Senior Security Engineer (DevSecOps)

  • 505 Penobscot Dr, Redwood City, CA 94063, USA
  • Full-time

Company Description

Guardant Health is a leading precision oncology company focused on helping conquer cancer globally through use of its proprietary blood tests, vast data sets and advanced analytics. The Guardant Health Oncology Platform is designed to leverage our capabilities in technology, clinical development, regulatory and reimbursement to drive commercial adoption, improve patient clinical outcomes and lower healthcare costs. 

In pursuit of our goal to manage cancer across all stages of the disease, Guardant Health has launched two liquid biopsy-based tests, Guardant360 and GuardantOMNI, for advanced stage cancer patients, and is developing programs for recurrence and early detection, called Project LUNAR. Since its launch in 2014, Guardant360 has been used by more than 5,000 oncologists, over 40 biopharmaceutical companies and all 27 of the National Comprehensive Cancer Network centers.

Job Description

We are looking for a Senior Security Engineer (DevSecOps) who has 3-5 years of experience doing security testing to identify and mitigate security issues. The candidate will work with developers and DevOps teams to design and implement DevSecOps practices and tools within Guardant Health.

In this role, the candidate will be responsible for cybersecurity hardening of Cancer Diagnostic products which may or may not run at third party sites.

More Specifically:

  1. Provide input for system hardening and apply security standards during the product development phase.

  2. Champion security by injecting security concerns into the existing development workflow; build security thinking into every stage of software development.

  3.  Provide hands-on technical support expertise in general SW development, system engineering, IT and networking as necessary.

  4.  Perform security gap assessments and implement remediations: Threat modeling, penetration testing, etc.

  5.  Know the many flavors of K8s, ECS and help enhance DevSecOps.

  6.  Monitor industry security updates, changes, technologies, emerging threats and best practices for continuous improvement

  7. Perform continuous monitoring for new high-risk vulnerabilities of released products, triggering proactive actions when needed (security patching)

  8. Collaborate with and provide feedback to Security Officers to ensure the relevancy and the value of the central governance mechanisms, toolsets, reference architecture, and other repositories

  9.  Enjoy working in a fast-paced environment to help meet mission-critical objectives.

  10.  Write comprehensive reports and deliver presentations for technical and non-technical audiences, including executives and stakeholders

 Desired:

  1. Strong understanding of security concepts, standard methodologies and how to apply them, such as SSH, public key encryption, access credentials, certificates, TLS, data encryption

  2. Experience working in Scrum and/or Kanban agile environments.

  3. Experience with AWS commercial or HealthCare regulated environment, implementation, and administration

  4. Experience with compute clusters like that of Kubernetes or HPC (SGE, slurm, etc)

  5.  Working knowledge of common information security management frameworks such as ISO27001

  6. Bachelors or Masters' degree in Computer Science or Information Security or equivalent work experience

  7. Relevant security certifications are a plus, but not required (OSCP/OSCE/GPEN/GWAPT/LPT).

#LI-MT1

Additional Information

All your information will be kept confidential according to EEO guidelines.

Privacy Policy