- Company Name
- Nabla
- Job Title
- Lead Security Engineer
- Job Description
-
**Job Title**
Lead Security Engineer
**Role Summary**
Owns and builds the end‑to‑end security engineering function for a SaaS platform on Google Cloud that handles sensitive healthcare data. Works with engineering, IT, and security leadership to harden infrastructure, embed secure development practices, manage threat detection, and ensure compliance with HIPAA, SOC 2, ISO 27001, and GDPR.
**Expectations**
- Lead strategic security planning and execution.
- Own and grow a low‑size, high‑impact security organization.
- Deliver measurable improvement in risk posture and compliance readiness.
**Key Responsibilities**
Infrastructure Security
- Harden GCP environment (network, IAM, VPC Service Controls, firewalls, proxies).
- Deploy WAF, DDoS protection, IDS/IPS, and ensure cloud‑native security alignment with HIPAA/SOC 2/ISO 27001.
Application Security
- Define authentication/authorization (OAuth, SAML/SCIM) and least‑privilege.
- Integrate SAST, DAST, IaC, container, and dependency scanning into CI/CD.
- Conduct threat modeling, secure coding reviews, and vulnerability remediation.
Security Operations (SecOps)
- Select & operate SIEM, SOAR, log aggregation, endpoint (EDR/MDM).
- Develop incident playbooks, triage alerts, and lead response efforts.
External Partnerships & Program Management
- Manage pentest, red‑team, bug‑bounty, and vulnerability disclosure programs.
- Liaise with compliance, governance, and vendor security functions.
Data Protection
- Implement encryption at rest/in‑transit, key management (KMS/HSM).
- Enforce data minimization, tokenization, and DLP controls per regulatory requirements.
**Required Skills**
- 6–10+ years in security engineering (infrastructure, application, or cloud).
- Deep GCP security expertise: IAM, VPC, Cloud Armor, Cloud Security Command Center.
- Proven experience with secure SDLC practices (SAST, DAST, IaC scanning).
- Incident response, SIEM/SOAR, endpoint and network security tooling.
- Familiarity with HIPAA, SOC 2, ISO 27001, GDPR compliance frameworks.
- Strong communication, mentorship, and cross‑functional collaboration.
**Required Education & Certifications**
- Bachelor’s or higher in Computer Science, Information Security, or related field.
- Relevant certifications preferred: CISSP, CISM, GCP Professional Cloud Security Engineer, OSCP, or equivalent.