Charta Health

Charta Health

Founding Security Reliability Engineer

San Francisco

Sponsorship not specified$150k-$250kDetected 6 days ago
SwiftCode ReviewAWSCloud PlatformsTerraformAnsibleCI/CDSite Reliability EngineeringRESTData EngineeringLLMsCybersecurityPenetration TestingNetwork SecuritySIEMSOC OperationsIncident ResponseComplianceFirewallHIPAAResearchCommunicationCollaborationProblem Solving

About the role

  • You'll be crucial in engineering security into every layer from day one within a highly regulated healthcare environment.
  • Serve as a subject matter expert on security best practices. - Security Culture & Training: Champion a strong security-first culture.
  • We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Responsibilities

  • Engineer Secure & Resilient Infrastructure: Design, develop, and implement highly scalable, resilient, and inherently secure cloud infrastructure and application architectures to support our AI platform and data pipelines, prioritizing security-by-design and resilience against attacks.
  • Security Automation & DevSecOps: Lead efforts to automate security controls, infrastructure provisioning, deployment, and operational tasks using tools like Terraform, Ansible, and CI/CD pipelines.
  • Cloud Security Engineering: Implement and manage security best practices for our cloud environments (primarily AWS), including network security, identity and access management (IAM), data encryption at rest and in transit, secrets management, and secure configuration baselines.
  • Application Security: Partner with development teams to conduct threat modeling, perform security code reviews, and implement secure coding practices. Integrate application security testing tools into CI/CD pipelines and drive vulnerability remediation.
  • Security Reliability Metrics & Incident Response: Define, implement, and monitor key security-focused metrics (e.g., Mean Time To Detect (MTTD) security incidents, Mean Time To Respond (MTTR) security incidents, vulnerability remediation SLAs).
  • Design and lead robust incident response plans and procedures for security incidents and breaches, ensuring swift and effective containment, eradication, recovery, and thorough post-incident analysis (blameless post-mortems) focused on improving system security and resilience.
  • Vulnerability Management: Establish and manage a comprehensive vulnerability management program, including regular scanning, penetration testing coordination, analysis of findings, and driving timely remediation efforts across infrastructure and applications.
  • Cross-Functional Security Collaboration: Partner closely with Engineering, Product, and IT teams to embed security requirements as first-class citizens into business processes, new projects, and system development lifecycles.
  • Security Culture & Training: Champion a strong security-first culture. Develop and deliver engaging security awareness and secure coding training programs for all employees to promote a security-conscious and proactive mindset.
  • Continuously research and integrate the latest security technologies, emerging threats, attack vectors, and threat intelligence to enhance Charta's security program and maintain a strong defensive posture.

Requirements

  • Solid understanding of common web application vulnerabilities, secure coding practices, and experience with application security testing tools.
  • Solid understanding and practical experience with container technologies and orchestration platforms, including container security best practices and runtime protection.
  • Experience setting up and managing robust security monitoring, logging, and alerting solutions (e.g., SIEM, EDR, IDS/IPS).
  • Experience with established security frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, CIS Benchmarks, MITRE ATT&CK).
  • Application Security Fundamentals: Solid understanding of common web application vulnerabilities, secure coding practices, and experience with application security testing tools.
  • Containerization & Orchestration Security: Solid understanding and practical experience with container technologies and orchestration platforms, including container security best practices and runtime protection.
  • Security Frameworks: Experience with established security frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 2, CIS Benchmarks, MITRE ATT&CK).

Skills

  • Strategically plan for future security needs and technological advancements.

Compensation

  • Competitive salary and comprehensive benefits package, including health, dental, and vision.

Benefits

  • Competitive salary and comprehensive benefits package, including health, dental, and vision.
  • Equity & growth opportunities in a fast-growing, innovative tech startup.
  • Ongoing professional development and access to cutting-edge AI and healthcare tools.
  • $150,000 - $250,000 depending on experience + Equity + Benefits
  • Join us in our mission to transform healthcare through innovation!
  • In an industry where the focus should rightly be on delivering quality care to patients, healthcare providers remain burdened by the complexities of non-clinical operations.
  • We're building the operating system for modern healthcare organizations.
  • Backed by Bain Capital Ventures, Charta is on a mission to make every healthcare dollar accountable and every chart accurate, reimagining healthcare infrastructure from the ground up.

Company info

  • Champion a strong security-first culture.
  • Develop and deliver engaging security awareness and secure coding training programs for all employees to promote a security-conscious and proactive mindset.

Equal opportunity

  • equal opportunity employer and value diversity at our company.
  • We are an equal opportunity employer and value diversity at our company.

This listing is sourced directly from Charta Health's careers page and normalized into a canonical job model.