Senior Security Engineer

Thirty Madison
Summary
Join Thirty Madison as a Senior Security Engineer and contribute to building a secure digital health platform that protects patients. You will work alongside experienced security engineers and collaborate with technologists across the company to ensure the safety of our patients and their data. Your responsibilities will include designing and building security infrastructure, partnering with various teams to maintain and improve cloud security posture, resolving security vulnerabilities and risks, researching threats and attack vectors, and responding to security incidents. You will be responsible for defining and maintaining key performance indicators for a healthy infrastructure and cloud security program. This role requires experience with SIEM, EDR, and CSPM tools, expertise in cloud security, especially for AWS, and a deep understanding of Kubernetes security. You should also have experience with Infrastructure as Code, the ability to understand the whole solution, and a focus on the end-to-end lifecycle of problem-solving. Thirty Madison offers a competitive salary, annual incentive plan, stock options, robust benefits, and a flexible time off policy.
Requirements
- Experience with SIEM, EDR, and CSPM tools (Wiz, SentinelOne, Island)
- Experience in cloud security, especially for AWS, anything to do with IAM, secure configuration of services, AWS native security services like AWS Cloudtrail, SCPβs, AWS Org, Config etc
- Kubernetes Security Expertise: Deep understanding of Kubernetes security, including secure deployments, network policies, S2S authentication & authorization, RBAC, workload identity, admissions controllers, and runtime security
- Expertise responding to complex incidents across endpoint, network, and cloud as well as experience being an Incident Commander/Responder
- Expertise responding to complex incidents across endpoint, network, and cloud
- Capable of understanding an unfamiliar system enough to successfully respond to an incident involving the system
- Experience with Infrastructure as Code. We use Terraform
- Ability to understand the whole solution, not just the technology
- Focus on the end to end lifecycle of solving a problem and solutioning for it and not just implementing a security technology
- Have a well-rounded view for problem solving and a deep care for the patient and your fellow employees' experience as you surpass security challenges
- Hunger to drive decision making, collaboration and to have deeper opinions on security design
Responsibilities
- Design and build the security for the future of our infrastructure
- Partner with the infrastructure team, engineering team, compliance team and within security teams to maintain and further improve our cloud security posture management and help deliver secure products and services for our patients and doctors
- Take care of real world problems and challenges related to infrastructure security and implement sustainable solutions
- Create solutions and processes to identify, resolve and mitigate security vulnerabilities and risks
- Research threats and attack vectors that impact Thirty Madisonβs applications and infrastructure
- Devise and bolster defense-in-depth through secure-by-default frameworks, architectures and processes
- Define and maintain key KPIs for a healthy infra/cloudSec program
- Detect and respond to security incidents and participate in an incident on-call rotation for critical and non-critical alerts
Benefits
- The base pay range for this position is $159,200 - $218,900 per year**
- Annual Incentive Plan + Stock Option Package
- Robust and affordable Medical, Dental, and Vision plan options
- 401(k) with a match, commuter benefits, and FSA
- Annual $750 vacation stipend and $500 happiness stipend
- Flexible time off policy