Security Engineer

Cala HealthSan Mateo, CA
$155,000 - $190,000Hybrid

About The Position

We are seeking a skilled and proactive Security Engineer to join our cybersecurity team. In this role, you will be responsible for safeguarding our organization’s digital assets, infrastructure, and applications. You will play a critical part in identifying vulnerabilities, managing risks, orchestrating incident responses, and fostering a strong culture of security awareness across our engineering teams. The ideal candidate is a blend of a technical defender and a strategic thinker—someone who can dive deep into dependency graphs today and lead a high-stakes tabletop simulation tomorrow.

Requirements

  • 3+ years of experience in Security Engineering, Application Security, or Incident Response.
  • Hands-on experience with modern security tooling (e.g., Snyk, Dependabot, Burp Suite, Splunk, Datadog).
  • Strong understanding of OWASP Top 10, CWE, and cloud security best practices.
  • Hands-on experience with CI/CD pipelines and build automation tools (e.g., Jenkins, GitHub Actions, GitLab CI) to integrate security scanning and controls.
  • Proficiency in Python and Shell scripting (Bash) to automate security workflows and build security tooling.

Nice To Haves

  • Familiarity with additional programming languages such as Go, JavaScript/TypeScript, or Rust for deeper code reviews and custom tooling.
  • Experience securing cloud-native environments (Docker, AWS/GCP) and native AWS security tools (AWS Inspector, GuardDuty).
  • Hands-on experience with GRC platforms (e.g., Vanta).
  • Familiarity with Infrastructure as Code (IaC) security scanning (e.g., Checkov, TFLint).
  • Relevant industry certifications (e.g., CISSP, CEH, OSCP, GCIH, AWS Certified Security).
  • Excellent communication skills with the ability to articulate technical security concepts to non-technical stakeholders.
  • Familiarity with bug bounty services like BugCroud.
  • Experience working on cloud connected IoT devices (provisioning, key rotation, OTA update security).

Responsibilities

  • Monitor and manage open-source and third-party dependencies using Software Composition Analysis (SCA) tools to identify and mitigate supply chain risks.
  • Track and prioritize Common Vulnerabilities and Exposures (CVEs) affecting our tech stack.
  • Collaborate with development teams to automate dependency updates and integrate security scanning into the CI/CD pipeline.
  • Manage end-to-end scope, execution, and tracking of external Penetration Tests and bug bounty programs.
  • Analyze penetration testing reports, validate findings, and translate complex technical vulnerabilities into actionable remediation plans for engineering teams.
  • Conduct internal vulnerability scanning and architectural risk assessments.
  • Own and drive security remediation tasks across infrastructure, networks, and applications.
  • Provide hands-on technical guidance and code/configuration reviews to developers to ensure secure coding practices are met.
  • Implement security controls and guardrails (e.g., IAM policies, network segmentation, secrets management) to proactively reduce our attack surface.
  • Serve as a core member of the Incident Response (IR) team, participating in an on-call rotation to detect, contain, and eradicate security incidents.
  • Analyze security logs (SIEM, EDR, cloud provider logs) to investigate potential breaches or anomalous behavior.
  • Conduct post-incident reviews (root-cause analysis) and document lessons learned to continuously harden our defenses.
  • Design, facilitate, and execute regular security tabletop exercises for both technical teams and executive leadership.
  • Develop realistic threat scenarios (e.g., ransomware, supply chain attacks) to test the efficacy of our incident response plans and identify gaps in communication or tooling.
  • Monitor and secure cloud infrastructure (AWS/GCP) configurations to prevent drift and misconfigurations.
  • Define, track, and report on key security performance indicators (KPIs) like Mean Time to Remediate (MTTR) and patch compliance.
  • Assist in gathering evidence and maintaining controls for security frameworks and certifications (e.g., SOC 2, ISO 27001, HIPAA).
  • Champion a security-first culture by mentoring junior engineers and creating targeted security training content.

Benefits

  • Tools, training and mentoring they need to succeed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service