Everlywell is a digital health company pioneering the next generation of biomarker intelligence—combining AI-powered technology with human insight to deliver personalized, actionable health answers. We transform complex biomarker data into life-changing insights—seamlessly integrating advanced diagnostics, virtual care, and patient engagement to reshape how and where health happens.
Over the past decade, Everlywell has delivered close to 1 billion personalized health insights, transforming care for 60 million people and powering hundreds of enterprise partners. In 2024 alone, an estimated 1 in 86 U.S. households received an Everlywell test, solidifying our spot as the #1 at-home testing brand in the country. And we’re just getting started. Fueled by AI and built for scale, we’re breaking down barriers, closing care gaps, and unlocking a more connected healthcare experience that is smarter, faster, and more personalized.
As a member of the security team at Everlywell, you will have the opportunity to shape the security detection, operations and incident response processes. You will research and discover the latest threats on product, cloud infrastructure, workloads, containers and develop methods, queries, and dashboards to detect and visualize events of interest. You will develop incident response playbooks to allow quick resolution of identified security events.You'll work across many teams including infrastructure, engineering, product, compliance, and across multiple streams. We’re looking for someone that has deep technical expertise in threat detection, incident root cause analysis, querying and alerting using SIEM systems, automation, AWS cloud, and the experience to join a fast-paced, growing team tackling challenging problems at scale.
Everlywell is a digital health company pioneering the next generation of biomarker intelligence—combining AI-powered technology with human insight to deliver personalized, actionable health answers. We transform complex biomarker data into life-changing insights—seamlessly integrating advanced diagnostics, virtual care, and patient engagement to reshape how and where health happens.Over the past decade, Everlywell has delivered close to 1 billion personalized health insights, transforming care for 60 million people and powering hundreds of enterprise partners. In 2024 alone, an estimated 1 in 86 U.S. households received an Everlywell test, solidifying our spot as the #1 at-home testing brand in the country. And we’re just getting started. Fueled by AI and built for scale, we’re breaking down barriers, closing care gaps, and unlocking a more connected healthcare experience that is smarter, faster, and more personalized.As a member of the security team at Everlywell, you will have the opportunity to shape the security detection, operations and incident response processes. You will research and discover the latest threats on product, cloud infrastructure, workloads, containers and develop methods, queries, and dashboards to detect and visualize events of interest. You will develop incident response playbooks to allow quick resolution of identified security events.You'll work across many teams including infrastructure, engineering, product, compliance, and across multiple streams. We’re looking for someone that has deep technical expertise in threat detection, incident root cause analysis, querying and alerting using SIEM systems, automation, AWS cloud, and the experience to join a fast-paced, growing team tackling challenging problems at scale.
What You'll Do:
Threat Detection: It's important to detect security incidents before they cause material damage to the business. You will detect attacks and prioritize, analyze and drive alerts to resolution. In the event an alert is identified as a security incident, you will kick off
Incident ResponseIncident Response: You will rapidly scope, contain and eradicate threats, minimizing financial, legal, business and content losses. Services include but are not limited to root-cause analysis, memory and disk forensics, reverse engineering, network containment, threat eradication and postmortems. You will also develop and refine processes, plans and procedures and partner closely with Legal, Comms and other stakeholders across the business.
Design and carry out security incident preparedness activities, such as compromise assessments and tabletop exercises, and conduct training and awareness sessions for relevant staff.
Deploy and support tools to collect and correlate security telemetry. Tooling includes Network Detection and Response, SIEM, Endpoint Detection and Response, Threat Intelligence platforms, and Security Orchestration Automation and Response tools.
Design and implement security controls across cloud, network, and application layers.
Drive the adoption of best practices for security through the SDLC
Build automated guardrails to enhance the security of our applications
Automate vulnerability management, secrets management, and patching.
AI first mindset for building out Security Automations and Threat Detection
Educate the engineering team on defensive coding
Support HIPAA, HITRUST, and SOC2 compliance efforts.
Work with Privacy and Compliance to document and monitor our security practices.
Partner with product engineering teams on secure cloud development practices and build security automation into CI/CD pipelines
Improve vulnerability management processes and security control maintenanceCollaborate with senior leaders to assess near-term and long-term security needs.
Collaborate with senior leaders to assess near-term and long-term security needs.
Who You Are:
Naturally curious and interested in security and privacy
Comfortable engaging with departments outside of engineering to heighten security
Experience with vulnerabilities, exploits, and their defenses
Can balance articulating the big picture and details depending on the audience
Eager and excited to evangelize security
Knowledge of Cybersecurity Frameworks: HITRUST, NIST, ISO
Collaborates well with cross functional team members: product, compliance, privacy, and engineering in a fast paced, regularly changing environment
Is most comfortable when there’s too much to do and can juggle a variety of tasks
Everyone knows that when you take on a task whether it’s huge and scary or tiny and boring, you’re going to see it through
What You've Done
BS (or equivalent) in Computer Science, Software Engineering, or related field.
5+ years of Experience with Cloud security (AWS, Azure, etc.)
Experience with secure SDLC best practices
Understanding of authentication protocols and frameworks (OAuth, SSO/SAML, OpenID, etc.)
DevOps and configuration management with tools like Terraform, Ansible, etc.
Estas cookies son necesarias para que el sitio web funcione y no se pueden desactivar en nuestros sistemas. Puede configurar su navegador para bloquear estas cookies, pero entonces algunas partes del sitio web podrían no funcionar.
Seguridad
Experiencia de usuario
Cookies orientadas al público objetivo
Estas cookies son instaladas a través de nuestro sitio web por nuestros socios publicitarios. Estas empresas pueden utilizarlas para elaborar un perfil de sus intereses y mostrarle publicidad relevante en otros lugares.
Google Analytics
Anuncios Google
Utilizamos cookies
🍪
Nuestro sitio web utiliza cookies y tecnologías similares para personalizar el contenido, optimizar la experiencia del usuario e indvidualizar y evaluar la publicidad. Al hacer clic en Aceptar o activar una opción en la configuración de cookies, usted acepta esto.
Los mejores empleos remotos por correo electrónico
¡Únete a más de 5.000 personas que reciben alertas semanales con empleos remotos!