Sr. Security Analyst – Cloud Security & Application Security

2 Months ago • 5 Years + • Cyber Security

Job Summary

Job Description

Blink Health seeks a Sr. Security Analyst to design and implement a Threat and Vulnerability Management program for AWS cloud and applications. Responsibilities include threat modeling, security architecture reviews, managing security tools (SAST, SCA, DAST, API security, data security, SIEM), conducting penetration tests, responding to security incidents, monitoring identity security, and preparing status reports. The ideal candidate possesses 5+ years of experience in information security, AWS cloud security, OWASP Top 10, API security, and data security. Experience with various security tools and compliance frameworks (HIPAA, PCI) is essential. The role also involves developing security content and assisting with audits and assessments.
Must have:
  • 5+ years InfoSec experience
  • AWS Cloud Security expertise
  • OWASP Top 10, API & Data Security knowledge
  • SAST, SCA, DAST experience
  • SIEM, incident response skills
Good to have:
  • CISSP or equivalent
  • AWS Security certification
  • Experience with WAF, IAM, DLP
  • Familiarity with GitHub, Kubernetes
  • HIPAA, PCI compliance knowledge

Job Details

Company Overview:

Blink Health is the fastest growing healthcare technology company that builds products to make prescriptions accessible and affordable to everybody.  Our two primary products – BlinkRx and Quick Save – remove traditional roadblocks within the current prescription supply chain, resulting in better access to critical medications and improved health outcomes for patients. 

BlinkRx is the world’s first pharma-to-patient cloud that offers a digital concierge service for patients who are prescribed branded medications. Patients benefit from transparent low prices, free home delivery, and world-class support on this first-of-its-kind centralized platform. With BlinkRx, never again will a patient show up at the pharmacy only to discover that they can’t afford their medication, their doctor needs to fill out a form for them, or the pharmacy doesn’t have the medication in stock. 

We are a highly collaborative team of builders and operators who invent new ways of working in an industry that historically has resisted innovation. Join us!

Responsibilities

  • Design and implement Threat and Vulnerability Management program for AWS cloud and Engineering applications.
  • Ensure alignment with the Security Pillar of AWS Well Architected Framework.
  • Facilitate and review Threat modeling with Applications teams.
  • Conduct Security architecture review of key application enhancements.
  • Manage the operations of cloud security tools, triage and prioritize findings, work with stakeholders to fix defects.
  • Manage the operations of source code scanning security tools (SAST), 3rd party modules scanning security tools (SCA), runtime application scanning security tools (DAST). Triage and prioritize findings, work with stakeholders to fix defects.
  • Manage the operations of API security tools. Triage and prioritize findings, work with stakeholders to fix defects.
  • Manage the operations of Data Security tools. Monitor, Identify, triage, and prioritize findings. Work with stakeholders to fix defects.
  • Manage the operations of SIEM, ensure security logs are being sent to the SIEM, configure and find fund thresholds and alerts.
  • Perform internal application pen tests. Identify, triage, and prioritize findings. Work with stakeholders to fix defects.
  • Monitor alerts and respond to security incidents according to incident response plan.
  • Monitor identity security including Periodic review of access logs, anomaly access and account review, excessive and outlier permissions, inactive accounts with high privileges.
  • Prepare relevant metrics and status reports related to Cloud Security and Engineering Application Security
  • Develop and maintain content for Cloud Security and Engineering Applications for Infosec CoE (Center of Excellence) and Product Security Baselines.
  • Assists in the review and update of cyber security policies, architectures and standards.
  • Assists in responding to audits, penetration tests and vulnerability assessments.

Requirements

  • Bachelor’s degree in computer science, cybersecurity or a related field
  • 5+ years of experience in Information Security 
  • Certifications (CISSP) or equivalent is a plus. AWS Security certification is a plus.
  • Experience in AWS Cloud Security
  • Experience in OWASP Top Ten, API Security, Data Security, SAST, SCA, DAST
  • Experience in WAF, IAM, DLP
  • Experience in XDR, SIEM, SOC
  • Familiarity with GitHub, Kubernetes
  • Familiarity with Networking, VPN, Firewall
  • Familiarity with Compliance Frameworks & Controls (HIPAA, PCI)

Why Join Us:

It is rare to have a company that both deeply impacts its customers and is able to provide its services across a massive population.  At Blink, we have a huge impact on people when they are most vulnerable: at the intersection of their healthcare and finances. We are also the fastest growing healthcare company in the country and are driving that impact across millions of new patients every year.  Our business model not only helps people, but drives economics that allow us to build a generational company. We are a relentlessly learning, constantly curious, and aggressively collaborative cross-functional team dedicated to inventing new ways to improve the lives of our customers.

We are an equal opportunity employer and value diversity of all kinds. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Similar Jobs

Hawk Eye Innovations - Backend Java Engineer - Contract

Hawk Eye Innovations

London, England, United Kingdom (On-Site)
1 Week ago
ION - Lead Software Engineer, Italy

ION

Turin, Piedmont, Italy (On-Site)
4 Months ago
Luxoft - .NET and Azure API Developer

Luxoft

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Playrix - Location Game Designer

Playrix

Serbia (Remote)
4 Months ago
Sandsoft Games - Playable Ad Developer

Sandsoft Games

Barcelona, Catalonia, Spain (On-Site)
5 Months ago
PwC - Project Manager Security Testing

PwC

Amsterdam, North Holland, Netherlands (On-Site)
1 Month ago
Virtuos - IT Security Operation Specialist

Virtuos

Ukraine (Hybrid)
1 Month ago
PwC - Workday - Senior Consultant-  Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
OKX - Graduate Hire 2024/25 - SRE/Security Engineer

OKX

Hong Kong (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

InvenioLSI - MuleSoft Managing Consultant

InvenioLSI

Dubai, Dubai, United Arab Emirates (On-Site)
2 Months ago
Vena Solutions - Software Developer in Test 2

Vena Solutions

Indore, Madhya Pradesh, India (On-Site)
4 Months ago
X Studios,  Inc  - Engineer, Django/Python (Contractor)

X Studios, Inc

Winter Park, Florida, United States (On-Site)
6 Months ago
DPS Games - Senior Release QA (Steel Hunters)

DPS Games

Guildford, England, United Kingdom (Hybrid)
3 Weeks ago
Condé Nast Technology Lab - Application Security - Engineer IV

Condé Nast Technology Lab

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Next Level Business Services - Java/C++ Developer

Next Level Business Services

Sunnyvale, California, United States (On-Site)
3 Months ago
Netflix - Senior Analytics Engineer

Netflix

United States (Remote)
4 Weeks ago
The Walt Disney Company - Labor Systems Web Integration Intern

The Walt Disney Company

Lake Buena Vista, Florida, United States (On-Site)
5 Days ago
Titmouse - Pipeline Technical Director

Titmouse

Los Angeles, California, United States (On-Site)
13 Hours ago
undefined - DX Engineer

United States (Remote)
4 Months ago

Get notifed when new similar jobs are uploaded

Jobs in India

PwC - IN-Senior Associate_SAP SD_Enterprise Apps SAP_Advisory_PAN India

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
STAGE - Content Acquisition Executive

STAGE

Noida, Uttar Pradesh, India (On-Site)
2 Weeks ago
Imagineio - Lighting & Shading Artist

Imagineio

Delhi, India (On-Site)
1 Month ago
STAGE - Founder's Office

STAGE

Noida, Uttar Pradesh, India (On-Site)
1 Month ago
Employ - Senior Software Engineer

Employ

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Starkflow - Lighting Design Engineer

Starkflow

India (Remote)
1 Month ago
InMobiInMobi - Lead - Product Analytics

InMobiInMobi

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
PwC - Senior Associate_Azure Data Engineer_Data & Analytics_Advisory_PAN  India

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
InMobiInMobi - Assistant Manager - Processes and Coordination

InMobiInMobi

New Delhi, Delhi, India (On-Site)
1 Month ago
CGI - Guidewire CC, PC - Automation Tester

CGI

Bengaluru, Karnataka, India (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Senior Experimentado- Business Analyst

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
4 Months ago
Jagex - Senior Cyber Security Manager - GRC

Jagex

Cambridge, England, United Kingdom (Hybrid)
15 Hours ago
ION - IT/Cyber Security Analyst

ION

London, England, United Kingdom (On-Site)
4 Months ago
Egnyte - Sr. Customer Success Manager, S&G Specialist

Egnyte

India (Remote)
1 Month ago
Ubisoft - Resilience and Security Specialist

Ubisoft

Montreal, Quebec, Canada (Hybrid)
2 Weeks ago
Google - Senior Cyber Security Consultant, Google Public Sector

Google

Reston, Virginia, United States (On-Site)
1 Month ago
Microsoft - Digital Solution Specialist - Security

Microsoft

Montreal, Quebec, Canada (On-Site)
4 Weeks ago
Windranger Labs - Security Engineer

Windranger Labs

Australia (Remote)
3 Months ago
Microsoft - Software Engineer

Microsoft

Cambridge, England, United Kingdom (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded