Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Security Engineer image - Rise Careers
Job details

Principal Security Engineer

Nursa is a healthcare platform that directly addresses the severe staffing challenges confronting the U.S. healthcare system by connecting qualified registered nurses (RNs), licensed practical nurses (LPNs), and certified nursing assistants (CNAs) seeking flexible work with facilities in need of help. Founded in 2019, we are a growing venture backed startup whose mission is to put a nurse at the bedside of every patient in need. With your help, we will be able to enrich the lives of nurses and be a valued partner in delivering effective, compassionate patient care in every market we serve.

Job Summary:

We are seeking an experienced and dynamic Principal Security Engineer to join our team. In this role, you will play a critical part in shaping and executing our security strategy, ensuring that our platform, infrastructure, and data are protected from evolving threats. You will work closely with cross-functional teams including engineering, product, and compliance to implement security best practices and maintain compliance with healthcare and technology regulations and standards.

This role is an individual contributor role that requires strong leadership capabilities. It has a likelihood to grow into a management role.

Key Responsibilities:

  • Security Architecture & Design: Lead the design, implementation, and evaluation of security architecture to protect the platform, data, and systems across our cloud-based infrastructure. 

  • Vulnerability Management: Facilitate regular vulnerability assessments, penetration testing, and security audits. Proactively address identified risks or weaknesses in the system.

  • Incident Response: Lead the investigation and response to security incidents, providing analysis, root cause identification, and implementing corrective actions.

  • Compliance & Risk Management: Ensure the company’s security posture aligns with industry regulations and standards (e.g. SOC) and support audits and certifications as necessary.

  • Security Best Practices: Develop, document, and enforce security policies, guidelines, and procedures across engineering, product, and IT teams. Prepare and present regular reports to executive management highlighting key security metrics, risks, and remediation efforts.

  • Collaboration & Mentorship: Work closely with engineers, DevOps, and IT teams to integrate security into the development lifecycle (DevSecOps). 

  • Threat Intelligence: Stay ahead of emerging security threats and vulnerabilities, analyzing industry trends and incorporating proactive measures into the security framework.

  • Cloud Security: Ensure the security of cloud-based services, primarily GCP, by configuring security controls, access management, and ensuring secure deployment practices.

Required Qualifications:

This role requires the ability to operate independently while working collaboratively. Self awareness and open communication will be crucial in prioritizing effectively. 

  • Education: Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience).

  • Experience: 5+ years of experience in information security, with at least 2 years in a senior or leadership role, preferably within healthcare, fintech, or regulated industries.

  • Certifications: CISSP, CISM, or similar industry-standard security certifications preferred.

  • Technical Skills:

    • Cloudflare Expertise: Proven experience in configuring and managing Cloudflare services for securing web applications, DDoS protection, WAF (Web Application Firewall), DNS management, and CDN performance optimization.

    • Robust experience in securing cloud environments (AWS, Azure, GCP).

    • Proficiency in network security, cryptography, and identity and access management (IAM).

    • Familiarity with common web application vulnerabilities (OWASP Top 10) and mitigation strategies.

    • Proficient in security tools and frameworks (e.g., intrusion detection, SIEM, firewalls, endpoint protection).

    • Familiarity with containerization technologies (Docker, Kubernetes) and securing containerized applications.

  • Communication: Excellent written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical stakeholders.

What you get in return:

  • Opportunity to revolutionize healthcare industry and build both relationships and teams that make a tangible impact 

  • We empower team members to act intelligently and be owners, believing that execution is everything, and have designed a learning-focused environment where you get ongoing support and regular feedback to help you grow

  • An opportunity to join an international team with a work culture that is based on trust, flexibility, and curiosity

  • Competitive salary and benefits

Closing:

Nursa is an equal opportunity employer. We aim to build a workforce of individuals from different backgrounds, with different abilities, identities, and mindsets. Even if you do not meet all of the qualifications listed above, we encourage you to apply!

Nursa Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Nursa DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Nursa
Nursa CEO photo
Curtis Anderson
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Security Engineer, Nursa

Nursa is on a mission to enhance healthcare staffing by connecting dedicated nurses with facilities in need. As we expand, we're excited to welcome a Principal Security Engineer to our team in Murray. This pivotal role involves creating and executing a robust security strategy, ensuring our platform and data are safe from threats. You'll collaborate with various teams, including engineering and product, to implement best practices and uphold compliance with regulations. This isn't just a role; it's an opportunity to shape the future of healthcare IT while enriching the lives of nurses. From designing security architecture to managing vulnerabilities and incident responses, your expertise will be crucial in providing effective and compassionate patient care. This individual contributor position offers great growth potential into a managerial role. If you have over five years of experience in information security, particularly in healthcare or regulated sectors, and a passion for security best practices, we invite you to apply! At Nursa, every team member matters, and we appreciate the diverse perspectives that help us revolutionize healthcare. Join us for a unique opportunity that blends innovation, collaboration, and the chance to make a tangible difference in the world of healthcare.

Frequently Asked Questions (FAQs) for Principal Security Engineer Role at Nursa
What are the key responsibilities of a Principal Security Engineer at Nursa?

As a Principal Security Engineer at Nursa, your key responsibilities include leading the design and implementation of security architectures, conducting regular vulnerability assessments, responding to security incidents, ensuring compliance with industry regulations, and fostering a security-aware culture across engineering and IT teams. You'll also be expected to stay updated on emerging threats and manage cloud security effectively.

Join Rise to see the full answer
What qualifications are needed for the Principal Security Engineer position at Nursa?

The Principal Security Engineer role at Nursa requires a Bachelor's degree in Computer Science, Information Security, or a related field, complemented by at least five years of experience in information security, with two years in a leadership role. Preferred certifications include CISSP, CISM, or similar. Strong technical skills in managing cloud environments, security tools, and communication are essential.

Join Rise to see the full answer
How does Nursa approach compliance and risk management for technical security?

Nursa prioritizes compliance by aligning its security posture with industry standards like SOC. As a Principal Security Engineer, you will ensure effective risk management by facilitating security audits, maintaining documentation of security policies, and preparing reports that highlight security metrics and remediation efforts for executive management.

Join Rise to see the full answer
What kind of work culture can a Principal Security Engineer expect at Nursa?

At Nursa, we cultivate a work environment rooted in trust, flexibility, and curiosity. As a Principal Security Engineer, you will be part of an international team that values your insights and encourages ownership of your work, providing ample opportunities for personal and professional growth in an innovative atmosphere.

Join Rise to see the full answer
How can one apply for the Principal Security Engineer role at Nursa?

Interested candidates can apply for the Principal Security Engineer position at Nursa by submitting their resume and cover letter through our careers page. We encourage applicants from diverse backgrounds, even if they do not meet all listed qualifications, to apply and join our mission in revolutionizing healthcare staffing.

Join Rise to see the full answer
Common Interview Questions for Principal Security Engineer
Can you describe your experience with cloud security in a Principal Security Engineer role?

When answering this question, it's essential to showcase specific experiences managing cloud environments, detailing the security measures you implemented and any challenges you faced. Highlight your knowledge in securing platforms like GCP and your approach to compliance with best practices.

Join Rise to see the full answer
How do you manage incidents and vulnerabilities within a cloud-based infrastructure?

In your response, discuss your process for conducting vulnerability assessments, how you prioritize incidents, and any frameworks or tools you employ for incident response and remediation. A structured approach will demonstrate your competence in handling security incidents effectively.

Join Rise to see the full answer
What security standards and regulations do you adhere to in healthcare security?

You should mention industry standards such as HIPAA, SOC, and others relevant to healthcare. Sharing examples of how you ensure compliance with these regulations in your previous roles will reinforce your qualifications for the Principal Security Engineer position.

Join Rise to see the full answer
Explain your experience with developing security policies and procedures.

Highlight any prior experience in creating or updating security policies. Discuss how you engage stakeholders to ensure that the policies are practical and aligned with business objectives while also emphasizing the importance of training and awareness among teams.

Join Rise to see the full answer
How do you keep up with emerging security threats and trends?

Focus on your strategies for continuous learning, such as attending conferences, participating in webinars, or following industry publications. You can also mention communities you engage with to stay informed about the latest security developments relevant to your role.

Join Rise to see the full answer
What experience do you have working with cross-functional teams?

Provide specific examples of projects or initiatives where you collaborated with engineering, product, or compliance teams. Discuss your approach to fostering communication and establishing security practices that integrate smoothly into the development lifecycle.

Join Rise to see the full answer
Can you provide an example of a significant security incident you managed?

Share a detailed but concise incident-related example, emphasizing your role, the analysis process, the corrective actions you took, and the lessons learned. This illustrates your hands-on experience and ability to respond effectively under pressure.

Join Rise to see the full answer
What tools and technologies do you find most effective for cloud security?

List specific tools like Cloudflare, intrusion detection systems, SIEM, or firewalls you have experience with. Elaborate on why you find them effective and how they contribute to maintaining a secure cloud environment in previous roles.

Join Rise to see the full answer
Describe a time when you had to explain complex security issues to non-technical stakeholders.

Illustrate this by describing your approach: how you simplified the information, what communication strategy you used, and the outcome of the interaction. Emphasizing your communication skills will show you can bridge the gap between technical and non-technical teams.

Join Rise to see the full answer
What do you believe is the biggest challenge facing security in the healthcare sector today?

Discuss current challenges such as data privacy, regulatory compliance, or rising cyber threats. It's crucial to express your passion for tackling these challenges and how you envision contributing to solutions in the Principal Security Engineer position.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Mission Driven
Empathetic
Collaboration over Competition
Transparent & Candid
Growth & Learning
Customer-Centric
Medical Insurance
Dental Insurance
Vision Insurance
Health Savings Account (HSA)
Mental Health Resources
Equity
Maternity Leave
Paternity Leave
Paid Time-Off
Life insurance
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 6 hours ago
Photo of the Rise User
ServiceNow Remote America Free Zone North Plaza Real Cariari, C. Domingueños 600 America Free Zone, Heredia, Heredia, Costa Rica
Posted 10 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
Nexthink Remote Bengaluru, Karnataka, India
Posted 12 days ago
Photo of the Rise User
Posted 4 days ago

Reimagining the healthcare staffing industry by connecting clinicians and facilities directly to improve patient care.

68 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Mission Driven
Empathetic
Collaboration over Competition
Transparent & Candid
Growth & Learning
Customer-Centric
BENEFITS & PERKS
Medical Insurance
Dental Insurance
Vision Insurance
Health Savings Account (HSA)
Mental Health Resources
Equity
Maternity Leave
Paternity Leave
Paid Time-Off
Life insurance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 31, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!