Simplify Logo

Full-Time

Staff Engineer

Product Security

Posted on 3/7/2024

One Medical

One Medical

1,001-5,000 employees

Primary healthcare with smart technology integration

Hardware
Biotechnology
Healthcare

Compensation Overview

$152k - $270kAnnually

Senior

United States

Category
Software Engineering
Required Skills
Kotlin
Python
JavaScript
React.js
Ruby on Rails
Go
iOS/Swift
AngularJS
Requirements
  • 7+ years of application security experience, or 5+ years of application security experience and 2+ years of software development experience
  • Significant experience collaborating with product development teams
  • Extensive experience identifying, testing, and remediating against vulnerabilities including those found in the OWASP Top 10 and CWE/SANS Top 25
  • Experience with providing security recommendation and guidance in at least two of the following languages/frameworks: Ruby on Rails, Python, GoLang, JavaScript, React, Angular, Swift, Kotlin, C, C++
  • Proven skills communicating and collaborating with product development leadership
  • Proven track record mentoring and maturing product security engineers
  • Experience building automation and/or writing scripts to solve security problems
Responsibilities
  • Participate in Product Development architecture and strategy meetings and discussions; in particular, you are a sounding board and guide for architectural considerations regarding access control and systems integration
  • Help align One Medical’s application security practices with Amazon’s secure-by-design patterns
  • Conduct Application Security Assessments, Security Architecture Reviews, and Threat Modeling
  • Analyze security test results, document risks, and recommend mitigating controls
  • Design new security automation and select tooling to improve our detection of application vulnerabilities, and to assist in the remediation of findings
  • Provide security subject matter expertise to the Product Security team itself, as well as to development teams, developing secure coding practices, and develop hands-on training to developers and quality engineers
  • Contribute to our incident response and vulnerability remediation efforts
  • Security research, presentation, security industry collaboration, and participation in hackathons
  • On occasion, step in on hands-on security testing and code review of internally developed applications
Desired Qualifications
  • OSCP, OSWE, GPEN or similar certifications
  • Contributions to the security community such as research, public CVEs, bug-bounty recognitions, open-source projects, and blogs or publications
  • Experience working in highly regulated environments subject to compliance requirements such as HIPAA and PCI
  • Experience with authentication/authorization technologies, like OpenID Connect, JWTs, SAML, and HMACs
  • Experience with the security considerations for data pipelines, reporting, ML, and LLMs
  • Experience with mobile security reviews and testing
  • Dual Builder / Breaker mindset: Passion for breaking things and working alongside teams to fix them
  • Familiarity with books and articles by authors such as Loren Kohnfelder, Adam Shostack, Dafydd Stuttart, etc.
  • A writing sample that is a threat model, security design review, or a memo to development team regarding an issue (this could be blacked out for confidential information)
  • Good sense of humor :)

One Medical provides accessible and affordable primary care services, prioritizing a seamless healthcare experience through innovative technologies and patient-centered design. The company leverages smart technology applications to save time and money for patients while enhancing health outcomes.

Company Stage

M&A

Total Funding

$4.3B

Headquarters

San Francisco, California

Founded

2007

Growth & Insights
Headcount

6 month growth

3%

1 year growth

14%

2 year growth

41%

Benefits

Paid sabbatical for your 5th and 10th year

Paid health, vision, and dental insurance

PTO cash out program lets you get cash for up to 40 accrued PTO hours each year

Free One Medical memberships for you and three friends or family members

Pre-tax commuter benefits

Paid maternity and paternity leave at 100% of your base salary

Credit towards childcare

INACTIVE