1 day ago

Security Engineer

Stedi

Hybrid
Full Time
$180,000
Hybrid

Job Overview

Job TitleSecurity Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$180,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Stedi

In the healthcare sector, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) requires that all insurance payers exchange transactions such as claims, eligibility checks, prior authorizations, and remittances using a standardized EDI format called X12 HIPAA. A small group of legacy clearinghouses process the majority of these transactions, offering consolidated connectivity to carriers and providers.

Stedi is the world's only programmable healthcare clearinghouse. By offering modern API interfaces alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked as Ramp’s #3 fastest-growing SaaS vendor.

Stedi has lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company’s infrastructure; passion for automation and eliminating toil; $92 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more. To learn more about how we work, watch our founder Zack’s interview with First Round Capital.

What We’re Looking For

We are seeking an experienced Security Engineer to join our Platform Team. This team is at the core of our infrastructure, responsible for managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications.

The Platform Team’s responsibilities span a wide range of areas, including:

  • The AWS infrastructure that our engineering teams rely on.
  • Management of our GitHub organization and IT operations.
  • Supporting compliance efforts to ensure alignment with industry standards (SOC, HIPAA, HITRUST).

As a Security Engineer, you will play an active role in how we set up our AWS infrastructure, software development lifecycle, and endpoint security. Your contributions will help ensure our engineering teams build applications in a way where it is easy to demonstrate alignment with regulatory and compliance requirements.

How We Build

We use AWS exclusively for our backend infrastructure that processes customer data. We use tools like GitHub, Stripe, Vanta, and PagerDuty, but all of our application work happens on AWS. We use serverless technologies almost exclusively: Lambda, API Gateway, SQS, SNS, DynamoDB, Aurora Serverless, and more. We don’t run a single server on prem or in the cloud. We use the CDK (TypeScript) to define infrastructure-as-code. We have a strong preference for using AWS products over 3rd party solutions. This simplifies vendor management and compliance, and ensures we can benefit from AWS's integration capabilities and innovations now and in the future.

What You'll Do

  • Develop playbooks and address security-related tasks in our AWS serverless environments.
  • Drive improvements in our broader security posture, including application security, endpoint security, access management / just-in-time access, email and web gateways, browser security, and data loss prevention.
  • Collaborate with product engineering teams to raise the bar for security, supporting CI/CD pipelines, dependency management, and secure application design reviews.
  • Help secure and improve our AWS organization using infrastructure as code (CDK), enforcing security controls, and ensuring strong tenant isolation.
  • Continuously assess vulnerabilities and perform regular risk assessments.

Who You Are

  • 4+ years of experience in engineering, working as a security engineer or in security-adjacent roles.
  • Familiarity with compliance frameworks such as SOC, HIPAA, and/or HITRUST.
  • 4+ years working with AWS services, including compliance and governance services like AWS Organizations, AWS CloudTrail, AWS Config, Security Hub, and GuardDuty.
  • Proficiency in TypeScript.
  • Ability to prioritize your work based on the needs of the business and the customers.
  • High bandwidth; thoughtful attention to many areas simultaneously.
  • Ability to context switch throughout the course of the day or week as priorities shift.
  • Philosophical alignment with the Stedi Standards and the Unwritten laws of engineering.

Key skills/competency

  • AWS Security
  • Serverless Architecture
  • HIPAA Compliance
  • SOC Compliance
  • HITRUST Compliance
  • Infrastructure as Code (CDK)
  • TypeScript
  • Application Security
  • Risk Assessment
  • Access Management

Tags:

Security Engineer
AWS security
serverless
compliance
application security
endpoint security
access management
risk assessment
vulnerability management
infrastructure as code
CI/CD security
AWS
Lambda
API Gateway
SQS
SNS
DynamoDB
Aurora Serverless
CDK
TypeScript
GitHub
Vanta

Share Job:

How to Get Hired at Stedi

  • Research Stedi's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor, focusing on their "Unwritten laws of engineering."
  • Customize your resume for Stedi: Highlight experience with AWS serverless, security frameworks (HIPAA, SOC, HITRUST), and TypeScript, tailoring it to the Security Engineer role.
  • Showcase AWS and security expertise: Prepare to discuss specific achievements in AWS infrastructure security, compliance, and application security during interviews.
  • Demonstrate philosophical alignment: Articulate how your work approach aligns with Stedi's "passion for automation and eliminating toil" and their "Stedi Standards."
  • Network strategically: Connect with Stedi employees on LinkedIn to gain insights into their engineering practices and team dynamics, especially within the Platform Team.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background