Senior Security Operations Engineer

Included Health Remote, San Francisco, United States Publicerat 18 augusti 2026
full_timeonsitesenior
Senior Security Operations Engineer Remote · Security & Cyber Security · Full-Time At Included Health, security is central to the trust our members, customers, partners, and care teams place in us. We protect sensitive health information and the systems that support our products by building security into architecture, engineering practices, and day-to-day operations. Our Security Engineering team works closely with IT, platform engineering, and product teams to build practical, scalable security controls that reduce risk through automation, secure-by-default patterns, strong technical partnerships, and controls that teams can actually operate in real production environments. As the Senior Security Operations Engineer, you'll be responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You'll lead hands-on deployment and tuning of DLP controls across endpoint, network, and SaaS; investigate and respond to potential data exfiltration events; and drive remediation and hardening based on real-world incidents and detections. You'll own the operational lifecycle of our DLP stack — building and refining policies, partnering with stakeholders to validate business-safe controls, automating response playbooks, and turning signals from alerts and logs into durable security improvements. You'll also contribute to adjacent security operations functions, including incident response and vulnerability management, where they intersect with data protection. This is a full-time, remote role reporting to the Senior Manager, Security Engineering. The role requires hands-on technical execution as well as the ability to influence IT, engineering, and business stakeholders to adopt practical, business-safe data protection controls. Who You Are You are a practical, hands-on security operations engineer who can bring structure to ambiguous data risks or control gaps without waiting for perfect clarity. You clarify the desired outcome, stakeholders, constraints, and available facts, then make a reasonable first move and adapt as you learn. You are comfortable going deep in logs, alerts, endpoint and network telemetry, SaaS configurations, and cloud storage to find the signal in the noise. You use evidence to test hypotheses and turn findings into durable fixes, reusable automation, clear documentation, or repeatable processes. You build trust through preparation, responsiveness, direct communication, technical credibility, and follow-through. You listen to operational realities, explain risks and tradeoffs clearly, and work with teams toward practical controls they can operate in production. You take ownership through the full loop: investigation, containment, remediation, root cause analysis, and knowledge sharing. You know when to investigate independently, when to involve the right expertise, and when broader organizational alignment is needed. What You'll Do Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling. Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data. Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements. Build and refine automated response playbooks and workflows that enrich, triage, and respond to alerts, reducing manual effort and mean time to respond. Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes. Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners. What You Bring Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP. Direct, hands-on experience deploying, tuning, and operating: DLP tools (endpoint, network, SaaS, and/or cloud) Cloud Access Security Broker (CASB) or similar SaaS security controls in a production environment DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel) Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale. Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types. Pay: The United States new hire base salary target ranges for this full-time position are: Zone A: $128,130 - $180,990+ equity + benefits Zone B: $140,943 - $199,089 + equity + benefits Zone C: $153,756 - $217,188 + equity + benefits Zone D: $166,569 - $235,287 + equity + benefits This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones. Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry. Benefits & Perks: In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more: Remote-first culture

Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.

Visa jobbet och ansök

Ursprunglig annons: jobs.lever.co