Jobs and Careers
ON

Engineering Manager, Product Security

One Medical
United States, United StatesRemotefull_timeVerifiedPosted 27 Dec 2023
💰 $260,000/yr($150,000/yr$260,000/yr)

About the role

About Us

One Medical is a primary care solution challenging the industry status quo by making quality care more affordable, accessible and enjoyable. But this isn’t your average doctor’s office. We’re on a mission to transform healthcare, which means improving the experience for everyone involved - from patients and providers to employers and health networks. Our seamless in-office and 24/7 virtual care services, on-site labs, and programs for preventive care, chronic care management, common illnesses and mental health concerns have been delighting people for the past fifteen years.

In February 2023 we marked a milestone when One Medical joined Amazon. Together, we look to deliver exceptional health care to more consumers, employers, care team members, and health networks to achieve better health outcomes. As we continue to grow and seek to impact more lives, we’re building a diverse, driven and empathetic team, while working hard to cultivate an environment where everyone can thrive.

The Opportunity

Our  Product Security team at One Medical is currently hiring an Engineering Manager for our growing team. You will be a driving force in securing health and personal information at scale and will work closely with our Product Development teams and Amazon Security teams to ensure the security of One Medical’s applications and the cloud infrastructure they run on. You will lead the development and standardization of product security policies and processes designed to address software security risk, such as security assessment and risk management procedures. This is a leading security role, where you have the opportunity to contribute to the overall direction of the information security team for our company and the healthcare industry as a whole.

Our highly technical staff collaborates with a "team first" mentality that enables us to move the security needle forward, for both One Medical and for the greater healthcare industry. If you have a strong vision for bringing scalable and frictionless security to a product development organization and want the opportunity to lead a capable team in achieving those goals, this role is for you.

What you'll work on: 

  • Lead a team of product security engineers focused on solving software and cloud security challenges in an innovative, fast paced environment
  • Develop and mature security touchpoints into the Product Development Lifecycle, working with stakeholders across the Technology team and Amazon Security to create efficiencies or resolve communication gaps
  • Act as the subject matter expert for complex security problems or escalations
  • Build a roadmap to improve the security of One Medical’s proprietary Electronic Health Record (EHR) system and associated applications 
  • Sustain a data-driven and automated vulnerability management process that shifts security left, in order to get the right information in the hands of software engineers at the right time 
  • Provide the tools, training and processes to allow Product Development to operate securely and without friction
  • In collaboration with other leaders on the team, develop and iterate on processes to support the team’s success
  • Facilitate a healthy team environment by providing support, feedback, career guidance, mentoring, and group cohesion for team members

What you'll need:

  • 7+ years of overall software development and/or security engineering development experience
  • 4+ years experience within an internal security team, this can be both individual contributor and management positions
  • 3+ years of experience people managing an internal security team or equivalent technical leadership experience, including and agile frameworks such as Scrum or Kanban
  • Lead technical teams through design reviews, offensive assessments/threat models, penetration testing, exploit development, and vulnerability analysis
  • A strong passion for making developers highly productive, while minimizing risk
  • Strong working proficiency with application security tool concepts, like SAST, DAST, SCA, and WAFs
  • Understanding of architectural and operational security concerns for the cloud, specifically AWS
  • Understanding of the fundamentals of identifying and protecting against web and mobile application vulnerabilities including those found in the OWASP Top 10 and CWE Top 25
  • Proficiency with providing security recommendation and guidance in at least two of the following languages/frameworks: Ruby on Rails, Python, GoLang, JavaScript, React, Angular

Not required, but would be great if you also had:

  • A passion for healthcare and/or experience working with electronic health record systems (EHR)
  • Understanding of compliance frameworks such as

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

One Medical

View company profile →