Full-Time

Staff Software Engineer

Cloud Security

Included Health

Included Health

51-200 employees

Accessible primary, behavioral, and virtual care

Compensation Overview

$174.3k - $320.1k/yr

+ Equity

Remote in USA

Remote

Bachelor's

Category
Software Engineering
Required Skills
Kubernetes
Python
Ruby
Infrastructure as Code (IaC)
Docker
Role-based Access Control
AWS
Go
Terraform
Google Cloud Platform

Get referred to Included Health

See people who can refer or advise you

Requirements
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of experience in cloud security, with a strong emphasis on designing, developing (primarily in Python and Go), and implementing security solutions in AWS.
  • Proven hands-on software development experience, particularly in Python and Go, for security automation, building security tools, and infrastructure management.
  • Demonstrable experience designing and implementing robust authorization and access control frameworks (e.g., RBAC, ABAC, policy-as-code) and Just-In-Time (JIT) access solutions.
  • Experience with Infrastructure as Code with deep proficiency in writing and maintaining Terraform modules for security.
  • Experience with containerization (Docker, Kubernetes/EKS), including hands-on experience hardening containerized environments.
  • Experience with SDLC security, CI/CD pipeline security integration, and secure software development practices.
  • Experience with security logging, monitoring, alerting tools (e.g., SIEM, AWS CloudTrail, CloudWatch, GuardDuty), and scripting against their APIs (Python, Go).
  • Experience with cloud security frameworks (especially HIPAA), regulations, and standards.
Responsibilities
  • Design, develop, and implement a comprehensive authorization framework for cloud resources, addressing user roles, resource-specific restrictions, task-based access, and granular engineering access
  • Lead the technical implementation of Just-In-Time (JIT) access control systems for production environments (systems, secrets, data) to minimize standing privileges for engineering and platform teams.
  • Collaborate with engineering to integrate data classification (e.g., safe-harbor annotations) with access control mechanisms, ensuring that data sensitivity directly informs access decisions.
  • Develop and maintain security automation scripts, tools, and services in Python or Go to streamline security operations, vulnerability management, compliance checks, and incident response.
  • Write clean, maintainable, and testable code (primarily Python and Go; familiarity with Ruby is a plus) for security automation, building custom security integrations, and developing security-focused tools.
  • Implement and champion Infrastructure as Code (IaC) principles, specifically using Terraform, for programmatic definition, enforcement, and auditing of security configurations.
  • Contribute to the design and implementation of centralized security controls, such as an engineering-owned Web Application Firewall (WAF), to manage rate limiting, IP blocking, input validation, and request filtering.
  • Partner with engineering teams to establish and implement secure practices for managing the development toolchain (code generation utilities, linters, browser extensions, CLI tools, IDE plugins) to mitigate supply chain risks.
  • Design and help implement a secure, "blessed" mechanism for webhook testing in local development environments, blocking unauthorized tunneling tools.
  • Define, implement, and enforce container security hardening standards (e.g., least privilege, no unnecessary utilities, limited internet access) in collaboration with engineering teams.
  • Drive the remediation of legacy cloud environments, particularly in GCP, by inventorying, assessing, and improving security controls.
  • Design and implement solutions for granular data access control in cloud environments, particularly addressing compliance requirements for handling sensitive data.
  • Collaborate closely with infrastructure software, engineering, DevOps, and product teams to co-design and integrate robust, automated security controls into systems, architectures, and CI/CD pipelines.
  • Act as a subject matter expert on cloud security (AWS, GCP), providing guidance, code reviews (Python, Go), and technical expertise on secure cloud adoption, secure software development, and access control best practices.
  • Support organizational change management efforts related to new security controls and practices by providing technical rationale and assisting in the development of new workflows.
  • Conduct security assessments, threat modeling, and contribute to incident response, developing automation for prevention and faster response.
  • Develop and maintain comprehensive documentation for security architectures, controls, automation scripts, and incident response playbooks.

Included Health coordinates accessible healthcare and advocacy for underserved populations, offering primary care, behavioral health, therapy, psychiatry, and virtual care. Members access a unified platform with 24/7 on-demand care from dedicated providers, integrating primary and behavioral health with care guidance. It differentiates itself through care advocacy, integrated services for underserved groups, and partnerships with employers and consultants that aim for measurable clinical and financial outcomes. The goal is to improve the member experience, achieve better health outcomes, and lower costs for client organizations.

Company Size

51-200

Company Stage

Growth Equity (Venture Capital)

Total Funding

$347M

Headquarters

San Francisco, California

Founded

2020

Get referred to Included Health

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Blue Cross Minnesota added Doctor On Demand virtual primary care on January 13, 2026.
  • January 28, 2026 alternative plan design launched live with large self-insured employers.
  • Dot rolled out December 11, 2025 after eighteen months of pilots and ten billion tokens.

What critics are saying

  • February 2025 data breach investigation and Quincy O'Neal settlement damage trust and invite lawsuits.
  • January 2024 layoffs and 2026 hiring slowdown signal margin pressure inside a crowded category.
  • Google, Teladoc, and health plans can replicate navigation and AI, commoditizing Included Health quickly.

What makes Included Health unique

  • Included Health pairs navigation, primary care, behavioral health, and specialty referrals in one workflow.
  • Dot uses claims, benefits, and clinical data for clinician-in-the-loop guidance, not generic chat.
  • Firefly Health acquisition announced July 29, 2026 extends Included Health into integrated plan design.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Along with comprehensive medical, dental and vision plans; all employee spouses and children can access Included Health services at no cost. For time off, take it when you need it with our unaccrued discretionary time off for all exempt employees.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
PR Newswire
May 11th, 2021
Grand Rounds Health and Doctor On Demand Complete Merger to Form the Only Virtual Care Company of its Kind

/PRNewswire/ -- Grand Rounds Health, a leader in healthcare quality and navigation, and Doctor On Demand, a leading virtual care provider, today announced the...

HIT Consultant
Apr 12th, 2021
SOC Telemed Inc. acquired Accesstelecare for $194M on Oct 18th 20'.

SOC Telemed acquired Access Physicians for $194mm to solidify its acute care telemedicine services.

Talk to Mira
Dec 20th, 2020
Talktomira hired Lorrie Evans as Vice President Business Strategy and Operations on Dec 20th 20'.

I am extremely happy to announce today that Lorrie Evans has joined its team as Mira‚s Vice President Business Strategy and Operations.

Private Equity Wire
Sep 9th, 2020
Carlyle leads USD175 million round into Grand Rounds

Grand Rounds, a healthcare quality and clinical navigation company, has secured a USD175 million round led by investment funds affiliated with global investment firm The Carlyle Group.