Jobs and Careers
SP

Security Engineer II

Spring Health
UKRemotefull_timeVerifiedPosted 12 Oct 2023
💰 $125,800/yr($105,000/yr$125,800/yr)

About the role

Our mission: to eliminate every barrier to mental health. 

Spring Health is a comprehensive mental health solution for employers and health plans. Unlike any other solution, we use clinically validated technology called Precision Mental Healthcare to pinpoint and deliver exactly what will work for each person  — whether that’s meditation, coaching, therapy, medication, and beyond. 

Today, Spring Health equips over 800 companies, from start-ups to multinational Fortune 500 corporations, as a leading and preferred mental health service. Companies like J.P. Morgan Chase & Co., Microsoft, J.B. Hunt, Bumble, and Instacart use the Spring Health platform to provide mental health services to thousands of their team members globally. We have raised over $370 million from prominent investors including Kinnevik, Tiger Global, Northzone, RRE Ventures, and many more. Thanks to their partnership, our current valuation has reached $2.5 billion.

We are looking for a Security Engineer II to be part of our Security Operations & Engineering (SecOps) team. SecOps is committed to proactively detect, respond to, simulate, and identify breach attempts and threat actors. You will work with a team who oversee overall enterprise security systems implementation, lifecycle (S-SDLC), and support. You will help improve the company’s ability to respond to threats through technology selection, internal product development and implementations with a heavy emphasis on automation of manual tasks and processes. We’re looking for security engineers that can work collaboratively with our security, product, infrastructure architecture and engineering teams to implement secure solutions.

What you’ll be doing

  • Design, build, maintain, tune and enhance the effectiveness of our security controls in multiple security domains including but not limited to:
    • Cloud security
    • Endpoint detection and response
    • Data loss prevention (DLP)
    • Security Information and Event Management (SIEM)
    • Identity and Access Management (IAM)
  • Build security automation to secure our corporate and cloud infrastructure and development environments
  • Participate in on call rotation, addressing most issues without assistance and escalate to Subject Matter Experts (SMEs) where needed
  • Assist peer teams in securing applications, business software and services, and infrastructure
  • Assist with the secure integrations of cloud applications and infrastructure
  • Develop and maintain technical support/knowledge base documentation
  • Develop and maintain security and incident response playbooks
  • Other duties as assigned. Management reserves the right to assign or reassign duties and responsibilities at any time

 

What we expect of you

  • Proficiency with Infrastructure as Code (Terraform, Terragrunt, CloudFormation, etc)
  • Familiarity with cloud platforms (AWS, Azure, GCP) and their security features, best practices and configurations
  • Proficiency with at least one programming or scripting language such as Python (preferred), Perl, Bash to automate tasks, analyze data and develop security tools
  • Ability to manage multiple tasks and projects simultaneously while effectively prioritizing based on risk and business impact
  • Strong knowledge of security principles, technologies and best practices including encryption, authentication, firewalls, intrusion detection/prevention systems and incident response
  • You are a dedicated, highly organized and motivated person who is passionate about security
  • You can work under deadlines in a fast-paced environment
  • Experience with security testing tools and techniques such as vulnerability scanning and penetration testing
  • Understanding of regulatory compliance standards such as GDPR, HIPAA, PCI-DSS or ISO 27001
  • Strong analytical and problem-solving skills with the ability to identify security risks and develop effective mitigation strategies
  • Excellent communication and collaboration skills, enabling effective interaction with both technical and non-technical stakeholders
  • Minimum of 2 years professional or technical experience with a strong background in all aspects of security tools administration and incident response

 

What we’d love to see as a bonus

  • Experience with threat modeling
  • Cloud security certifications
  • Experience with SIEM evaluation and implementation

 

The target salary range for this position is $105,000 - $125,800, and is part of a competitive total rewards package including stock options, benefits, and incentive pay for eligible roles. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Spring Health

View company profile →