored benefits.

Job Requirements

  • 10+ years of experience in application security, secure software development, cloud security or related roles.
  • Bachelor’s degree in Computer Science or related field, or equivalent experience.
  • Proficiency in secure coding practices and languages such as Typescript, Node, Python, Java, C++ or similar.
  • Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler).
  • Knowledge of container security concepts, including container image scanning, secure image pipelines, and common misconfigurations in containerized environments.
  • Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc.
  • Experience implementing security in CI/CD pipelines such as GitHub Action and agile development workflows.
  • Familiarity with AWS cloud platform and AWS security best practices.
  • Familiarity with management and deployment of SAST, DAST, and SCA tooling.
  • Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications.
  • Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences.
  • Preferred Qualifications
  • Experience with HIPAA and securing applications in healthcare, or other regulated, environments.
  • OSCP, OSWE, AWS Security or other relevant security certifications.
  • Experience securing custom software collaboratively on a team.
  • Experience with Wiz or similar CNAPP tools.
  • Knowledge of AI/ML security best practices.
  • Familiarity with Infrastructure as Code (IaC).
  • Knowledge of security standards such as SOC2, ISO 27001/2, NIST 800-53, HITRUST, or HIPAA Security Rule.

Benefits

  • Comprehensive benefits to all full-time, exempt employees.
  • Total target base compensation for this role will be between $180,000 and $240,000 per year.
  • Pay will be determined on an individualized basis and will be impacted by location, experience, expertise, internal pay equity, and other relevant business considerations.
  • Cash compensation is only part of the total compensation package, which may include stock options and other Charlie Health-sponsored benefits.

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Specialist

ProArch

Consulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.

Security Engineer40 days ago
Full TimeRemoteTeam 201-500H1B Sponsor

Security Specialist maintaining a comprehensive security program for ProArch customers.

AWSAzureCloudCyber SecurityGoogle Cloud PlatformIoTPythonSplunk
New York
Security Engineer41 days ago
Full TimeRemoteTeam 5,001-10,000Since 1985H1B Sponsor

Staff Product Security Engineer providing cyber security expertise for PTC's SaaS applications

AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaJavaScriptPythonTypeScriptGo
United States
$105K - $155K / year

Lead Security Engineer

Charlie Health

Personalized mental health treatment for teens, young adults & families in crisis.

Security Engineer41 days ago
Full TimeRemoteTeam 501-1,000H1B No Sponsor

Charlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will...

TypeScriptNode.jsPythonJavaC++Burp SuiteOWASP ZAPFiddlerDockerAWSGitHub ActionsAuth0OktaCI/CDSASTDASTSCAXSSCSRFSQLiSession ManagementPenetration TestingThreat ModelingVulnerability Management
United States
$180K - $240K / year
Full TimeRemoteTeam 10,001+H1B Sponsor

Senior Offensive Security Engineer leading red team operations at P&G

AWSAzureCloudCyber SecurityGoogle Cloud PlatformIoTPython
Ohio
$110K - $165K / year