Security Engineer
Job description
Security Engineer at Candid Health.
About the role
Candid Health is on a mission to streamline the revenue cycle for healthcare providers by automating the complex medical billing process, thereby lowering administrative overhead across the US healthcare landscape. As the organization enters a rapid growth phase, they are looking for a Senior Security Engineer to take ownership of protecting their cloud infrastructure and maturing their compliance posture. This position sits at the intersection of application security, cloud hardening, and regulatory adherence, requiring a practitioner who can build programmatic guardrails rather than simply enforcing policy. You will act as a force multiplier for the product engineering teams, embedding security into the development lifecycle from design review through deployment. The ultimate goal is to ensure that patient data and financial transactions remain protected while the platform scales to handle increasing volume.
Key facts
What you'll do
- Architect and implement security guardrails and paved roads within the CI/CD pipeline and cloud environment to enforce secure defaults across all microservices and infrastructure components.
- Collaborate closely with product engineering squads to perform threat modeling sessions and secure design reviews for upcoming features, identifying risk vectors early in the software development lifecycle.
- Own the end-to-end compliance program, driving readiness and managing external audit engagements for critical frameworks including HIPAA, SOC 2 Type II, SOC 1, PCI DSS, and HITRUST CSF certification.
- Design and execute continuous vulnerability management processes, encompassing scheduled scanning, triage of findings, coordination of remediation SLAs, and validation of fixes across container images, Kubernetes clusters, and serverless functions.
- Manage relationships with third-party security assessors and penetration testing firms, scoping engagements, reviewing deliverables, and tracking closure of identified critical and high-severity findings.
- Build and maintain internal security tooling and automation scripts using languages such as Python or Go to reduce manual toil in log analysis, asset inventory, and policy enforcement.
- Develop and refine incident response playbooks specific to data breach scenarios involving Protected Health Information (PHI), conducting regular tabletop exercises with cross-functional stakeholders.
- Harden the AWS cloud footprint by implementing least-privilege IAM policies, service control policies (SCPs), and continuous configuration monitoring via Infrastructure as Code (Terraform) and CSPM tooling.
- Establish and monitor security-relevant metrics and dashboards (e.g., mean time to remediate, coverage of security controls, phishing simulation results) to report posture to leadership and the board.
- Champion a security-first culture by delivering targeted training to developers on secure coding practices, OWASP Top 10 mitigation, and the specific handling requirements for regulated healthcare data.
Requirements
- A minimum of four years of professional experience in a dedicated security engineering role, with a proven track record of securing modern cloud-native architectures.
- Deep, practical expertise administering and evidencing compliance for HIPAA Security and Privacy Rules within a technology environment, including Business Associate Agreement (BAA) management.
- Demonstrated ability to write production-grade code for security automation, preferably in Python, Go, or TypeScript, moving beyond scripting into maintainable tooling.
- Strong proficiency in auditing complex network topologies, Linux/containerized systems, and IT infrastructure configurations against benchmarks such as CIS or NIST 800-53.
- Hands-on experience leading complex security projects from inception through delivery, such as a SOC 2 Type II attestation, a cloud migration hardening effort, or a zero-trust network implementation.
- Solid understanding of application security concepts, including SAST/DAST integration, dependency scanning (SCA), and secrets management patterns in distributed systems.
- Familiarity with container orchestration security, specifically securing Kubernetes control planes, runtime security (e.g., Falco, Sysdig), and admission controller policies (OPA/Gatekeeper).
- Excellent written and verbal communication skills, capable of translating technical risk into business impact for non-technical audiences including legal, sales, and executive leadership.
Nice to have
- Prior experience working within a high-growth B2B SaaS startup or health-tech company subject to stringent regulatory oversight.
- Active certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or CCSK.
- Background in managing a bug bounty program or coordinating a vulnerability disclosure program (VDP) on platforms like HackerOne or Bugcrowd.
- Experience with data loss prevention (DLP) strategies and implementation for unstructured data stores containing PHI or PII.
- Knowledge of privacy regulations beyond HIPAA, such as GDPR, CCPA/CPRA, or state-specific consumer health data laws (e.g., Washington My Health My Data Act).
- Familiarity with the Candid Health tech stack specifics: Python/Django, React/TypeScript, PostgreSQL, Redis, Kubernetes (EKS), and Terraform.
Skills & tools
- HIPAA Security & Privacy Rule implementation
- SOC 2 (Type II), SOC 1, PCI DSS v4.0, HITRUST CSF (r2/i1)
- Security automation development (Python, Go, TypeScript)
- Threat modeling methodologies (STRIDE, PASTA, Attack Trees)
- Vulnerability management lifecycle & risk-based prioritization
- Cloud security posture management (AWS, CSPM tools like Wiz/Orca/Prowler)
- Kubernetes security (RBAC, Network Policies, Admission Control, Runtime)
- Infrastructure as Code security (Terraform, Checkov, tfsec)
- SIEM/Log analysis (Datadog, Splunk, or ELK stack)
- Identity and Access Management (Okta, AWS IAM, SCIM provisioning)
- Penetration testing coordination & red team collaboration
- Incident response & digital forensics in cloud environments
Practical notes
The total compensation package includes a significant equity grant, reflecting the company's current funding stage and growth trajectory; the base salary range of $180,000 to $258,000 is calibrated against market data and final offer determination weighs qualifications, interview performance, and internal equity bands. This role operates on a hybrid schedule requiring regular presence at the New York City headquarters, typically multiple days per week, to facilitate deep collaboration with engineering and compliance stakeholders. Visa sponsorship details are not explicitly stated in the source listing; candidates requiring work authorization should confirm eligibility directly with the recruiting team during initial screening. The engineering team values high autonomy and a "build vs buy" pragmatism, expecting this hire to write code and deploy tooling rather than solely managing vendors.