Senior Security Engineer, Blue Team
About the role
Who are we and why should you join us?
BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone. Founded in 2013, we are now the world’s largest online therapy service, providing affordable and convenient therapy in across the globe. Our network of over 30,000 licensed therapists has helped millions of people take ownership of their mental health and change their lives forever. And we’re not stopping there – as the unmet need for mental health services continues to grow, BetterHelp is committed to being part of the solution.
As a Senior Security Engineer on the Blue Team at BetterHelp, you’ll join a diverse team of licensed clinicians, engineers, product pros, creatives, marketers, and business leaders who share a passion for expanding access to therapy. And as a mental health company, we take employee mental health just as seriously as we do our mission. We deeply invest in our team’s well-being and professional development, because we know that business and individual growth go hand-in-hand. At BetterHelp, you’ll carve your own path, make an immediate impact, and be challenged every day – with a supportive community behind you the whole way.
What are we looking for?
We are seeking a motivated Blue Team Security Engineer who is looking to help build our security program, while growing their own security skill set. You will be on the front line of security, assessing third parties, building security tools, and executing incident response efforts. We are looking for an engineer with good attention to detail, the ability to learn quickly, and a get-things-done attitude with eagerness to build something awesome!
What will you do?
- Conduct security risk assessments of third parties, evaluating overall maturity, and mapping data flows to assess supplier security risks.
- Build security tooling and automation, contributing to the development of internal applications and scripts.
- Execute incident response efforts by identifying, investigating, and remediating security incidents.
- Enhance endpoint security by safeguarding organizational endpoints, focusing on device security through EDR (Endpoint Detection and Response), application control, and threat detection.
- Delve into the organization’s use of AWS, collaborating with DevOps to identify and mitigate security vulnerabilities.
What will you NOT do?
- You will NOT worry about "runway", "cash left", or "how much time we have until the next round". We have the startup DNA but we're fully backed and funded, all the way to success.
- You will NOT be confined to your "job". You will get involved in product, marketing, business strategy, and almost everything we do.
- You will NOT be bogged down by office politics, ego, or bad attitude. Only positive, pleasure-to-work-with people are allowed here!
- You will NOT get yourself burned out. We work hard but we believe in maintaining a sustainable work/life balance. Really.
Can I work remotely?
Yes. We operate on PST and candidates in any time zone are welcome to apply. We ask employees to travel to our San Jose, CA office up to three times per year plus one company-wide offsite to collaborate in person and strengthen working relationships. Travel expenses are covered and reasonable accommodations are made for those under unique circumstances who cannot travel.
Requirements
- 5+ YOE as a Security Engineer
- Experience performing security assessments on third party vendors and applications.
- Experience coding (Rust preferable, Python, PHP)
- Experience with MacOS and AWS
- Experience in incident response activities
- Ability to explain technical concepts to non-technical stakeholders.