Security Engineer, GRC

Candid Health

Denver (CO)

On-site

USD 180,000 - 258,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Candid Health is seeking a Security GRC Lead to build our first in-house GRC program from the ground up. You will engineer automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines.

You will transform audits into a continuous compliance telemetry system, ensuring the platform remains secure, resilient, and audit-ready while partnering with Legal, Finance, and DevOps teams to map

Qualifications

  • 3+ years in a technical security role such as security engineering or GRC.
  • Proficiency in Python, TypeScript, and SQL; strong API, log parsing, and database querying skills.
  • Hands-on experience with cloud platforms (GCP preferred) and infrastructure-as-code tools like Terraform.

Responsibilities

  • Build automated compliance evidence pipelines and CI/CD-integrated controls.
  • Develop infrastructure-as-code and policy enforcement to automate security baselines.
  • Maintain live compliance dashboards and real-time policy violation alerts.
  • Collaborate with Legal on Medicare/Medicaid compliance.
  • Lead audits and automate vendor risk management workflows.
  • Integrate compliance controls into CI/CD without slowing delivery.

Skills

3+ years in security role
Python
TypeScript
SQL
APIs
GCP
Terraform
CI/CD
Docker
Kubernetes

Tools

Terraform

Job description

About Candid Health
In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care.
About Candid Health
In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care.
That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.
Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish-submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.
Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups-processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.
Role Overview
We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.
You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.
Key Responsibilities
  • Compliance Automation & Engineering
  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Partnering with Legal on Medicare and Medicaid compliance
  • Partnering closely with legal and finance teams on future due diligence and compliance projects
  • Framework Mapping & Control Architecture
  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.
  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work.
  • Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.
  • Risk Management & Audits
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.
Required Qualifications
  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
  • Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).
Preferred Qualifications
  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security - Specialty, or CCSP.
  • Experience with Policy-as-Code engines
  • HITRUST experience
  • Background in software development, DevOps, or platform engineering.
  • Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).
Our values
  • We put our customers first
  • We take care of each other and ourselves
  • We anchor on outcomes and work relentlessly and creatively to achieve them
  • We collectively prioritize building a diverse and inclusive workspace
  • We believe humility is our greatest strength
  • We are candid, kind, and committed
  • We strive to be the most prepared person in the room
  • We are truth seekers
Pay Transparency
The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health's funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, GRC
Security Engineer, GRC

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • New York (NY), Northern (KY)

Hybrid
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security Engineer
Security Engineer

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security Engineer
Security Engineer

Candid Health • San Francisco (CA)

Hybrid
USD 180,000 - 258,000
Principal Security Engineer
Principal Security Engineer

Candid Health • San Francisco (CA)

On-site
USD 240,000 - 310,000
Equity options
Health benefits
Flexible working environment
Principal Security Engineer
Principal Security Engineer

Candid Group • New York (NY)

On-site
USD 240,000 - 310,000
Candid Health is hiring a Software Engineer
Candid Health is hiring a Software Engineer

TechTwitter.io • New York (NY), Northern (KY)

Hybrid
USD 135,000 - 200,000
Product Security Engineer
Product Security Engineer

Candid Group • New York (NY)

On-site
USD 180,000 - 258,000
Revenue Cycle Customer Success
Revenue Cycle Customer Success

Candid Health • Denver (CO)

On-site
USD 95,000 - 145,000