Enable job alerts via email!

Security Engineer

SimplePractice

Santa Monica (CA)

On-site

USD 120,000 - 160,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in healthcare technology seeks a Security Engineer to enhance the security of their AWS-hosted SaaS platform. This role involves developing secure solutions, assessing vulnerabilities, and ensuring compliance with industry standards. Join a dynamic team dedicated to safeguarding sensitive health data while fostering innovation in the wellness industry.

Benefits

Medical, dental, vision insurance
401(k) plan with company match
Flexible Time Off and wellbeing days
Mental health resources
Paid parental leave
Tuition reimbursement

Qualifications

  • 5+ years of experience in cybersecurity roles, focusing on application and cloud security.
  • Proficiency with security tools and frameworks to assess vulnerabilities.
  • Strong communication skills to convey technical concepts to various stakeholders.

Responsibilities

  • Collaborate with teams to enhance AWS security posture.
  • Conduct security assessments and integrate secure coding practices.
  • Monitor security alerts and manage incidents effectively.

Skills

Cybersecurity
Scripting Languages (Python, Go, JavaScript)
Application Security
Cloud Security
Incident Response
Risk Management

Education

Bachelor’s degree in Computer Science, Information Security, or related field

Tools

Burp Suite
OWASP ZAP
Metasploit
Nmap
Terraform
CloudFormation

Job description

Join to apply for the Security Engineer role at SimplePractice

Join to apply for the Security Engineer role at SimplePractice

About Us

At SimplePractice, our team is dedicated to improving the health and wellness industry by building a suite of innovative solutions for practitioners and their clients. Our product supports practitioners on their clinical journey to becoming licensed, helps them manage their business and practice once they’re up and running, and enables new clients to discover and interact with practitioners. Taking a practitioner-first approach in everything we do makes it possible for health and wellness practitioners to devote more time to their clients while they use SimplePractice to start, grow, and maintain a successful private practice.

About Us

At SimplePractice, our team is dedicated to improving the health and wellness industry by building a suite of innovative solutions for practitioners and their clients. Our product supports practitioners on their clinical journey to becoming licensed, helps them manage their business and practice once they’re up and running, and enables new clients to discover and interact with practitioners. Taking a practitioner-first approach in everything we do makes it possible for health and wellness practitioners to devote more time to their clients while they use SimplePractice to start, grow, and maintain a successful private practice.

The Role

SimplePractice is seeking a versatile and experienced Security Engineer to join our growing security team. This role is pivotal in safeguarding our AWS-hosted healthcare SaaS platform, ensuring the confidentiality, integrity, and availability of sensitive health data. The ideal candidate will possess a strong background in cybersecurity, secure software development, and cloud-native security practices, contributing to our mission of delivering secure and reliable healthcare solutions.

Responsibilities

  • Security Architecture & Collaboration
    • Collaborate with the cloud security engineer and infrastructure team to assess and enhance the security posture of our AWS environment, focusing on IAM policies, network configurations, and service deployments
    • Contribute to the implementation and management of Infrastructure as Code (IaC) security measures to ensure consistent and secure infrastructure provisioning
    • Assist in monitoring and responding to security events, collaborating with DevOps and IT teams to address potential threats promptly.
  • Application Security & Secure SDLC
    • Conduct comprehensive security assessments, including static and dynamic code analyses, to identify and remediate vulnerabilities in our applications
    • Collaborate with development teams to integrate security best practices throughout the software development lifecycle (SDLC), emphasizing secure coding standards and threat modeling
    • Develop and maintain security tools and automation scripts to enhance our CI/CD pipelines, ensuring continuous security validation.
  • Incident Response & Threat Management
    • Monitor security alerts and respond to incidents, conducting root cause analyses and implementing corrective actions
    • Participate in the development and refinement of incident response plans and playbooks
    • Stay informed about emerging threats and vulnerabilities, recommending proactive measures to mitigate risks.
  • Compliance & Risk Management
    • Ensure adherence to healthcare industry regulations and standards, such as HIPAA, HITRUST, and PCI, by implementing appropriate security controls and conducting regular audits
  • Security Monitoring & Reporting
    • Generate regular reports on security metrics, incidents, and compliance status for management review Stay informed about emerging threats and vulnerabilities, recommending proactive measures to mitigate risks.
  • Third-Party Risk Management
    • Assess and monitor third-party vendors to ensure they meet security and compliance requirements
    • Work closely with procurement and legal teams to incorporate security considerations into vendor contracts
    • Maintain an up-to-date inventory of third-party vendors and their associated risk profiles
    • Utilize security ratings services to continuously evaluate the security posture of third-party vendors
    • Participate in risk assessments and contribute to the development of policies and procedures to manage and mitigate security risks.
Desired Skills & Experience

  • Bachelor’s degree in Computer Science, Information Security, or a related field
  • Minimum of 5 years of experience in cybersecurity roles, with a focus on application security, infrastructure security, or cloud security within cloud-based environments
  • Proficiency in scripting and programming languages such as Python, Go, or JavaScript
  • Experience with security tools and frameworks, including but not limited to Burp Suite, OWASP ZAP, Metasploit, and Nmap
  • Strong understanding of AWS services and security features, as well as Infrastructure as Code (IaC) tools like Terraform or CloudFormation
  • Familiarity with CI/CD processes and integrating security testing into development pipelines
  • Excellent analytical and problem-solving abilities.
  • Strong communication skills, capable of articulating complex security concepts to technical and non-technical stakeholders
  • Proven ability to work collaboratively in cross-functional teams and adapt to a fast-paced, agile environment

Bonus Points

  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or AWS Certified Security – Specialty are highly desirable

Base Compensation Range

$120,000 - $160,000 annually

Base salary is one component of total compensation. Employees may also be eligible for an annual bonus or commission. Some roles may also be eligible for overtime pay.

The above represents the expected base compensation range for this job requisition. Ultimately, in determining your pay, we’ll consider many factors including, but not limited to, skills, experience, qualifications, geographic location, and other job-related factors.

Benefits

We offer a competitive benefits program including:

  • Medical, dental, vision, life & disability insurance
  • 401(k) plan with company match
  • Flexible Time Off (FTO), wellbeing days, paid holidays, and summer Fridays
  • Mental health resources
  • Paid parental leave & Backup Care
  • Tuition reimbursement
  • Employee Resource Groups (ERGs)

California Job Applicant Privacy Notice

Thank you for your interest in opportunities at SimplePractice LLC (“SimplePractice” or “us” or “we” or “our”). Please note that when you submit your resume or application materials to us for employment purposes, you are subject to the SimplePractice California Job Applicant Privacy Notice.

For more information about our privacy practices, please contact us at privacy@simplepractice.com.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Software Development

Referrals increase your chances of interviewing at SimplePractice by 2x

Get notified about new Security Engineer jobs in Santa Monica, CA.

Santa Monica, CA $80,000.00-$100,000.00 3 days ago

Security Solutions Engineer (Pre-Sales) - Remote
Systems and Network Engineer 2 (contract)

Hawthorne, CA $80,000.00-$115,000.00 2 weeks ago

Security Engineer - Detection & Response
Cybersecurity Engineer/Senior Cybersecurity Engineer
ML Software Engineer (L4/L5) - Media Algorithms
Military Veterans and Military Spouses Encouraged to Apply - Software Development Engineer, Ring Subscriptions, Ring

Hawthorne, CA $129,300.00-$223,600.00 1 week ago

Los Angeles Metropolitan Area 4 weeks ago

Military Veterans and Military Spouses Encouraged to Apply - Software Development Engineer, Ring Subscriptions, Ring

Santa Monica, CA $129,300.00-$223,600.00 1 week ago

Cybersecurity Analyst & IT Administrator

Hawthorne, CA $130,000.00-$150,000.00 2 days ago

Rosemead, CA $140,400.00-$210,500.00 1 week ago

System & Network Administrator Engineer (Associate or Mid-Level)
Info Security Engineer I / IS - Information Security / Full-time / Days

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Information Security Engineer II / IS - Information Security

Children’s Hospital Los Angeles

Anaheim

Remote

USD 99,000 - 179,000

Today
Be an early applicant

Information Security Engineer II / IS - Information Security

Children’s Hospital Los Angeles

Long Beach

Remote

USD 99,000 - 179,000

5 days ago
Be an early applicant

Senior Microsoft Security Engineer (remote)

Converge Technology

Remote

USD 120,000 - 160,000

Yesterday
Be an early applicant

[Hiring] Senior Application Security Engineer @Practical DevSecOps

Practical DevSecOps

Remote

USD 100,000 - 140,000

Today
Be an early applicant

Wireless Security Engineer II, SPEAR Wireless Security

Amazon

California

Remote

USD 136,000 - 213,000

Today
Be an early applicant

Wireless Security Engineer II, SPEAR Wireless Security

Amazon

San Diego

Remote

USD 136,000 - 213,000

Yesterday
Be an early applicant

Wireless Security Engineer II, SPEAR Wireless Security

Amazon

San Diego

Remote

USD 136,000 - 213,000

Yesterday
Be an early applicant

Senior Information Security Engineer

Mayo Foundation for Medical Education and Research

Rochester

Remote

USD 131,000 - 191,000

Today
Be an early applicant

Senior Azure Cloud Security Engineer (remote)

Converge Technology

Remote

USD 100,000 - 150,000

Yesterday
Be an early applicant