Included Health

Staff Endpoint Security Engineer

Remote

Not SpecifiedCompensation
Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Health Tech, HealthcareIndustries

Staff Endpoint Security Engineer

Salary: [Not Specified] Location Type: Remote Employment Type: [Not Specified]

Position Overview

The Staff Endpoint Security Engineer is a critical, hands-on technical role responsible for designing, implementing, and maintaining robust security controls and detection mechanisms across all company and Bring-Your-Own-Device (BYOD) endpoints, including laptops, desktops, mobile phones, and other devices used by staff and contractors. This role is pivotal in protecting Included Health's sensitive data, particularly Protected Health Information (PHI), by preventing unauthorized exfiltration from endpoints and ensuring the security of devices accessing company resources. You will be instrumental in architecting and deploying advanced endpoint defenses, managing security tools, and contributing to threat response to reduce the number and criticality of HIPAA-related incidents. We are looking for deep technical expertise in endpoint security across diverse operating systems (Windows, macOS, ChromeOS, iOS, Android), strong automation skills for building and maintaining defenses, and a proactive approach to identifying and remediating vulnerabilities. This is a remote role reporting to the Chief Information Security Officer.

Responsibilities

  • Develop, implement, and maintain a comprehensive endpoint security strategy, architecture, and roadmap covering all corporate and BYOD endpoints, with a focus on proactive defense and detection engineering.
  • Design and enforce security configurations, hardening standards, and baselines for diverse operating systems (Windows, macOS, ChromeOS, iOS, Android, and potentially others) to minimize attack surfaces.
  • Lead the selection, deployment, administration, and optimization of endpoint security solutions, including Endpoint Detection and Response (EDR/XDR) for threat detection, Mobile Device Management (MDM/UEM) for policy enforcement, Data Loss Prevention (DLP) for data protection, anti-malware, and endpoint encryption.
  • Develop and implement robust DLP policies and controls to prevent PHI and other sensitive data from leaving authorized systems via endpoints.
  • Manage endpoint encryption technologies (e.g., BitLocker, FileVault, mobile encryption) to ensure data at rest is protected.
  • Proactively look for threats on endpoints to identify gaps in defenses and inform the development of new detection capabilities.
  • Support and provide expertise during incident response activities for endpoint-related security events, with a focus on root cause analysis to enhance preventative and detective controls.
  • Conduct vulnerability assessments, manage endpoint patching and remediation efforts to address identified weaknesses in a timely manner, strengthening overall endpoint resilience.
  • Develop, document, and enforce endpoint security policies, standards, and procedures, particularly for BYOD environments, ensuring compliance with HIPAA and other relevant regulations.
  • Automate endpoint security tasks, compliance checks, defensive measure deployments, and reporting using scripting languages (e.g., Python, PowerShell, Bash) and security orchestration tools.
  • Collaborate closely with IT operations, network security, application development, and legal/compliance teams to ensure a cohesive security posture and integrate endpoint defenses.
  • Provide expert consultation and support to end-users and IT staff on endpoint security matters and best practices.
  • Stay current with the latest endpoint threats, vulnerabilities, and security technologies to continuously improve our defenses.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of experience in endpoint security, with a strong emphasis on designing, building, implementing, and managing security controls, detection mechanisms, and defensive capabilities across a diverse range of endpoint operating systems (Windows, macOS, iOS, Android).
  • Proven hands-on experience with leading Endpoint Detection and Response (EDR/XDR) solutions (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint).
  • [Additional qualifications not fully provided in the original text]

Skills

Endpoint Security
EDR/XDR
MDM/UEM
DLP
Windows Security
macOS Security
ChromeOS Security
iOS Security
Android Security
Automation
Vulnerability Management
Security Architecture
Threat Detection
Data Loss Prevention
Mobile Device Management
Endpoint Encryption

Included Health

Healthcare advocacy and specialized care services

About Included Health

Included Health focuses on enhancing the healthcare experience for individuals who often face challenges in accessing quality care. The company provides a variety of services, including primary care, behavioral health, and virtual care, ensuring that members receive timely and appropriate treatment. Their model emphasizes 24/7 on-demand care with a diverse group of providers, allowing for personalized support tailored to complex health needs. Unlike many competitors, Included Health prioritizes underserved populations and partners with employers and consultants to deliver comprehensive healthcare solutions that not only improve health outcomes but also help reduce costs. The ultimate goal of Included Health is to make quality healthcare accessible and understandable for everyone, particularly those who have been overlooked by traditional healthcare systems.

San Francisco, CaliforniaHeadquarters
2020Year Founded
$337.5MTotal Funding
GROWTH_EQUITY_VCCompany Stage
HealthcareIndustries
51-200Employees

Benefits

Along with comprehensive medical, dental and vision plans; all employee spouses and children can access Included Health services at no cost. For time off, take it when you need it with our unaccrued discretionary time off for all exempt employees.

Risks

Competition from Teladoc and Amwell threatens market share.
Post-merger integration challenges could affect service delivery.
Regulatory scrutiny on telehealth may impact operational flexibility.

Differentiation

Included Health offers integrated primary and behavioral health services.
They provide 24/7 on-demand care with diverse providers.
Their data-driven approach enhances healthcare outcomes and reduces costs.

Upsides

Rising demand for telehealth boosts Included Health's virtual care services.
Employers investing in healthcare benefits expand Included Health's client base.
Value-based care models align with Included Health's focus on outcomes.

Land your dream remote job 3x faster with AI