About the job
At Assured, we're revolutionizing the insurance industry by modernizing claims processing, which often relies on outdated methods such as phone calls and faxes. This inefficiency costs the industry billions annually, and we believe there is a better way.
We empower large insurance providers with innovative software solutions essential for thriving in today's technology-driven landscape. Our offerings range from self-service claim filing to advanced fraud detection, serving as a vital engine for claims processing for some of the world’s largest insurers.
The challenges we tackle are significant and varied, from developing digital experiences that offer clarity and comfort to claimants during stressful times to managing large-scale machine learning-driven decision-making on substantial claims payments. Life at Assured is dynamic, collaborative, and fulfilling.
We are seeking a Staff Security Engineer to enhance and scale security across our platform, infrastructure, and development workflows. This position will work closely with engineering, infrastructure, and product teams to integrate security within our software development and operational processes.
In this role, you will leverage your deep technical expertise and strategic mindset to identify risks, design scalable security solutions, and develop programs that bolster both our security posture and engineering efficiency.
Your Responsibilities:
Oversee security architecture and design reviews across applications, infrastructure, and integrations to embed secure practices early in the development lifecycle.
Coordinate penetration testing, threat modeling, and security reviews for critical services, new features, and third-party integrations.
Design and implement security automation within CI/CD pipelines to enforce secure coding practices and infrastructure policies at scale.
Collaborate with infrastructure and DevOps teams to secure cloud environments (AWS) and enhance identity, network, and workload security.
Establish security observability and detection capabilities, including security data pipelines, SIEM integrations, and threat intelligence signals.
Adopt an attacker’s perspective to identify systemic vulnerabilities and design controls that safeguard against broad attack classes, rather than focusing solely on individual vulnerabilities.
Work in tandem with developers to refine security practices through secure architecture guidance and code reviews.

