Senior Security Operations Engineer
Included Health · Remote
MeritLog read this listing from Included Health's Lever job board and last checked it on September 12, 2026.
Source: the employer's Lever job board. Open the original listing for current details.
Job details
- Work model
- Remote
- Salary
- Not listed by source
- Location
- Remote
Hiring context
How this role compares at Included Health
Included Health has 85 live roles in MeritLog’s catalog across 9 job families, and 7 of them are in engineering. 46 of those listings publish a pay range, a disclosure rate of 54%.
Included Health concentrates this hiring in:
Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.
What the role asks for
What you'd do
- Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling.
- Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data.
- Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements.
- Build and refine automated response playbooks and workflows that enrich, triage, and respond to alerts, reducing manual effort and mean time to respond.
- Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes.
- Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners.
What they're asking for
- You are a practical, hands-on security operations engineer who can bring structure to ambiguous data risks or control gaps without waiting for perfect clarity.Skill
- Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP.Experience
- Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale.Skill
Parsed by MeritLog from the employer’s own posting. The full description follows below.
Job description
Senior Security Operations Engineer Remote · Security & Cyber Security · Full-Time At Included Health, security is central to the trust our members, customers, partners, and care teams place in us. We protect sensitive health information and the systems that support our products by building security into architecture, engineering practices, and day-to-day operations. Our Security Engineering team works closely with IT, platform engineering, and product teams to build practical, scalable security controls that reduce risk through automation, secure-by-default patterns, strong technical partnerships, and controls that teams can actually operate in real production environments. As the Senior Security Operations Engineer, you'll be responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You'll lead hands-on deployment and tuning of DLP controls across endpoint, network, and SaaS; investigate and respond to potential data exfiltration events; and drive remediation and hardening based on real-world incidents and detections. You'll own the operational lifecycle of our DLP stack - building and refining policies, partnering with stakeholders to validate business-safe controls, automating response playbooks, and turning signals from alerts and logs into durable security improvements. You'll also contribute to adjacent security operations functions, including incident response and vulnerability management, where they intersect with data protection. This is a full-time, remote role reporting to the Senior Manager, Security Engineering. The role requires hands-on technical execution as well as the ability to influence IT, engineering, and business stakeholders to adopt practical, business-safe data protection controls. Who You Are • You are a practical, hands-on security operations engineer who can bring structure to ambiguous data risks or control gaps without waiting for perfect clarity. • You clarify the desired outcome, stakeholders, constraints, and available facts, then make a reasonable first move and adapt as you learn. • You are comfortable going deep in logs, alerts, endpoint and network telemetry, SaaS configurations, and cloud storage to find the signal in the noise. • You use evidence to test hypotheses and turn findings into durable fixes, reusable automation, clear documentation, or repeatable processes. • You build trust through preparation, responsiveness, direct communication, technical credibility, and follow-through. • You listen to operational realities, explain risks and tradeoffs clearly, and work with teams toward practical controls they can operate in production. • You take ownership through the full loop: investigation, containment, remediation, root cause analysis, and knowledge sharing. • You know when to investigate independently, when to involve the right expertise, and when broader organizational alignment is needed. What You'll Do • Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling. • Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data. • Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements. • Build and refine automated response playbooks and workflows that enrich, triage, and respond to alerts, reducing manual effort and mean time to respond. • Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes. • Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners. What You Bring • Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP. • Direct, hands-on experience deploying, tuning, and operating: • • DLP tools (endpoint, network, SaaS, and/or cloud) • Cloud Access Security Broker (CASB) or similar SaaS security controls in a production environment • DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel) • Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale. • Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types. Pay: The United States new hire base salary target ranges for this full-time position are: Zone A: $128,130 - $180,990+ equity + benefits Zone B: $140,943 - $199,089 + equity + benefits Zone C: $153,756 - $217,188 + equity + benefits Zone D: $166,569 - $235,287 + equity + benefits This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones. Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry. Benefits & Perks: In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more: Remote-first culture 401(k) savings plan through Fidelity Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance) Paid Time Off ("PTO") and Discretionary Time Off ("DTO") 12 weeks of 100% Paid Parental leave Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies. Work-From-Home reimbursement to support team collaboration home office work Your recruiter will share more about the salary range and benefits package for your role during the hiring process. About Included Health Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community - no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at includedhealth.com. ----- Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.
Keep exploring