SmithRx Logo

SmithRx

Senior Security Engineer

Sorry, this job was removed at 04:09 p.m. (EST) on Thursday, Aug 07, 2025
Remote
Hiring Remotely in USA
Remote
Hiring Remotely in USA

Similar Jobs

4 Days Ago
Remote or Hybrid
US
109K-151K Annually
Senior level
109K-151K Annually
Senior level
Information Technology
Design, implement, and support enterprise identity and access management using Microsoft Entra. Build controls for Conditional Access, MFA, identity governance, privileged access, authentication modernization, and Zero Trust. Develop PowerShell automation for identity lifecycle and governance, partner with technical and business teams, improve security operations, and mentor engineers. The role also includes on-call participation and occasional after-hours work.
Top Skills: Active DirectoryAzure DevopsConditional AccessCyberarkDelineaEntra Id GovernanceMfaMicrosoft EntraPamPimPowershellRbacSailpointSaml 2.0ServicenowZero Trust
12 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
167K-227K Annually
Senior level
167K-227K Annually
Senior level
Real Estate • Sales • Software • PropTech
Design, implement, and maintain security controls across cloud (AWS) and on-prem systems. Lead vulnerability management, incident response, and remediation. Serve as SME for SIEM, SAST/DAST, IAM. Embed security in SDLC, support SOC 2/ISO 27001 audit readiness, mentor junior engineers, and recommend control improvements.
Top Skills: AgileAWSDastIamIso 27001On-PremSaaSSastSIEMSoc 2Vulnerability Management
10 Days Ago
In-Office or Remote
83K-116K Annually
Senior level
83K-116K Annually
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Design and implement multi-cloud security controls, build policy-as-code and IaC guardrails integrated into CI/CD, harden container and Kubernetes workloads, perform vulnerability analysis and remediation, support incident response and forensics, provide audit evidence for compliance frameworks, mentor other security engineers, and participate in on-call incident rotations to improve remediation and response processes.
Top Skills: Admission ControllersAWSAws OrganizationsAzureBashCi/CdContainer Image ScanningContainer Runtime DetectionContainersDependency Vulnerability ScanningEdrGCPIamInfrastructure As Code (Iac)JavaScriptKubernetesNaclsNetwork PoliciesPod Security StandardsPolicy As CodePythonSecurity GroupsService Control Policies (Scps)Vpc

Who We Are:

SmithRx is a rapidly growing, venture-backed Health-Tech company.  Our mission is to disrupt the expensive and inefficient Pharmacy Benefit Management (PBM) sector by building a next-generation drug acquisition platform driven by cutting edge technology, innovative cost saving tools, and best-in-class customer service.  With hundreds of thousands of members onboarded since 2016, SmithRx has a solution that is resonating with clients all across the country.

We pride ourselves for our mission-driven and collaborative culture that inspires our employees to do their best work. We believe that the U.S healthcare system is in need of transformation, and we come to work each day dedicated to making that change a reality. At our core, we are guided by our company values:

  • Integrity: Our purpose guides our actions and gives us confidence in the path ahead. With unwavering honesty and dependability, we embrace the pressure of challenging the old and exemplify ethical leadership to create the new.
  • Courage: We face continuous challenges with grit and resilience. We embrace the discomfort of the unknown by balancing autonomy with empathy, and ownership with vulnerability. We boldly challenge the status quo to keep moving forward—always.
  • Together: The success of SmithRx reflects the strength of our partnerships and the commitment of our team. Our shared values bind us together and make us one. When one falls, we all fall; when one rises, we all rise.

Job Summary:

We are seeking an experienced Security Engineer specializing in Security Operations, Detection Engineering, and Incident Response. In this critical, hands-on role, you will be a leader in identifying, analyzing, and responding to complex security threats targeting our cloud-native environment, primarily within AWS. You will leverage your deep expertise and Python proficiency to design, build, and tune sophisticated detection mechanisms, automate response actions, and continuously improve our security monitoring and incident response capabilities. You'll tackle ambiguous security challenges, collaborate on incident response efforts, define technical roadmaps for detection and response, and support security improvements across engineering teams.

In order to be eligible for this position applicants must be based in one of the following states: Arkansas, Arizona, California, Colorado, Florida, Georgia, Kansas, Minnesota, Missouri, Nevada, North Carolina, South Carolina, Ohio, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin.

What you will do:

  • Leverage Python to design, develop, test, and maintain high-fidelity and actionable detection-as-code rules, automate detection logic, parse and enrich complex data sources, and integrate security systems via APIs.
  • Proactively hunt for threats within our AWS and corporate environments, analyzing logs and system data to uncover malicious activity that evades automated detections.
  • Develop, refine, and automate incident response playbooks and standard operating procedures using SOAR (Security Orchestration, Automation, and Response) platforms and custom Python scripts.
  • Perform technical analysis during incidents, including log analysis, network traffic analysis, and host/endpoint artifact collection.
  • Manage and optimize core security operations tools (SIEM, SOAR, EDR, etc.).
  • Serve as a strong technical contributor and subject matter expert within the Security Operations and Incident Response domain, influencing security practices across engineering and IT teams.
  • Autonomously define and deliver the technical roadmap for key detection and response initiatives, managing cross-functional dependencies.

What you will bring to SmithRx:

  • 5+ years of hands-on experience focused on Security Operations, Detection Engineering, and/or Incident Response.
  • Strong proficiency in Python for security automation, scripting, data analysis, and tool development.
  • Deep experience with AWS security, including logging services (CloudTrail, CloudWatch, VPC Flow Logs), security services (GuardDuty, Security Hub, IAM, Config), and incident response in the cloud.
  • Bachelor’s degree in Computer Science, Information Technology or a related field, or relevant work experience required in lieu of a degree.
  • Experience with infrastructure-as-code (e.g., Terraform) for deploying security resources.
  • Proven expertise in developing detection content (rules, queries, models) in SIEM platforms (e.g., Splunk, Elastic Security, Sentinel).
  • Hands-on experience with EDR solutions (e.g., CrowdStrike, SentinelOne, Carbon Black) for detection and response.
  • Strong understanding of incident response methodologies, threat intelligence, cyber kill chain, and frameworks like MITRE ATT&CK.
  • Experience with log analysis, network traffic analysis, and host/endpoint forensics techniques.
  • Demonstrated ability to lead complex security incident investigations and response efforts.
  • Excellent communication skills and ability to remain calm and effective under pressure.

Bonus Points:

  • Experience with SOAR platforms (e.g., Splunk SOAR, Palo Alto XSOAR, Tines) and automation techniques.
  • Relevant industry certifications (e.g., GCIH, GCFA, GNFA, GREM, AWS Security Specialty, Splunk Certified Architect/Consultant).
  • Experience with threat hunting and purple teaming methodologies and tools.
  • Strong track record of mentoring junior team members.

What SmithRx Offers You: 

  • Highly competitive wellness benefits including Medical, Pharmacy, Dental, Vision, and Life Insurance and AD&D Insurance
  • Flexible Spending Benefits 
  • 401(k) Retirement Savings Program 
  • Short-term and long-term disability
  • Discretionary Paid Time Off 
  • 12 Paid Holidays
  • Wellness Benefits
  • Commuter Benefits 
  • Paid Parental Leave benefits
  • Employee Assistance Program (EAP)
  • Well-stocked kitchen in office locations
  • Professional development and training opportunities

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account