Senior Security Engineer II (Engineering & Tooling)
Aledade
Job Summary
Aledade is seeking a Senior Security Engineer II to design, implement, and maintain security systems and tooling across its infrastructure. The role requires a strong background in security engineering, in-depth knowledge of security tools, and a proactive approach to mitigating cybersecurity risks. Responsibilities include infrastructure security, architecture reviews, threat modeling, and implementing security tools. The engineer will leverage automation, manage advanced security tools like SIEM and EDR, integrate security tooling in cloud environments (AWS, Azure, GCP), and collaborate with cloud engineering teams. This position also involves leading the evaluation of new security technologies, developing secure configurations, automating security processes using scripting languages, and ensuring the effectiveness of vulnerability management programs. The role also includes providing technical leadership and mentoring junior members of the security engineering team.
Must Have
- 7+ years of experience in security engineering
- Strong understanding of Threat Modeling Principles
- Experience with SIEM, EDR, and vulnerability management tools
- Proficiency in securing cloud environments (AWS, Azure, GCP)
- Experience with automation tools and scripting (Python, PowerShell, Bash)
- Familiarity with DevSecOps and container security
- Bachelor's degree in Computer Science or related field (or equivalent experience)
Good to Have
- Experience with Datadog
- Experience in monitoring security tools and leading forensic investigations
- Experience with Zero Trust models and microsegmentation
- Knowledge of regulatory frameworks (PCI DSS, GDPR, HIPAA)
- Mentored junior engineers and provided technical leadership
- Strong analytical and problem-solving skills
- Previous experience in healthcare, finance, or government sectors
- Certifications (CISSP, GSEC, AWS Certified Security Specialty, CCNP, CEH)
Perks & Benefits
- Flexible work schedules
- Remote work available
- Health, dental, and vision insurance (80% paid)
- 21 days of PTO
- Two paid volunteer days
- 11 paid holidays
- 12 weeks paid parental leave
- Six weeks paid sabbatical after six years
- Educational Assistant Program
- Clinical Employee Reimbursement Program
- 401(k) with up to 4% match
- Stock options
Job Description
Primary Duties:
- Primary focus will be on infrastructure security through architecture reviews, threat modeling for new and existing services and security tool implementations, while leveraging automation to scale security solutions.
- Design, deploy, and manage advanced security tools, including SIEM, EDR, DLP, vulnerability management, and firewalls.
- Engineer solutions to integrate security tooling across cloud environments, ensuring seamless protection and visibility. Collaborate with cloud engineering teams to implement and secure cloud-native solutions (e.g., IAM, VPC, security groups, cloud firewalls), implement security controls for cloud infrastructure and containerized environments.
- Lead the evaluation, implementation, and configuration of new security technologies to address evolving threats and stay updated on emerging technologies, trends, and best practices in security engineering and tooling.
- Develop and maintain secure configurations for operating systems, applications, and networking equipment and Automate security processes using scripting languages (Python, PowerShell) and tools like Terraform or Ansible.
- Conduct security assessments and ensure vulnerability management programs are effective, addressing gaps proactively.
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 7+ years of experience in security engineering, including designing and managing security tools.
- Strong understanding of Threat Modeling Principles
- Experience with Security Incident Response & Risk Management
- Strong hands-on expertise with SIEM (e.g., Splunk or Sumo logic), EDR (e.g., CrowdStrike, SentinelOne), and vulnerability management tools (e.g., Tenable, Qualys), Wiz, Snyk etc.
- Proficiency in securing cloud environments (AWS, Azure, or GCP), including experience with IAM, VPCs, security groups, EKS/ECR and cloud-native security solutions (e.g., AWS Security Hub, Azure Sentinel).
- Experience with automation tools IAC and CI/CD: Terraform, Helm, Chef, Ansible, Buildkite, Jenkins, ArgoCD and scripting (Python, PowerShell, or Bash) for integrating and managing security solutions.
- Familiarity with DevSecOps practices, container security (e.g., Kubernetes, Docker), and CI/CD pipeline security.
- Proven track record in incident response, threat hunting, and forensic investigations.
- Certifications such as CISSP, GSEC, AWS Certified Security Specialty, or equivalent.
Preferred Knowledge, Skills, and/or Abilities:
- Strongly Preferred:
- Experience with Datadog for metrics and log analysis.
- Experience in monitoring security tools and leading forensic investigations and helping in incident response efforts.
- Experience with Security incident response & Risk Management.
- Stay updated on emerging technologies, trends, and best practices in security engineering and tooling.
- Experience with Zero Trust models, microsegmentation, and cloud-native security solutions (e.g., AWS Security Hub, Azure Sentinel).
- Knowledge of regulatory frameworks (e.g., PCI DSS, GDPR, HIPAA) and how to engineer tools to support compliance.
- Has mentored junior engineers and provided technical leadership for security-focused initiatives.
- Strong analytical and problem-solving skills, with excellent communication and documentation abilities.
- Previous experience in healthcare, finance, or government sectors, particularly in managing network security within compliance frameworks like HIPAA, PCI-DSS, or SOX.
- Preferred:
- Certifications such as CISSP, CCNP, CEH, or similar are strongly preferred.