Senior Security Operations Engineer
Quick Summary
Senior Security Operations Engineer Remote · Security & Cyber Security · Full-Time At Included Health, security is central to the trust our members, customers, partners, and care teams place in us.
At Included Health, security is central to the trust our members, customers, partners, and care teams place in us. We protect sensitive health information and the systems that support our products by building security into architecture, engineering practices, and day-to-day operations. Our Security Engineering team works closely with IT, platform engineering, and product teams to build practical, scalable security controls that reduce risk through automation, secure-by-default patterns, strong technical partnerships, and controls that teams can actually operate in real production environments.
As the Senior Security Operations Engineer, you'll be responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You'll lead hands-on deployment and tuning of DLP controls across endpoint, network, and SaaS; investigate and respond to potential data exfiltration events; and drive remediation and hardening based on real-world incidents and detections. You'll own the operational lifecycle of our DLP stack — building and refining policies, partnering with stakeholders to validate business-safe controls, automating response playbooks, and turning signals from alerts and logs into durable security improvements. You'll also contribute to adjacent security operations functions, including incident response and vulnerability management, where they intersect with data protection.
This is a full-time, remote role reporting to the Senior Manager, Security Engineering. The role requires hands-on technical execution as well as the ability to influence IT, engineering, and business stakeholders to adopt practical, business-safe data protection controls.
You clarify the desired outcome, stakeholders, constraints, and available facts, then make a reasonable first move and adapt as you learn.
You are comfortable going deep in logs, alerts, endpoint and network telemetry, SaaS configurations, and cloud storage to find the signal in the noise.
You use evidence to test hypotheses and turn findings into durable fixes, reusable automation, clear documentation, or repeatable processes.
You build trust through preparation, responsiveness, direct communication, technical credibility, and follow-through.
You listen to operational realities, explain risks and tradeoffs clearly, and work with teams toward practical controls they can operate in production.
You take ownership through the full loop: investigation, containment, remediation, root cause analysis, and knowledge sharing.
You know when to investigate independently, when to involve the right expertise, and when broader organizational alignment is needed.
Direct, hands-on experience deploying, tuning, and operating:
-
DLP tools (endpoint, network, SaaS, and/or cloud)
-
Cloud Access Security Broker (CASB) or similar SaaS security controls in a production environment
-
DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel)
- Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale.
-
Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types.
Location & Eligibility
Listing Details
- Posted
- August 18, 2026
- First seen
- August 18, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 42
- Repost count
- 1
- Trust Level
- 42%
- Scored at
- September 30, 2026
Signal breakdown
Similar Security Operations Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.