Security Engineer

Candid Health

New York (NY)

On-site

USD 180,000 - 258,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A healthcare technology firm in New York seeks a Senior Security Engineer to enhance system security and ensure compliance with industry standards like HIPAA, SOC2, and more. The role involves building security safeguards, conducting audits, and collaborating with engineering teams to address vulnerabilities. Ideal candidates should have over 4 years of security experience, strong compliance knowledge, and the ability to automate security tasks. Join this innovative firm to contribute to essential healthcare work, with a competitive salary range of $180,000 - $258,000.

Qualifications

  • 4+ years of hands-on experience in security projects.
  • Strong compliance knowledge related to security frameworks.
  • Ability to audit systems, networks, and IT setups.

Responsibilities

  • Build security protections into systems for a secure posture.
  • Participate in design reviews and identify security flaws.
  • Oversee HIPAA, SOC2, SOC1, PCI, and HITRUST compliance.
  • Audit platforms for vulnerabilities and address them promptly.
  • Coordinate with vendors for penetration testing and security services.

Skills

Experience in security domain
Knowledge of HIPAA
Coding ability for automation
Adaptability and flexibility

Job description

What we do

We’re fixing one of the most broken and costly pieces of the US healthcare system: medical billing.

Today, healthcare providers spend over $250B each year on administrative overhead just to get paid by insurance. Medical billing is expensive because it’s nuanced and hard - maybe ~100x harder than credit card payment processing - and because it’s traditionally done by armies of humans who track and manage complex rules and processes specific to individual insurance companies with little or no supporting software. We’re rethinking medical billing from the ground up, building software backed by best-in-class data science (and, soon, a dash of machine learning) to automate much of this complexity so healthcare providers can get paid dramatically more easily and inexpensively.

We were in the Y Combinator W20 batch and have since been well funded by a world-class group of funds (8VC, First Round Capital, BoxGroup) + angel investors. We're now helping our customers treat opioid addiction, provide holistic care for women, lose weight, increase access to mental health care, and much more. This is such important and gratifying work; we can't wait for you to join our team and help support some of the most important innovation happening in healthcare today!

Curious to learn more about our story? Check out this blog post written by our founders.

The Role

We're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our platforms are resilient against all threats while meeting compliance requirements. We value a hands‑on approach and seek someone who is conversant with the nitty‑gritty of security frameworks, while being deeply engaged in strategic and operational security endeavors.

What You’ll Do
  • Build Security Guardrails: Build security protections into our systems to ensure a secure by default posture.

  • Collaborate with Engineering Teams: Participate in design reviews and threat modelling sessions to identify potential security flaws early in the development process, and validate the security of new features and services during rollout ensuring security remains at the forefront of all initiatives.

  • Implement & Navigate Compliance Rituals: Understand, oversee, and drive the rituals associated with HIPAA, SOC2, SOC1, PCI and HITRUST to ensure that we remain compliant and informed.

  • Vulnerability Management: Regularly audit our platforms and tech stack for vulnerabilities, ensuring that vulnerabilities are identified and addressed in a timely manner.

  • Manage Third‑party Relationships: Coordinate with vendors for penetration testing and other security services, ensuring that our platforms undergo regular scrutiny and remain fortified, review vendor security prior to integration.

Who You Are
  • You have 4+ years of experience in the security domain, with a proven track record of hands‑on involvement in complex projects.

  • Your expertise isn't just theoretical. You know how to "talk the talk", especially when it comes to the rituals and routines of security compliance.

  • With strong knowledge of HIPAA, you're no stranger to the delicate information we handle.

  • You are adaptable and flexible, always ready to engage with security challenges at both enterprise and client levels.

  • You write code to automate security, you possess the ability to read, understand, and audit systems, networks, and IT setups to ensure airtight security.

Our values

We spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):

  • We put our customers first

  • We take care of each other and ourselves

  • We anchor on outcomes and work relentlessly and creatively to achieve them

  • We collectively prioritize building a diverse and inclusive workspace

  • We believe humility is our greatest strength

  • We are candid, kind, and committed

  • We strive to be the most prepared person in the room

  • We are truth seekers

Pay Transparency

The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job‑related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer (Senior)
Security Engineer (Senior)

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security Engineer
Security Engineer

Candid Health • San Francisco (CA)

Hybrid
USD 180,000 - 258,000
Product Security Engineer
Product Security Engineer

Candid Group • New York (NY)

On-site
USD 180,000 - 258,000
Senior Security Engineer
Senior Security Engineer

Candid Health • San Francisco (CA)

On-site
USD 120,000 - 150,000
Principal Security Engineer
Principal Security Engineer

Candid Health • San Francisco (CA)

On-site
USD 240,000 - 310,000
Equity options
Health benefits
Flexible working environment
Principal Security Engineer
Principal Security Engineer

Candid Group • New York (NY)

On-site
USD 240,000 - 310,000
Software Engineer
Software Engineer

Candid Health • California (MO)

On-site
USD 135,000 - 200,000
Engineering Leader - Infrastructure & Platform
Engineering Leader - Infrastructure & Platform

Candid Health • San Francisco (CA)

On-site
USD 225,000 - 322,000
Software Engineer (Senior)
Software Engineer (Senior)

Candid Health • New York (NY), Menlo Park (CA), Denver (CO), San Francisco (CA)

On-site
USD 195,000 - 250,000
Engineering Leader - Infrastructure & Platform
Engineering Leader - Infrastructure & Platform

candidhealth • San Francisco (CA)

On-site
USD 225,000 - 322,000