Cala Health logo
Cala HealthPosted 1 week ago

Security Engineer

$155,000–$190,000 year

HybridSan Mateo, California, United States

Full TimeSmallHealthcare

Job Summary

Monitor and manage open-source dependencies using SCA tools to mitigate supply chain risks, while tracking CVEs and automating updates within the CI/CD pipeline. Lead end-to-end execution of penetration tests and bug bounty programs, translating findings into actionable remediation plans. Own security remediation across infrastructure and applications by implementing guardrails like IAM policies and secrets management. Serve on the Incident Response team with an on-call rotation to detect, contain, and eradicate breaches, conducting post-incident reviews to harden defenses. Design and facilitate security tabletop exercises to test incident response plans against realistic threat scenarios. Champion a security-first culture by mentoring engineers and creating training content, while supporting compliance efforts for frameworks like SOC 2 and HIPAA.

Required Qualifications

  • 3+ years of experience in Security Engineering, Application Security, or Incident Response
  • Hands-on experience with modern security tooling (e.g., Snyk, Dependabot, Burp Suite, Splunk, Datadog)
  • Strong understanding of OWASP Top 10, CWE, and cloud security best practices
  • Hands-on experience with CI/CD pipelines and build automation tools (e.g., Jenkins, GitHub Actions, GitLab CI) to integrate security scanning and controls
  • Proficiency in Python and Shell scripting (Bash) to automate security workflows and build security tooling
  • Applicants must be authorized to work in the United States on a full-time basis, or eligible for work authorization through a sponsorship path that Cala Health is able to support

Desired Qualifications

  • Familiarity with additional programming languages such as Go, JavaScript/TypeScript, or Rust for deeper code reviews and custom tooling
  • Experience securing cloud-native environments (Docker, AWS/GCP) and native AWS security tools (AWS Inspector, GuardDuty)
  • Hands-on experience with GRC platforms (e.g., Vanta)
  • Familiarity with Infrastructure as Code (IaC) security scanning (e.g., Checkov, TFLint)
  • Relevant industry certifications (e.g., CISSP, CEH, OSCP, GCIH, AWS Certified Security)
  • Excellent communication skills with the ability to articulate technical security concepts to non-technical stakeholders
  • Familiarity with bug bounty services like BugCroud
  • Experience working on cloud connected IoT devices (provisioning, key rotation, OTA update security)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce