Senior Security Engineer (Cloud & Infrastructure Security)
Thirty MadisonAbout the role
As a Senior Security Engineer, you will be working alongside an existing team of experienced security engineers and partnering closely with technologists across the company to help build digital health security and protect our patients here at Thirty Madison! We serve our patients from start to finish, and security works the same way, all the way from the deepest infrastructure to the patient experience, we want our patients to be safer by being with Thirty Madison. Above all, you embody the Thirty Madison mission of providing access to healthcare for all who suffer from chronic conditions.
Comp | Perks | Benefits
- The base pay range for this position is $159,200 - $218,900 per year**
- Annual Incentive Plan + Stock Option Package
- Robust and affordable Medical, Dental, and Vision plan options
- 401(k) with a match, commuter benefits, and FSA
- Annual $750 vacation stipend and $500 happiness stipend
- Flexible time off policy
**Base pay offered may vary depending on job-related knowledge, skills, and experience. An annual incentive plan and stock options may be provided as part of the compensation package, in addition to a full range of medical, financial, and/or other benefits, dependent on the position offered.
What you get to do every day
- Design and build the security for the future of our infrastructure
- Partner with the infrastructure team, engineering team, compliance team and within security teams to maintain and further improve our cloud security posture management and help deliver secure products and services for our patients and doctors
- Take care of real world problems and challenges related to infrastructure security and implement sustainable solutions
- Create solutions and processes to identify, resolve and mitigate security vulnerabilities and risks
- Research threats and attack vectors that impact Thirty Madison’s applications and infrastructure
- Devise and bolster defense-in-depth through secure-by-default frameworks, architectures and processes
- Create solutions and processes to identify, resolve and mitigate security vulnerabilities and risks
- Research threats, attack vectors and real-world problems that impact Thirty Madison’s applications and infrastructure security
- Devise and bolster defense-in-depth through secure-by-default frameworks, architectures and processes
- Define and maintain key KPIs for a healthy infra/cloudSec program
- Detect and respond to security incidents and participate in an incident on-call rotation for critical and non-critical alerts
What you bring to the role
- Experience with SIEM, EDR, and CSPM tools (Wiz, SentinelOne, Island)
- Experience in cloud security, especially for AWS, anything to do with IAM, secure configuration of services, AWS native security services like AWS Cloudtrail, SCP’s, AWS Org, Config etc
- Kubernetes Security Expertise: Deep understanding of Kubernetes security, including secure deployments, network policies, S2S authentication & authorization, RBAC, workload identity, admissions controllers, and runtime security
- Expertise responding to complex incidents across endpoint, network, and cloud as well as experience being an Incident Commander/Responder
- Expertise responding to complex incidents across endpoint, network, and cloud
- Capable of understanding an unfamiliar system enough to successfully respond to an incident involving the system
- Experience with Infrastructure as Code. We use Terraform
- Ability to understand the whole solution, not just the technology
- Focus on the end to end lifecycle of solving a problem and solutioning for it and not just implementing a security technology
- Have a well-rounded view for problem solving and a deep care for the patient and your fellow employees' experience as you surpass security challenges
- Hunger to drive decision making, collaboration and to have deeper opinions on security design
All Company policies and procedures are subject to change without notice based on business needs. This includes, but is not limited to, the locations where we hire remote, hybrid, or onsite employees.
U.S. Applicants Only
Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Thirty Madison we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s