Jobs and Careers
CU

Senior Cloud Security Engineer

Curology
Remote (within United States), United StatesRemotefull_timeVerifiedPosted 11 Sept 2023
💰 $200,000/yr($168,000/yr$200,000/yr)

About the role

Join us on the tech team of an extremely fast-growing, technology-driven startup that's making effective skincare accessible to everyone.
Curology is a technology company building the future of skincare through personalized prescription treatment. We believe that dermatology should be accessible to everyone—great skin shouldn't be a luxury, but a fact of life. To make this possible, we're building tech to power an entire in-house medical ecosystem, covering everything from medical care to provider licensing and pharmacy fulfillment operations.
Join our rapidly growing Platform team with exciting projects that enable our engineers to build services that make affordable and effective skincare accessible to everyone.
People, productivity, and security are at the forefront of our mission as a Cloud Security Engineer. We actively collaborate with our teams and stakeholders to maintain and improve the security of our services. Our team achieves all this by working with teammates who are: tenacious about engineering velocity and security; continually seek self-improvement; excited to experiment with new technologies and concepts.

In this role, you will:

  • Be responsible for the development, implementation, and management of the company’s cloud security framework. Leveraging a deep understanding of cloud architecture, security protocols, and compliance standards, this role ensures the integrity, confidentiality, and availability of data across our platform. Here are some examples of what you can look forward to working on:
  • Cloud security: Implement some of AWS's native security services such as GuardDuty, Inspector, and Macie, and take action on the findings/recommendations from those services. This includes mostly infrastructure-hardening work, such as closing ports, patching machines/containers, adding encryption, etc.
  • Security monitoring: Actively monitor our security posture. Establish a security monitoring and alerting process that surfaces potential threats to relevant members of the team.
  • Security Advocacy: Collaborate with cross-functional teams to advocate for security best practices, and ensure secure software development life cycle integration.
  • Dependency vulnerability management: Conduct regular security assessments, penetration tests, and vulnerability scanning. Provide actionable feedback and ensure mitigation of identified vulnerabilities.
  • Automation & Integration: Utilize DevSecOps tools and principles to automate security tasks and integrate security checks into CI/CD pipelines.
  • Application security: Evaluate our application security against the OWASP Top 10 to look for particular vulnerabilities or areas of focus. As we identify them, work with engineering teams to remedy issues. Integrate tooling such as Snyk or Github Advanced Security to do static analysis of our codebase and alert developers when potential changes would introduce security vulnerabilities.
  • Disaster Recovery + Incident Response Gamedays: Regular testing of our disaster recovery plan. This involves getting a group of responders together to run through a gameday exercise annually.
  • Regular penetration testing: Establish a process for doing internal penetration testing regularly at least quarterly. Have an external firm conduct a penetration test at least once per year.
  • Security Incident Response: Lead security incident detection, investigation, and resolution. Collaborate with SREs for post-mortem and lessons learned.
  • Compliance: Work closely with our legal team and Security and Privacy Working Group to ensure cloud environments are compliant with relevant industry standards and regulations.
  • Security Tooling: Recommend, implement, and manage security tools to help in threat detection, vulnerability assessment, and continuous monitoring.
  • Documentation: Create and maintain robust documentation related to security policies, procedures, and best practices.

You will be successful if you have:

  • 4 years of experience with any combination of the following: security engineering, system and network security, authentication, and security protocols, or application security.
  • Experience with network segmentation, network access controls, network monitoring, etc
  • Collaborated with engineers and stakeholders to implement secure solutions for infrastructure, applications, and services. Including coordinating audits and remediations for Compliance Regulations
  • Cloud security experience, including Containerization/Docker/Kubernetes
  • Ability to design and develop solutions to address security needs when third party offers aren't sufficient
  • Strong passion for Continuous Improvement and sharing knowledge through mentorship and acting like an owner

Why this role:

  • You Make a Difference. We don't expect you to just come in and only pick t

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Curology

View company profile →