Included Health Logo

Included Health

Cloud Engineer, Security

Posted One Month Ago
Remote
Hiring Remotely in USA
174K-320K Annually
Senior level
Remote
Hiring Remotely in USA
174K-320K Annually
Senior level
Design, implement, and automate cloud security controls (primarily AWS, with GCP work) using code (Python, Go) and IaC (Terraform). Build authorization and JIT access systems, harden containers and CI/CD pipelines, integrate data classification with access controls, automate security operations and incident response, and partner with engineering to embed HIPAA-compliant, secure-by-design practices.
The summary above was generated by AI

At Included Health, security is central to the trust our members, customers, partners, and care teams place in us. We protect sensitive health information and the systems that support our products by building security into architecture, engineering practices, and day-to-day operations.

 

Our Security Engineering team works closely with platform engineering and product teams to build practical, scalable security controls, especially focused on our infrastructure-as-code. We focus on reducing risk through automation, secure-by-default patterns, strong technical partnerships, and controls that teams can operate in real production environments.

 

As a Cloud Engineer on the Security team, you’ll help mature Included Health’s cloud security posture across primarily AWS environments, with consideration for GCP. You’ll design, implement, and automate controls that protect product infrastructure and help prevent unauthorized Protected Health Information (PHI) exfiltration.
This is a full-time, remote role reporting to the Senior Manager, Security Engineering. We are open to considering candidates at both the Senior and Staff levels.

The role requires hands-on technical execution as well as the ability to influence infrastructure, DevOps, engineering, and product teams.

 

What You'll Do

  • Design and automate cloud security controls across Identity & Access Management (IAM), authorization, Just-in-Time access, data access, and platform access.
  • Improve AWS and GCP security posture through Terraform guardrails, risk roadmaps, legacy remediation, and secure infrastructure patterns.
  • Build security tooling in Python, Go, and Lambda for vulnerability management, alerting, PHI logging, and cloud security workflows.
  • Secure containers, workloads, and CI/CD pipelines through practical controls teams can operate in production.
  • Partner with infrastructure, DevOps, engineering, and product teams on sensitive-data handling, incident response, and secure platform initiatives.
  • Document controls, standards, automation, and playbooks that help teams adopt secure workflows.

Who You Are

    You are a practical, hands-on cloud security engineer who can bring structure to ambiguous risks or control gaps without waiting for perfect clarity. You clarify the desired outcome, trust boundaries, stakeholders, constraints, and available facts, then make a reasonable first move and adapt as you learn.

    You are comfortable going deep in code, cloud APIs, logs, identity policies, network traffic, CI/CD pipelines, and infrastructure configuration. You use evidence to test hypotheses and turn findings into durable fixes, reusable automation, clear documentation, or repeatable processes.

    You build trust through preparation, responsiveness, direct communication, technical credibility, and follow-through. You listen to operational realities, explaining risks and tradeoffs clearly, and work with teams toward practical controls they can operate in production.

    You take ownership through the full loop: coordination, escalation, validation, closure, and knowledge sharing. You know when to investigate independently, when to involve the right expertise, and when broader organizational alignment is needed.

What You Bring

  • 5+ years of hands-on cloud security experience, with deep AWS expertise and familiarity with GCP.
  • Strong technical depth across cloud infrastructure, identity, authorization, networking, containers, CI/CD, logging, monitoring, and security operations.
  • Experience building security automation and infrastructure tooling in Python, Go, Terraform, and cloud-native services.
  • Experience designing and operating access controls, including RBAC, ABAC, policy-as-code, granular engineering access, and Just-in-Time access.
  • Familiarity applying cloud security frameworks, HIPAA requirements, and related standards to production environments.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.

Pay:
 
We are open to considering candidates at both the Senior and Staff levels.
The United States new hire base salary target ranges for this full-time position are:
 
  • Zone A: $130,050–$249,930 + equity + benefits
  • Zone B: $143,055–$274,923 + equity + benefits
  • Zone C: $156,060–$299,616 + equity + benefits
  • Zone D: $169,065–$324,909 + equity + benefits
 
This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones.
 
Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry.
 
Benefits & Perks:
 
In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more:
Remote-first culture
401(k) savings plan through Fidelity
Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
12 weeks of 100% Paid Parental leave
Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
Work-From-Home reimbursement to support team collaboration home office work
 
Your recruiter will share more about the salary range and benefits package for your role during the hiring process.

About Included Health

Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.

-----
Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.

Similar Jobs

3 Days Ago
Remote or Hybrid
199K-295K Annually
Senior level
199K-295K Annually
Senior level
Artificial Intelligence • Big Data • Software • Analytics • Business Intelligence • Big Data Analytics
Designs and manages security controls for AWS and Kubernetes environments, including sandboxing, infrastructure-as-code, cluster hardening, threat modeling, audits, CI/CD security, incident response, and compliance. The role collaborates with engineering and infrastructure teams, mentors engineers, and advocates for cloud security practices across the organization.
Top Skills: Apollo GraphqlAWSCi/CdCloudtrailCnappDevsecopsExpressGuarddutyHelmIamKubernetesPantherPostgresPythonRbacReactRedisReduxSecurity HubSIEMTerraformTerraform AssociateTypescriptWafWiz
4 Days Ago
Remote
USA
152K-175K Annually
Senior level
152K-175K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Secure Runpod’s multitenant GPU cloud infrastructure across bare-metal and virtualized environments. Responsibilities include designing workload and network isolation, hardening Linux kernels and container platforms, testing hypervisor and hardware security, developing low-level controls in C, Go, or Rust, securing GPU and PCIe interactions, and responding to infrastructure security incidents with forensic capabilities for ephemeral containers.
Top Skills: ApparmorBare-Metal Cloud InfrastructureCC.V.E.SCgroupsContainerdDockerEbpfGoGpu ArchitectureKubernetesKvmLinuxLinux KernelNamespacesPciePythonQemuRustSelinuxVirtualized Networking
Yesterday
Remote or Hybrid
150K-185K Annually
Senior level
150K-185K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Owns infrastructure security across AWS, Azure, and GCP cloud environments. Defines security standards, IAM policies, secrets management, guardrails, and infrastructure-as-code controls. Conducts threat modeling, vulnerability assessments, and penetration testing; monitors alerts and leads incident response. Drives SOC 2 and ISO 27001 compliance, audit readiness, and AI-assisted threat detection. Partners with platform, engineering, operations, legal, and business stakeholders to remediate risks and strengthen cloud security.
Top Skills: AWSAws Secrets ManagerAzureCi/CdCloudFormationDarktraceGCPIamIso 27001OrcaSIEMSoc 2TerraformVaultVectraWiz

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account