K Health

Security Operations Engineer

K Health$125K — $150K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of hands-on experience in Security Operations or IT Security.
  • Proven incident response experience in cloud/hybrid environments.
  • Strong background in endpoint administration (macOS/Windows) and network security.
  • Experience maintaining SOC2 and HIPAA compliance controls.
  • Hands-on automation experience using SOAR tools or scripting.

Responsibilities

  • Design and implement SecOps workflows and incident response procedures.
  • Build low-code automations to streamline security tasks and incident triage.
  • Administer and optimize key security and endpoint management tools.
  • Support compliance with SOC2 and HIPAA controls through audits and evidence gathering.
  • Collaborate with IT and engineering teams to enforce security policies and secure workflows.
  • Conduct root-cause analysis on security incidents to prevent future risks.

Benefits

  • Hybrid work schedule with weekly lunches and stocked fridges.
  • Monthly social events organized by company committees.
  • Generous vacation policy including 18 vacation days and 9 company holidays.
  • Stock options available for all full-time employees.
  • Paid parental leave and 401k benefit.
  • Commuter benefits and competitive health, dental, and vision insurance options.
Full Job Description
About the Role

As a Security Engineer at K Health, you will serve as a foundational force in securing our healthcare technology ecosystem. Reporting directly to the Director of Security, this is a deeply hands-on individual contributor role focused primarily on Security Operations (SecOps) and IT Security projects. You will be responsible for building, automating, and maintaining our security controls while acting as a key responder to security incidents. If you thrive in a fast-paced environment where you are empowered to own your domain, automate repetitive tasks, and directly safeguard patient and organizational data, this role is for you.

What You Will Do
  • Design, implement, and maintain hands-on SecOps workflows, threat detection, and incident response procedures across our corporate and cloud infrastructure.
  • Build low-code and custom automations (using tools like Torq) to streamline security alerts, routine IT security tasks, and incident triage.
  • Administer, optimize, and manage key security and endpoint management tools, including Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and related platforms.
  • Maintain and support continuous compliance with SOC2 and HIPAA security controls, actively participating in audit preparation, evidence gathering, and control enforcement.
  • Partner with cross-functional IT and engineering teams to harden systems, enforce zero-trust endpoint policies, and secure employee workflows.
  • Conduct root-cause analysis on security incidents and proactively implement preventative security measures to eliminate recurring risks.

What We Are Looking For
  • Experience: 3-5 years of dedicated hands-on experience in Security Operations, IT Security, or System Administration with a strong security focus.
  • Incident Response: Proven background in actively detecting, investigating, and remediating security incidents in a modern cloud/hybrid environment.
  • Technical Depth: Deep foundational IT background spanning endpoint administration (macOS/Windows), identity management, and network security.
  • Compliance Standards: Demonstrated experience maintaining controls for SOC2 and/or HIPAA frameworks in an operational setting.
  • Automation Mindset: Hands-on experience automating security operations or IT tasks using SOAR platforms, scripting (Python, PowerShell, Bash), or API integrations.

Bonus
  • Direct experience implementing SOC2 or HIPAA controls from scratch or directly interfacing with external auditors.
  • Hands-on familiarity with our specific technology stack: Sumo Logic, Jamf, Intune, Slack Enterprise, CrowdStrike, and Torq.
  • Relevant industry certifications (e.g., Security+, Network+, GIAC, or vendor-specific platform certifications).

Benefits & Perks: #LI-Hybrid
  • Hybrid work schedule with weekly lunches and stocked fridges
  • Monthly social committees for company events
  • 18 vacation days, 9 company holidays, 5 sick days, and 2 personal days
  • Stock options for every full-time employee
  • Paid parental leave
  • 401k benefit
  • Commuter Benefits
  • Competitive health, dental, and vision insurance options


Compensation:

$125,000-$150,000 USD

About K Health

K Health is a healthcare company that uses AI and machine learning to provide affordable and accessible primary care to patients. The company's app allows users to input their symptoms and receive a diagnosis and treatment plan from a licensed physician within minutes. K Health also offers virtual visits with doctors and prescription delivery services. The company was founded in 2016 and is headquartered in New York City.
Learn more about K Health
Size
500 employees
Industry
Founded
2016

Similar Jobs

More Jobs at K Health

More Healthcare Jobs

Find similar Security Operations Engineer jobs: