Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Sr. Security Engineer (Remote) image - Rise Careers
Job details

Sr. Security Engineer (Remote)

We believe that mental health is just as important as physical health. We recognize that mental health issues can be complex and multifaceted, and we are dedicated to treating the whole person, not just the symptoms.

We aim to create a world where mental health is no longer stigmatized or marginalized, but rather is embraced as an integral part of one's overall well-being. 

We believe that by providing quality care that is both evidence-based and compassionate, we can empower individuals to take charge of their mental health and achieve their full potential. We are passionate about making a positive impact on the lives of those struggling with mental health issues and we strive to be a force for positive change in the field of mental healthcare.

About the Engineering Team

Join our Engineering Team and shape the future of healthcare technology! Our dedicated team is revolutionizing mental healthcare with comprehensive Provider and Patient Portals, empowering providers and patients alike. As we transition to a Service-Oriented Architecture (SOA), you'll play a key role in reshaping our systems, ensuring agility and scalability. In our event-driven architecture, we're navigating challenges to protect sensitive data. With the introduction of GraphQL, a Centralized Component Library, and an Authorization Service, you'll be part of our innovative strides. Join us in shaping healthcare's future and making a difference!

About the Role

The Security Team at Rula is responsible for ensuring the protection of patient data and all of the technology behind our platform. We maintain close partnerships with Engineering and Product teams, but interface with everyone across the company to ensure that security is an organic and adopted element of our culture. In this role, you’ll have the opportunity to enhance the security of our code and development practices, and launch a vulnerability management program with Engineering and external partners. Overall, you’ll encounter endless learning opportunities and pursue projects that will leverage and refine your skills. More importantly, the work you do will help ensure the best outcomes for patients as we strive to make mental healthcare work for everyone.

Required Qualifications

  • 4+ years of experience as a security engineer (any role)

  • Experience with JavaScript, TypeScript, Node.js, and/or Ruby

  • Experience with OWASP Top 10 and the application of those to modern systems

  • Experience with common SAST and DAST tooling and best practices

Preferred Qualifications

  • Experience launching and/or managing a bug bounty program

  • A functional understanding of HIPAA requirements and how they apply to application security practices

  • Experience with Web Application Firewall (WAF) tuning and alerting

  • Familiarity with JS front-end libraries, preferably React

  • Experience interfacing with 3rd party pentesters to validate findings and develop remediation plans

Technical Stack

Rula's systems are written in Typescript/Node.js or Ruby on Rails, with React frontends. We use Postgres for our databases and everything is hosted on AWS. We also make heavy use of existing tools like Salesforce, Airtable, Typeform, etc. This has enabled us to scale very quickly with a small team but we’re now ready to bring much of this work in-house. We’re standing up the technical foundation that will power the future of the company. It doesn’t matter if you don’t have experience with the specific technologies in our stack, we’d still love to connect with you! 

We're serious about your well-being! As part of our team, full-time employees receive:

  • 100% remote work environment: Working hours to support a healthy work-life balance, ensuring you can meet both professional and personal commitments

  • Attractive pay and benefits: Full transparency of pay ranges regardless of where you live in the United States

  • Comprehensive health benefits: Medical, dental, vision, life, disability, and FSA/HSA

  • 401(k) plan access: Start saving for your future

  • Generous time-off policies: Including 2 company-wide shutdown weeks each year for self-care (for most employees)

  • Paid parental leave: Available for all parents, including birthing, non-birthing, adopting, and fostering

  • Employee Assistance Program (EAP): Support for your mental and physical health

  • New hire home office stipend: Set up your workspace for success

  • Quarterly department stipend: Fund team-building activities or in-person gatherings

  • Wellness events and lunch & learns: Explore a variety of engaging topics

  • Community and employee resource groups: Participate in groups that celebrate employee identity and lived experiences, fostering a sense of community and belonging for all

  • Discounted programs: Fetch, SmartSpend, Ladder, SoFi

Our team

We believe that diversity, equity, and inclusion are fundamental to our mission of making mental healthcare work for everyone.  We are dedicated to having a culture of inclusion that will support our employees in feeling safe, seen, heard, and valued.

Rula Glassdoor Company Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Rula DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Rula
Rula CEO photo
Unknown name
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr. Security Engineer (Remote), Rula

Welcome to Rula, where we are on a mission to revolutionize mental healthcare with technology! We are looking for a passionate and experienced Sr. Security Engineer to join our innovative Engineering Team based in Los Angeles (remote work welcomes applicants from anywhere). If you have a knack for protecting sensitive data and securing robust systems, this position might just be your perfect fit! At Rula, we believe that mental health care is as critical as physical health, and our aim is to make a positive impact on the lives of those we serve. As a Sr. Security Engineer, you’ll play a vital role in maintaining the security of our platforms, ensuring that both Provider and Patient Portals operate safely and efficiently. You'll work closely with various teams across the company, leading programs to bolster security in every facet of our operations. If you have over four years in the security engineering space and knowledge of modern technologies like JavaScript, TypeScript, Node.js, and Ruby, we'd love to hear from you! Join us, and you’ll not only enhance your own skills but contribute meaningfully to a project that truly matters. At Rula, we support your well-being with 100% remote work options, comprehensive health benefits, and generous time-off policies designed to help you thrive both professionally and personally.

Frequently Asked Questions (FAQs) for Sr. Security Engineer (Remote) Role at Rula
What skills are required for the Sr. Security Engineer position at Rula?

To apply for the Sr. Security Engineer role at Rula, you should have over four years of experience in security engineering. Familiarity with JavaScript, TypeScript, Node.js, and Ruby is essential. Additionally, being well-versed with the OWASP Top 10 and common SAST and DAST tooling will benefit you greatly in this position, as you’ll be enhancing our security practices and managing vulnerabilities.

Join Rise to see the full answer
What does a typical day look like for a Sr. Security Engineer at Rula?

As a Sr. Security Engineer at Rula, you can expect a dynamic workday filled with collaboration across departments. You will engage with Engineering and Product teams to integrate security deeply into our culture. Your tasks may range from enhancing code security to launching vulnerability management programs. Each day brings new learning opportunities as you navigate the challenges in protecting sensitive mental health data.

Join Rise to see the full answer
Is prior experience with specific technologies necessary for the Sr. Security Engineer role at Rula?

While specific experience with Rula’s technical stack, which includes Typescript/Node.js and Ruby on Rails, is preferred, it’s not mandatory. Rula values potential and willingness to learn just as much as prior experience, so if you possess strong core security skills, you’re encouraged to apply and connect with us.

Join Rise to see the full answer
What are the benefits of working as a Sr. Security Engineer at Rula?

Working as a Sr. Security Engineer at Rula comes with numerous perks, including a fully remote work environment that promotes work-life balance, comprehensive health benefits like medical and dental coverage, and a generous time-off policy including company-wide shutdowns for self-care. Additionally, you’ll find a supportive culture that celebrates diversity and community.

Join Rise to see the full answer
What impact does the Sr. Security Engineer role at Rula have on mental health services?

The Sr. Security Engineer role at Rula significantly impacts mental health services by ensuring the protection of sensitive patient data and fostering a secure environment for both providers and patients. Your efforts in securing our platforms will help create a trusted space where individuals can seek the mental health care they need.

Join Rise to see the full answer
How does Rula support the professional development of the Sr. Security Engineer?

At Rula, we highly value professional development and offer numerous learning opportunities for our Sr. Security Engineer. Through innovative projects tailored to your role, collaboration with talented teams, and opportunities for further training and growth, we ensure that your career continues to thrive while contributing to our mission.

Join Rise to see the full answer
How does Rula prioritize well-being in its workplace culture for Sr. Security Engineers?

Rula prioritizes well-being by fostering a supportive and inclusive workplace culture where mental health is recognized as essential. We offer paid parental leave, an Employee Assistance Program, regular wellness events, and a unique new hire home office stipend for creating a conducive work environment—all aimed at helping you maintain balance in your professional journey.

Join Rise to see the full answer
Common Interview Questions for Sr. Security Engineer (Remote)
Can you explain your experience with SAST and DAST security tools?

When discussing your experience with SAST and DAST tools, emphasize the specific tools you've used and how you applied them in past projects to identify vulnerabilities. Highlight your understanding of how these tools can integrate into the development pipeline and contribute to a culture of security throughout the organization.

Join Rise to see the full answer
How do you stay updated on the latest security threats and vulnerabilities?

In interviews, convey your proactive approach to staying informed about security threats. Discuss following industry thought leaders, subscribing to security newsletters, participating in relevant forums, and attending conferences. This shows your commitment to continuous learning and adapting based on evolving security landscapes.

Join Rise to see the full answer
What approach do you take when identifying security risks in a new application?

When asked about identifying security risks, you should explain your systematic approach—beginning with threat modeling and a comprehensive understanding of the application architecture, followed by utilizing SAST and DAST tools to evaluate the code. Detailed examples of past experiences will lend credibility to your approach.

Join Rise to see the full answer
Describe your experience with OWASP Top 10 vulnerabilities.

Provide a clear explanation of the OWASP Top 10 vulnerabilities by discussing each one briefly and detailing your experience in mitigating them. Share specific instances where you successfully addressed these vulnerabilities in past projects, demonstrating both technical proficiency and problem-solving skills.

Join Rise to see the full answer
How would you handle a security breach in a system?

In addressing this question, outline your immediate steps for containment and damage control, followed by a thorough investigation to understand the breach's source. Discuss creating a remediation plan to address the vulnerabilities and measures to prevent future occurrences, showcasing your leadership and crisis management skills.

Join Rise to see the full answer
Can you detail a successful security project you led?

Highlight a particular security project that you led, focusing on your leadership role, the challenges faced, results achieved, and how it impacted the overall security posture. Use metrics where possible to show the project's success, effectively demonstrating your abilities and contributions to security initiatives.

Join Rise to see the full answer
What tools or practices do you recommend for effective code reviews?

Share your insight on best practices for effective code reviews, mentioning security-focused tools that facilitate this process, such as automated code scanning tools, and the importance of establishing a culture of security awareness among the development teams. Highlight your personal experiences and the outcomes when incorporating these practices.

Join Rise to see the full answer
How do you communicate security issues to non-technical stakeholders?

Discuss techniques for communicating security issues to non-technical stakeholders, emphasizing the importance of using clear, jargon-free language, visual aids, and relatable analogies to enable understanding. Providing examples of previous experiences where you effectively communicated complex security concepts will demonstrate your communication skills.

Join Rise to see the full answer
What steps would you take to launch a vulnerability management program?

When addressing this, outline the key steps you would take to develop a vulnerability management program, starting from establishing a team, conducting risk assessments, and selecting appropriate tools and processes for scanning and remediation. Your organized approach will reflect your strategic thinking and experience in security management.

Join Rise to see the full answer
Have you ever managed a bug bounty program, and what was your approach?

If you have managed a bug bounty program, share your experience by discussing your approach to program structure, scope, and reward incentives. Detail how you communicated with external researchers, managed submissions, and processed findings, as well as the outcomes and enhancements made to security as a result.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Posted 2 days ago
Photo of the Rise User
Posted 14 days ago
Triumph Construction Hybrid No location specified
Posted 6 days ago
Photo of the Rise User
Posted yesterday
Photo of the Rise User
Posted 11 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Social Impact Driven
Rapid Growth
Maternity Leave
Paternity Leave
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Paid Holidays
Paid Time-Off
Photo of the Rise User
Posted 8 days ago

Rula's mission is to make mental healthcare work for everyone.

129 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
November 23, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!