What are the responsibilities and job description for the Sr. Security Engineer position at Castlight Health, INC?
Job Description Summary We’re apree health, a Mosaic Health company, whose vision is to transform US healthcare. We work with health plans and enterprise companies on everything from healthcare navigation, healthcare engagement, private health care clinics, to centralized wrap services. As a Senior Security Engineer at apree, you will design, implement, and maintain security architecture across apree's platforms. This role ensures the confidentiality, integrity, and availability of healthcare data by developing automation strategies, delivering Tier 4 support, and advancing detection engineering capabilities. You'll partner with cross-functional technology and compliance teams to ensure apree's infrastructure meets industry best practices, regulatory requirements, and evolving security threats. How will you make an impact & Requirements Key Responsibilities: Lead the design and implementation of secure architecture to support apree's evolving tech stack. Build out and refine security automations related to vulnerability scanning, configuration management, IT integrations, detection engineering and automated incident response. Provide Tier 4 (expert-level) support for complex cloud security incidents, escalations, and system issues. Collaborate with engineering, IT, compliance, and business stakeholders to ensure security standards and policies are implemented consistently. Stay current with emerging security threats, cloud technologies, and regulatory frameworks relevant to healthcare. Qualifications: Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred) or equivalent work experience. 5 years of experience in security engineering in a cloud environment, preferably with expertise in GCP. Demonstrated experience rationalizing, implementing, operating and maintaining security controls in cloud-centric environments. Fluency in Python, Terraform and git. Demonstrated experience in serverless computing. Deep understanding of cloud architecture, automation tooling, and detection tools (e.g., SIEM, EDR). Experience working in an environment that processes PHI and with applicable standards, such as: NIST CSF, ISO/IEC 27701, ISO 27001, HIPAA, HITRUST, SOC 2, FedRAMP. Advanced problem-solving skills and ability to independently lead cross-functional technical projects. Compensation: $108,466K - $135,582K annual salary & bonus eligible Beware of fraudulent job postings: While Mosaic Health job advertisements may be found on many sites, our current openings page and its associated Workday account are the only places we accept applications for open roles. If you suspect a job post is fraudulent, please let us know at recruiting@apree.health. Mosaic Health is a national care delivery platform focused on expanding access to comprehensive primary care for consumers with coverage across Commercial, Individual Exchange, Medicare, and Medicaid health plans. Learn More about Mosaic Health Learn more about apree health Learn more about Carelon Health Learn more about Elevance Health
Salary : $108,466 - $135,582