Security Engineer
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Healthcare is complex. We’re here to change that.
RVO Health is a health technology company on a mission to make health easier to navigate, more accessible, and more affordable for everyone.
Here, you'll help over 40 million people every month, with a team that genuinely cares about the work and each other.
AT A GLANCERVO Health is a first-of-its-kind comprehensive consumer healthcare platform that meets people where they are in their personal journeys and connects them with both the information and the care they need. RVO Health is a partnership between Red Ventures and United Health Group. Together we're focused on delivering on our vision of a stronger and healthier world. RVO Health has the largest consumer health and wellness audience online.
Every month, we help nearly 100 million people take steps on their daily journey to lifelong well-being.
As part of our RVO Health Security team, you will play a major part in strategic initiatives that improve our security posture and protect our sensitive data. You will work in a collaborative Agile environment, working closely with the business, IT, and engineering teams. You will apply your skills in a highly dynamic, innovative, cloud-native environment with a strong security-minded culture.
WhereYou'll Be
We believe great collaboration happens when we're together, solving problems, learning from each other, and connecting as a team. That's why we’re in our offices Tuesday through Thursday each week. You are welcome to work remotely Mondays and Fridays if you wish.
What You’ll Do- Design, implement, and maintain security controls and architectures to protect the company's cloud infrastructure, applications, and data from cyber threats.
- Improve our cloud security posture and vulnerability management program — pull-request scanning, triage and tracking of findings to closure across engineering teams, and coverage and license optimization.
- Build and enforce software supply chain controls across the developer toolchain — package, dependency, and extension guardrails, with enforcement thresholds tuned to reduce noise rather than generate it.
- Extend security into CI/CD pipelines, including the emerging problem of governing AI-authored code at the pipeline chokepoint.
- Build automation, internal tooling, and integrations against our developer platform and security stack so that security controls are self-service rather than ticket-driven.
- Partner with Platform & Software Engineering teams to create visibility and awareness of security issues and work to prioritize their resolution in a collaborative way.
- Perform security assessments, including code reviews and application security testing, to identify and mitigate risk in new and changing systems.
- Participate in a weekly on-call rotation for managed detection and response escalations; investigate potential threats, respond to security incidents, and perform root cause analysis.
- Develop and maintain security standard operating procedures and policies in accordance with industry best practices and regulatory requirements (e.g., HIPAA, NIST CSF).
- Stay informed of the latest developments in tactics, techniques, and procedures related to application and infrastructure vulnerabilities — especially in the healthcare space — and adapt the strategy or tooling to address new threats.
Required
:
- Bachelor's degree in Computer Science, related field OR equivalent experience
- Minimum 4+ years of experience in application security, cloud security, or a related cybersecurity role.
- Solid understanding of cloud security principles, architectures, and services (AWS or Azure preferred).
- Hands-on experience with cloud security posture management or CNAPP tooling (e.g., Wiz, Orca, Prisma Cloud), and a track record…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).