Security Engineer
Cala Health · San Mateo, CA
About this role
**About Cala** At Cala, we’re working to free people from the burden of chronic disease. We began by creating the first non-invasive prescription therapy for hand tremor, and after years of fine-tuning and improvements, we released Cala kIQ—our most sophisticated therapy yet. Our technology is being applied across neurology, cardiology, and more. **The Opportunity: Security Engineer** Join our cybersecurity team as a **Security Engineer**. You’ll safeguard our digital assets, infrastructure, and applications—identifying vulnerabilities, managing risk, orchestrating incident response, and helping build a strong security culture across engineering. **Location / Reporting / Employment** - **Title:** Security Engineer - **Reports to:** Staff DevOps Engineer - **Location:** Remote (or Hybrid if local to San Mateo, CA headquarters) - **Employment type:** Full-Time, Exempt - **Pay range:** $155,000 - $190,000 --- ## A Day in the Life ### Vulnerability & Dependency Management - Monitor and manage open-source and third-party dependencies using **Software Composition Analysis (SCA)** tools to mitigate supply chain risks. - Track and prioritize **CVEs** affecting our tech stack. - Collaborate with development teams to automate dependency updates and integrate security scanning into **CI/CD**. ### Penetration Testing & Vulnerability Assessment - Own end-to-end scope, execution, and tracking of external penetration tests and bug bounty programs. - Analyze reports, validate findings, and translate vulnerabilities into actionable remediation plans. - Conduct internal vulnerability scanning and architectural risk assessments. ### Security Remediation & Engineering - Own and drive security remediation across infrastructure, networks, and applications. - Provide hands-on technical guidance and code/configuration reviews to support secure development. - Implement security controls and guardrails (e.g., **IAM policies**, **network segmentation**, **secrets management**) to reduce attack surface. ### Incident Response & Threat Hunting - Participate in an **on-call rotation** as a core member of the Incident Response (IR) team. - Investigate potential breaches using security logs (**SIEM, EDR, cloud provider logs**). - Run post-incident reviews (root-cause analysis) and document lessons learned. ### Resilience & Preparedness (Tabletop Exercises) - Design, facilitate, and execute regular security tabletop exercises for technical teams and executive leadership. - Develop realistic threat scenarios (e.g., ransomware, supply chain attacks) to test incident response plans and identify gaps. ### Additional Responsibilities - **Cloud Security Posture Management (CSPM):** Monitor and secure AWS/GCP configurations to prevent drift and misconfigurations. - **Security Metrics & Reporting:** Define and report KPIs such as **MTTR** and patch compliance. - **Compliance Support:** Help gather evidence and maintain controls for frameworks/certifications (e.g., **SOC 2, ISO 27001, HIPAA**). - **Security Awareness:** Mentor junior engineers and create targeted security training content. --- ## Qualifications & Skills ### Required Experience - **3+ years** in Security Engineering, Application Security, or Incident Response. - Hands-on experience with modern security tooling (e.g., **Snyk, Dependabot, Burp Suite, Splunk, Datadog**). - Strong understanding of **OWASP Top 10**, **CWE**, and cloud security best practices. - Hands-on CI/CD and build automation experience
Listing freshness
CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.