Sr. Security Engineer

Castlight Health

Castlight Health

Software Engineering
Washington, USA
USD 108,466-135,582 / year
Posted on Oct 10, 2025

Job Description Summary

We’re apree health, a Mosaic Health company, whose vision is to transform US healthcare. We work with health plans and enterprise companies on everything from healthcare navigation, healthcare engagement, private health care clinics, to centralized wrap services. As a Senior Security Engineer at apree, you will design, implement, and maintain security architecture across apree's platforms. This role ensures the confidentiality, integrity, and availability of healthcare data by developing automation strategies, delivering Tier 4 support, and advancing detection engineering capabilities. You'll partner with cross-functional technology and compliance teams to ensure apree's infrastructure meets industry best practices, regulatory requirements, and evolving security threats.

How will you make an impact & Requirements

Key Responsibilities:

  • Lead the design and implementation of secure architecture to support apree's evolving tech stack.

  • Build out and refine security automations related to vulnerability scanning, configuration management, IT integrations, detection engineering and automated incident response.

  • Provide Tier 4 (expert-level) support for complex cloud security incidents, escalations, and system issues.

  • Collaborate with engineering, IT, compliance, and business stakeholders to ensure security standards and policies are implemented consistently.

  • Stay current with emerging security threats, cloud technologies, and regulatory frameworks relevant to healthcare.

Qualifications:

  • Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred) or equivalent work experience.

  • 5+ years of experience in security engineering in a cloud environment, preferably with expertise in GCP.

  • Demonstrated experience rationalizing, implementing, operating and maintaining security controls in cloud-centric environments.

  • Fluency in Python, Terraform and git.

  • Demonstrated experience in serverless computing.

  • Deep understanding of cloud architecture, automation tooling, and detection tools (e.g., SIEM, EDR).

  • Experience working in an environment that processes PHI and with applicable standards, such as: NIST CSF, ISO/IEC 27701, ISO 27001, HIPAA, HITRUST, SOC 2, FedRAMP.

  • Advanced problem-solving skills and ability to independently lead cross-functional technical projects.

Compensation: $108,466K - $135,582K annual salary & bonus eligible