Included Health Logo

Included Health

Senior Security Operations Engineer

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
128K-235K Annually
Senior level
Remote
Hiring Remotely in USA
128K-235K Annually
Senior level
Leads DLP security operations across endpoint, network, SaaS, and cloud environments. Responsibilities include deploying and tuning DLP controls, investigating data exfiltration incidents, developing data classification policies, automating alert response playbooks, threat hunting for anomalous data movement, managing incident remediation, and tracking DLP effectiveness metrics. The role also supports incident response and vulnerability management and partners with stakeholders to balance security, usability, and regulatory requirements.
The summary above was generated by AI

The Senior Security Operations Engineer is responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You will lead hands-on deployment and tuning of DLP controls, including endpoint, network, and SaaS. You will investigate and respond to potential data exfiltration events. Additionally, you will drive remediation and hardening based on real-world incidents and detections.

 

You will own the operational lifecycle of our DLP stack. It involves building and refining policies, partnering with stakeholders to validate business-safe controls, automating response playbooks, and turning signals from alerts and logs into durable security improvements. You will also contribute to adjacent security operations functions, including incident response and vulnerability management, where they intersect with data protection.

 

You will play a crucial role within the Security Engineering team, reporting directly to the Senior Manager, Security Engineering. This is a remote role.

Responsibilities:

    • Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling.

    • Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data.

    • Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements.

    • Build and refine automated response playbooks and workflows that enrich, triage, and respond to alerts, reducing manual effort and mean time to respond.

    • Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes.

    • Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners.

Qualifications:

    • Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP.

    • Direct, hands-on experience deploying, tuning, and operating

      • DLP tools (endpoint, network, SaaS, and/or cloud)

      • Cloud Access Security Broker (CASB) or similar SaaS security controls in a production environment.

      • DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel)

      • Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale.

      • Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types.

Pay:
 
The United States new hire base salary target ranges for this full-time position are:
 
Zone A: $128,130 - $180,990+ equity + benefits
Zone B: $140,943 - $199,089 + equity + benefits
Zone C: $153,756 - $217,188 + equity + benefits
Zone D: $166,569 - $235,287 + equity + benefits
 
This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones.
 
Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry.
 
Benefits & Perks:
 
In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more:
Remote-first culture
401(k) savings plan through Fidelity
Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
12 weeks of 100% Paid Parental leave
Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
Work-From-Home reimbursement to support team collaboration home office work
 
Your recruiter will share more about the salary range and benefits package for your role during the hiring process.

About Included Health

Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com.

-----
Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.

Similar Jobs

3 Days Ago
Remote
United States
133K-209K Annually
Senior level
133K-209K Annually
Senior level
Healthtech
Lead design and improvement of detection, alerting, incident response playbooks, and threat hunting. Drive investigations, digital forensics, AI-assisted automation, and cross-functional coordination to contain, eradicate, and prevent security incidents while measuring and improving SOC effectiveness.
Top Skills: Ai Platforms/ApisAWSAzureBashCis ControlsDigital ForensicsEdrGCPIso 27001Log ManagementMicrosoft SentinelMitre Att&CkNist 800-61PythonSIEMSoarSplunkXdr
3 Days Ago
Remote
United States
165K-205K Annually
Senior level
165K-205K Annually
Senior level
Blockchain • Energy • Cryptocurrency
Lead security assessments and controls across cloud-hosted applications, APIs, mobile (Flutter), CI/CD, and infrastructure. Implement and harden shared security tooling (dependency/secret/static/container scanning), review IAM and privileged access, support incident readiness and monitoring, evaluate SRE/recovery changes for security impact, and coordinate remediation with system owners. Establish security policies, automation, and review triggers to integrate practical controls into engineering workflows.
Top Skills: APIsCi/CdCloud SecurityContainer ScanningContainerized PlatformsDatabasesDependency ScanningFlutterIdentity And Access Management (Iam)Incident ResponseInfrastructure As CodeMonitoringSecret ScanningSre/Disaster RecoveryStatic AnalysisVulnerability Scanning
14 Hours Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
135K-228K Annually
Senior level
135K-228K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Lead detection, response, and digital forensics for security incidents. Monitor alerts, perform technical analysis, act as Incident Commander, build automation and runbooks, mentor engineers, and coordinate cross-team investigations and insider threat work.
Top Skills: AWSGCPLinuxmacOSPythonSIEMWindows

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account