高级安全工程师II - 应用安全
Senior Security Engineer II - Application Security
高级安全工程师II将负责设计、实施和维护支持我们业务的安全服务。您将理解数据和自动化是我们使命的重要组成部分,并知道如何在大规模上积极运用这些要素。除了技术专长,我们重视能够跨团队协作、推动有影响力成果并进一步保障我们数字环境的个人。
我们对地理位置灵活,理想的候选人应能够在美国内远程办公或在家办公,或在马里兰州贝塞斯达总部办公室工作。
我们是谁:
Aledade PBC是一家公共利益公司,致力于赋能医疗保健领域最具变革性的部分——独立初级护理。我们成立于2014年,至今已成为全国最大的独立初级护理网络,帮助诊所、卫生中心和医疗机构为患者提供更好的护理,并在基于价值的护理中蓬勃发展。此外,通过在各种健康计划中创建基于价值的合同,我们旨在改变传统的按服务收费模式。我们的工作加强了护理的连续性,协调了激励措施,并确保初级护理医生因他们最擅长的工作——保持患者健康而获得报酬。如果您希望参与创建一个对患者、诊所和社会都好的医疗体系,并且渴望加入一个协作、包容且以远程为主的文化,那么您来对地方了。
对你来说意味着什么?
在Aledade PBC,您将融入一个由热情驱动的创意文化,以尊重、开放心态和学习欲望解决复杂问题。您将与来自不同经验、兴趣、背景、信仰和成就的团队成员合作,他们共同拥有对公共卫生的热情和对Aledade使命的承诺。
除了支持工作与生活平衡和享受的时间外,我们还提供以下全面的福利计划,以促进团队成员的整体福祉:
许多职位可灵活安排工作时间,并具备远程办公能力
员工、家属和伴侣的健康、牙科和视力保险费用支付高达80%
完善的带薪休假计划(第一年21天带薪假期)
每年2天带薪志愿服务日
查看英文原文
The Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape.
We are flexible with respect to geographic location, and the ideal candidate will be comfortable working remotely/work from home within the U.S. or from our headquarters office in Bethesda, MD.
Who We Are:
Aledade PBC, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.
What Does This Mean for You?
At Aledade PBC, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.
In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:
Flexible work schedules and the ability to work remotely are available for many roles
Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
Robust time-off plan (21 days of PTO in your first year)
Two paid volunteer days and 11 paid holidays
12 weeks paid parental leave for all new parents
Six weeks paid sabbatical after six years of service
Educational Assistant Program and Clinical Employee Reimbursement Program
401(k) with up to 4% match
Stock options
And much more!
At Aledade PBC, we don’t just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.
Primary Duties:
- Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
- Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
- Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
- Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
- Mentoring and coaching more junior engineers or analysts
Minimum Qualifications:
- BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree
- 6+ years of experience in securing and deploying applications within Cloud Native environments
- 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes
Preferred Knowledge, Skills, and/or Abilities:
Application Security
- Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc, direct experience preferred.
- Experience architecting, developing, and deploying large-scale distributed systems at scale.
- Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.
- Proven experience conducting code reviews, and threat modeling.
- Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc.
- Proficient in coding languages such as Python, R, C++, Javascript.
- Extensive experience working in AWS/Azure/GCP software development environment..
- Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc.
- In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them.
- In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices.
- Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go).
- 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value
- Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred.
Physical Requirements
- Must be able to sit for prolonged periods of time