Sr. Security Engineer

Sorry, this job was removed at 10:54 p.m. (PST) on Tuesday, Aug 13, 2024
Be an Early Applicant
Hiring Remotely in USA
Remote
135K-155K Annually
7+ Years Experience
Beauty • Consumer Web • eCommerce • Healthtech • Telehealth
Taking care of yourself doesn’t need to involve a doctor’s waiting room.
The Role

Hims & Hers Health, Inc. (better known as Hims & Hers) is the leading health and wellness platform, on a mission to help the world feel great through the power of better health. We are revolutionizing telehealth for providers and their patients alike. Making personalized solutions accessible is of paramount importance to Hims & Hers and we are focused on continued innovation in this space. Hims & Hers offers nonprescription products and access to highly personalized prescription solutions for a variety of conditions related to mental health, sexual health, hair care, skincare, heart health, and more.

Hims & Hers is a public company, traded on the NYSE under the ticker symbol “HIMS”. To learn more about the brand and offerings, you can visit hims.com and forhers.com, or visit our investor site. For information on the company’s outstanding benefits, culture, and its talent-first flexible/remote work approach, see below and visit www.hims.com/careers-professionals.

As a Senior Security Engineer, you will be a thought leader in the Security Team focused on helping design, implement, and mature innovative and cutting-edge security capabilities. Senior Security Engineer ensures defense-in-depth, provides hands-on technical leadership for security domains, assists with defining vision and execution of strategy aligning to business needs, and is also expected to help solve a wide range of security challenges. The Senior Security Engineer is part of a highly collaborative security program and an engineering culture-driven technology organization.

  • Ownership of security scanning complex (SAST, SCA, DAST, etc.)  
  • Develop and promote security architecture and design strategies, frameworks, and patterns while collaborating closely with engineering, and product organization
  • Actively partner with stakeholders to understand business requirements and develop supporting security and resiliency principles to ensure the adoption of industry best practices
  • Ensure information security and regulatory requirements are effectively integrated into new or improved systems
  • Demonstrates expert technology competence in security domains including but not limited to application, cloud, resiliency, identity, access management, and data security
  • Establish credibility among technology experts as the subject matter expert across security disciplines
  • Review and influence the security of vendor applications and systems to ensure they meet our security objectives and can be implemented securely
  • Analyze technical risks of existing systems and applications against correlating policies and risks, and provide appropriate remediation or risk reduction plans
  • Participate in the design and execution of vulnerability assessments, red team /penetration tests, security audits, and cybersecurity exercises
  • Define, publish, and implement Security Standards / Frameworks
  • Effectively communicates across departments and leadership groups and builds consensus in support of strategic objectives
  • Establish a security vision and roadmap while ensuring it aligns with the cybersecurity strategy, enterprise business and technology strategy, and industry trends.
  • Mentor and guide engineering teams on security best practices
  • Serve as a champion for secure SDLC and secure cloud adoption
  • Threat modeling, end-to-end security evaluation

  • Bachelor's degree in Computer Science, Engineering, Information Systems, or equivalent background or experience
  • 8+ years of relevant technical experience
  • 5+ years of security experience
  • Prior experience with Mobile and API security
  • Deep understanding of the Twelve-Factor App methodology
  • Prior experience working with cloud-based platforms (AWS, Azure, GCP) in an enterprise environment
  • Prior experience with security scanning tools (SAST, DAST, SCA, etc.), PEN Testing, and the Bug Bounty program
  • Prior experience in the healthcare industry including a strong understanding of HIPAA Privacy and Security Rules preferred
  • Experience in the IAM domain including tools (Okta, Centrify, CyberArk, Ping) preferred
  • Significant experience with Java/Kotlin, JavaScript, web services (REST/SOAP), and modern development and delivery techniques
  • Strong knowledge of authentication and authorization industry standards such as SAML, OpenID, OAuth2
  • CISSP, CCSP,  and AWS Cloud certification desirable
  • Experience developing solutions in an iterative (Agile) approach and hands-on knowledge of DevSecOps practices 

  • Competitive salary & equity compensation for full-time roles
  • Unlimited PTO, company holidays, and quarterly mental health days
  • Comprehensive health benefits including medical, dental & vision, and parental leave
  • Employee Stock Purchase Program (ESPP)
  • Employee discounts on hims & hers & Apostrophe online products
  • 401k benefits with employer matching contribution
  • Offsite team retreats




Outlined below is a reasonable estimate of H&H’s compensation range for this role for . If you're based outside of the US, your recruiter will be able to provide you with an estimated salary range for your location.
The actual amount will take into account a range of factors that are considered in making compensation decisions including but not limited to skill sets, experience and training, licensure and certifications, and location. H&H also offers a comprehensive Total Rewards package that may include an equity grant.
Consult with your Recruiter during any potential screening to determine a more targeted range based on location and job-related factors.

An estimate of the current salary range for US-based employees is

$135,000$155,000 USD

The Company
San Francisco, CA
205 Employees
Remote Workplace
Year Founded: 2017

What We Do

Hims and Hers offers a modern approach to health and wellness. Our mission is to eliminate stigmas and make it easier for people to access care and treatment for the conditions that impact their daily lives. That starts with creating an open and honest culture of care that is accessible for everyone, no matter who you are or where you live.

Why Work With Us

Our mission is to make it easier for people to access care and treatment for the conditions that impact their day-to-day lives, whether that involves finding the right birth control, addressing hair loss or skincare issues, or treating low libido. We’re searching for talented, high-performing, and passionate people to join our growing team!

Gallery

Gallery

Similar Companies Hiring

Whatnot Thumbnail
Sports • Mobile • Fashion • eCommerce
US
500 Employees
Headway Thumbnail
Software • Social Impact • Professional Services • Healthtech • Consumer Web
San Francisco, CA
504 Employees
Resident Thumbnail
Retail • Manufacturing • eCommerce
San Francisco, CA
322 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account