Cala Health logo
Cala Health
Posted 34 days agoVerified live 1d ago

Security Engineer

Brief overview

Remote
$155k–$190k/yrStated range
Sponsors visasStated in posting
Security EngineeringApplication SecurityIncident ResponseVulnerability ManagementPenetration TestingSoftware Composition AnalysisOWASP Top 10CI/CD PipelinesPythonBash ScriptingCloud SecurityAWS/GCP

About the company

Cala Health logo
Cala Healthcalahealth.com

Cala Health is a bioelectronic medicine company that develops wearable neuromodulation devices for the treatment of chronic diseases.

Job description

Summary

Cala Health develops non-invasive prescription therapies to help people manage chronic disease. The Security Engineer will safeguard digital assets, infrastructure, and applications by managing vulnerabilities, conducting penetration testing, driving remediation, responding to incidents, and strengthening security preparedness and awareness.

Responsibilities

  • Monitor and manage open-source and third-party dependencies using Software Composition Analysis (SCA) tools to identify and mitigate supply chain risks
  • Track and prioritize Common Vulnerabilities and Exposures (CVEs) affecting our tech stack
  • Collaborate with development teams to automate dependency updates and integrate security scanning into the CI/CD pipeline
  • Manage end-to-end scope, execution, and tracking of external Penetration Tests and bug bounty programs
  • Analyze penetration testing reports, validate findings, and translate complex technical vulnerabilities into actionable remediation plans for engineering teams
  • Conduct internal vulnerability scanning and architectural risk assessments
  • Own and drive security remediation tasks across infrastructure, networks, and applications
  • Provide hands-on technical guidance and code/configuration reviews to developers to ensure secure coding practices are met
  • Implement security controls and guardrails (e.g., IAM policies, network segmentation, secrets management) to proactively reduce our attack surface
  • Serve as a core member of the Incident Response (IR) team, participating in an on-call rotation to detect, contain, and eradicate security incidents
  • Analyze security logs (SIEM, EDR, cloud provider logs) to investigate potential breaches or anomalous behavior
  • Conduct post-incident reviews (root-cause analysis) and document lessons learned to continuously harden our defenses
  • Design, facilitate, and execute regular security tabletop exercises for both technical teams and executive leadership
  • Develop realistic threat scenarios (e.g., ransomware, supply chain attacks) to test the efficacy of our incident response plans and identify gaps in communication or tooling
  • Cloud Security Posture Management (CSPM): Monitor and secure cloud infrastructure (AWS/GCP) configurations to prevent drift and misconfigurations
  • Security Metrics & Reporting: Define, track, and report on key security performance indicators (KPIs) like Mean Time to Remediate (MTTR) and patch compliance
  • Compliance Support: Assist in gathering evidence and maintaining controls for security frameworks and certifications (e.g., SOC 2, ISO 27001, HIPAA)
  • Security Awareness: Champion a security-first culture by mentoring junior engineers and creating targeted security training content

Skills

  • Bachelor's degree in Computer Science, Software Engineering, or a related technical field
  • 3+ years of experience in Security Engineering, Application Security, or Incident Response
  • Hands-on experience with modern security tooling (e.g., Snyk, Dependabot, Burp Suite, Splunk, Datadog)
  • Strong understanding of OWASP Top 10, CWE, and cloud security best practices
  • Hands-on experience with CI/CD pipelines and build automation tools (e.g., Jenkins, GitHub Actions, GitLab CI) to integrate security scanning and controls
  • Proficiency in Python and Shell scripting (Bash) to automate security workflows and build security tooling
  • Applicants must be authorized to work in the United States on a full-time basis, or eligible for work authorization through a sponsorship path that Cala Health is able to support
  • Familiarity with additional programming languages such as Go, JavaScript/TypeScript, or Rust for deeper code reviews and custom tooling
  • Experience securing cloud-native environments (Docker, AWS/GCP) and native AWS security tools (AWS Inspector, GuardDuty)
  • Hands-on experience with GRC platforms (e.g., Vanta)
  • Familiarity with Infrastructure as Code (IaC) security scanning (e.g., Checkov, TFLint)
  • Relevant industry certifications (e.g., CISSP, CEH, OSCP, GCIH, AWS Certified Security)
  • Excellent communication skills with the ability to articulate technical security concepts to non-technical stakeholders
  • Familiarity with bug bounty services like BugCroud
  • Experience working on cloud connected IoT devices (provisioning, key rotation, OTA update security)

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Software Engineering, or a related technical field
  • 3+ years of experience in Security Engineering, Application Security, or Incident Response
  • Hands-on experience with modern security tooling (e.g., Snyk, Dependabot, Burp Suite, Splunk, Datadog)
  • Strong understanding of OWASP Top 10, CWE, and cloud security best practices
  • Hands-on experience with CI/CD pipelines and build automation tools (e.g., Jenkins, GitHub Actions, GitLab CI) to integrate security scanning and controls
  • Proficiency in Python and Shell scripting (Bash) to automate security workflows and build security tooling
  • Applicants must be authorized to work in the United States on a full-time basis, or eligible for work authorization through a sponsorship path that Cala Health is able to support

Nice to Haves

  • Familiarity with additional programming languages such as Go, JavaScript/TypeScript, or Rust for deeper code reviews and custom tooling
  • Experience securing cloud-native environments (Docker, AWS/GCP) and native AWS security tools (AWS Inspector, GuardDuty)
  • Hands-on experience with GRC platforms (e.g., Vanta)
  • Familiarity with Infrastructure as Code (IaC) security scanning (e.g., Checkov, TFLint)
  • Relevant industry certifications (e.g., CISSP, CEH, OSCP, GCIH, AWS Certified Security)
  • Excellent communication skills with the ability to articulate technical security concepts to non-technical stakeholders
  • Familiarity with bug bounty services like BugCroud
  • Experience working on cloud connected IoT devices (provisioning, key rotation, OTA update security)

Benefits

  • Applicants must be authorized to work in the United States on a full-time basis, or eligible for work authorization through a sponsorship path that Cala Health is able to support.
  • Remote, Hybrid if local to our San Mateo, CA headquarters
  • We offer all employees the tools, training and mentoring they need to succeed.

More jobs like this