GoodRx Logo

GoodRx

Lead Security Engineer

Posted 2 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in USA
75K-288K Annually
Senior level
Remote or Hybrid
Hiring Remotely in USA
75K-288K Annually
Senior level
Lead security architecture, threat modeling, and enterprise risk management. Drive incident response, DevSecOps enablement, secure SDLC practices, and mentor engineers while aligning security with compliance and business needs.
The summary above was generated by AI

GoodRx is the leading prescription savings platform in the U.S. Trusted by more than 25 million consumers and 750,000 healthcare professionals annually, GoodRx provides access to savings and affordability options for generic and brand-name medications at more than 70,000 pharmacies nationwide, as well as comprehensive healthcare research and information. Since 2011, GoodRx has helped consumers save nearly $75 billion on the cost of their prescriptions.

Our goal is to help Americans find convenient and affordable healthcare. We offer solutions for consumers, employers, health plans, and anyone else who shares our desire to provide affordable prescriptions to all Americans.

Responsibilities:

Security Architecture & Strategy

  • Define and evolve the security architecture across cloud, application, and infrastructure domains.

  • Lead threat modeling and risk analysis for complex systems and new product initiatives.

  • Develop and guide implementation of secure design principles across engineering teams.

  • Evaluate emerging security technologies and recommend strategic adoption.

Risk Management & Governance

  • Perform enterprise-level risk assessments and translate findings into prioritized remediation roadmaps.

  • Define and improve security policies, standards, and control frameworks.

  • Drive alignment of security practices with regulatory and compliance requirements.

  • Provide executive-ready summaries of risk posture and mitigation strategy.

Incident Response & Investigations

  • Lead complex security investigations and incident response efforts.

  • Conduct root cause analysis and implement systemic improvements to reduce future risk.

  • Develop and refine runbooks, playbooks, and response automation.

  • Act as an escalation point for high-impact security events.

DevSecOps & Secure Engineering Enablement

  • Partner with engineering teams to integrate security into the SDLC.

  • Define standards for secure code reviews and static/dynamic analysis.

  • Improve automation for vulnerability scanning, detection, and remediation.

  • Guide cloud security best practices across AWS/GCP environments.

Collaboration & Influence

  • Act as a trusted advisor to engineering leadership and cross-functional partners.

  • Influence technical decisions that balance security, scalability, and delivery speed.

  • Foster strong relationships with vendors and external security partners.

  • Mentor and guide junior security engineers and engineers outside the security team.

Qualifications:

  • 8+ years of cybersecurity or security engineering experience.

  • Deep expertise in application security, cloud security (AWS/GCP), and modern DevSecOps practices.

  • Prior experience with modern javascript frameworks and microservice architecture

  • Demonstrated experience designing and implementing scalable security architectures.

  • Strong understanding of SDLC, CI/CD pipelines, and secure development practices.

  • Experience conducting enterprise-level risk assessments and incident investigations.

  • Strong analytical thinking and ability to assess ambiguous risk scenarios.

  • Excellent written and verbal communication skills, including ability to influence senior stakeholders.

  • Ability to operate independently and exercise sound judgment on high-impact security decisions.

Preferred Qualifications:

  • Experience working in regulated environments (HIPAA, SOC2, PCI, etc.).

  • Offensive security experience or strong understanding of adversarial techniques.

  • Development experience in any modern programming language is a plus (Python, Rust, Go, etc).

  • Experience with SSO platforms (Okta, SAML).

  • Experience with SIEM/SOC tooling and observability platforms.

  • CISSP or equivalent security certification.

  • Cloud security certifications (AWS/GCP) preferred.

  • Certified Kubernetes Administrator certification is a plus.

Security is responsible for implementing security measures, monitoring suspicious activity, and taking immediate action against cyber threats through the incident response process and vulnerability management program. Additionally, Security monitors GoodRx’s organizational systems for end users’ activities from an information security perspective and correlates / analyzes logs to detect potential Events and Incidents. Lastly, the team works collaboratively with other departments to improve the organization’s security posture.

At GoodRx, pay ranges are determined based on work locations and may vary based on where the successful candidate is hired. The pay ranges below are shown as a guideline, and the successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, and other relevant business and organizational factors. These pay zones may be modified in the future. Please contact your recruiter for additional information.

San Francisco and Seattle Offices:

$180,000.00 - $288,000.00

New York Office:

$165,000.00 - $264,000.00

Santa Monica Office:

$150,000.00 - $240,000.00

Other Office Locations:

$135,000.00 - $216,000.00

GoodRx also offers additional compensation programs such as annual cash bonuses or commission, and annual equity grants for most positions as well as generous benefits. Our great benefits offerings include medical, dental, and vision insurance, 401(k) with a company match, an ESPP, unlimited vacation, 13 paid holidays, and 72 hours of sick leave. GoodRx also offers additional benefits like mental wellness and financial wellness programs, fertility benefits, generous parental leave, pet insurance, supplemental life insurance for you and your dependents, company-paid short-term and long-term disability, and more!

We’re committed to growing and empowering a more inclusive community within our company and industry. That’s why we hire and cultivate diverse teams of the best and brightest from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has a seat at the table and the tools, resources, and opportunities to excel.

With that said, research shows that women and other underrepresented groups apply only if they meet 100% of the criteria. GoodRx is committed to leveling the playing field, and we encourage women, people of color, those in the LGBTQ+ communities, individuals with disabilities, and Veterans to apply for positions even if they don’t necessarily check every box outlined in the job description. Please still get in touch - we’d love to connect and see if you could be good for the role!

GoodRx is committed to providing reasonable accommodations for candidates with disabilities during our recruiting process. If you need any assistance or accommodations due to a disability, please reach out to us at [email protected].

We prioritize candidate safety. Please be aware that all official communication will only be sent from @goodrx.com or [email protected] addresses.

GoodRx is America's healthcare marketplace. The company offers the most comprehensive and accurate resource for affordable prescription medications in the U.S., gathering pricing information from thousands of pharmacies coast to coast, as well as a tele-health marketplace for online doctor visits and lab tests. Since 2011, Americans with and without health insurance have saved $60 billion using GoodRx and million consumers visit goodrx.com each month to find discounts and information related to their healthcare. GoodRx is the #1 most downloaded medical app on the iOS and Android app stores. For more information, visit www.goodrx.com.

Top Skills

Aws,Gcp,Javascript Frameworks,Microservice Architecture,Ci/Cd,Static Analysis,Dynamic Analysis,Vulnerability Scanning,Okta,Saml,Siem,Soc Tooling,Observability Platforms,Python,Rust,Go,Kubernetes

Similar Jobs at GoodRx

2 Hours Ago
Remote or Hybrid
USA
75K-350K Annually
Senior level
75K-350K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Drive business growth within the employer market, manage relationships with benefits consultants, and educate them about pharmacy and benefits solutions.
2 Hours Ago
Remote or Hybrid
USA
75K-402K Annually
Expert/Leader
75K-402K Annually
Expert/Leader
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
The Executive Director is responsible for driving growth in organizational operations and market strategy, ensuring effective business processes and excellent client experience in pharmacy benefits and employer-sponsored solutions.
Yesterday
Remote or Hybrid
USA
60K-173K Annually
Senior level
60K-173K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Lead end-to-end employer implementation projects for Benefit Solutions, serving as primary client liaison, coordinating cross-functional teams, managing timelines, risks, documentation, and process improvements to ensure successful go-lives and client satisfaction.
Top Skills: Smartsheet,Asana,Jira,Ms Project

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account