What you'll do :
- Secure AI products and internal tools by assessing security and privacy risks
- Conduct secure design reviews and threat modeling to instill security best practices
- Work with cross-functional teams to implement and maintain identity and access management (IAM) policies and controls within our Service-Oriented Architecture
- Design and operate a robust Public Key Infrastructure (PKI) to ensure secure authentication and encryption across the organization's systems
- Develop secure by default infrastructure using technologies such as Terraform and Kubernetes
- Support the vulnerability management program and prioritize vulnerability fixes
- Perform compliance tasks related to security controls, audits, and reporting
- Oversee the weekly organization wide security newsletter
- Be agile to work across multiple security domains and tackle projects that are critical to maintaining risk to the organization
To be successful in this role, you'll need :
5+ years as a Security EngineerProven leadership in risk assessment and threat modelingExcellent communication for technical concepts to all stakeholdersSolid grasp of Identity Access Management lifecycle (Okta preferred)In-depth knowledge : PKI architecture, CAs, certificate lifecycle toolsExperience securing cloud (AWS, GCP) and KubernetesUnderstanding common security flaws (OWASP Top 10, CIS Benchmarks)Familiarity with HIPAA, HITRUST, related healthcare data security rulesPay Transparency Statement
This is a hybrid position based out of one of our offices : San Francisco, CA, Plano, TX, or Lehi, UT. Hybrid employees are expected to be in the office two days per week. #LI-hybrid
The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the salary, you will be eligible for stock options and benefits like health insurance, 401k, and paid time off.