Jobs Companies Candid Health Security Engineer, GRC

Über diese Security Engineer, GRC Stelle bei Candid Health

Candid Health · Hybrid · San Francisco

About Candid Health

In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care.

 

That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.

 

Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish—submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.

 

Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups—processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.

Role Overview

We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.

You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.

Key Responsibilities

1) Compliance Automation & Engineering

  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.

  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.

  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.

  • Partnering with Legal on Medicare and Medicaid compliance

  • Partnering closely with legal and finance teams on future due diligence and compliance projects

2) Framework Mapping & Control Architecture

  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.

  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work.

  • Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.

3) Risk Management & Audits

  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.

  • Automate vendor risk management workflows and API-driven vendor evaluations.

  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.

Required Qualifications

  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.

  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.

  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform

  • Deep familiarity with core frameworks such as

  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Preferred Qualifications

  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.

  • Experience with Policy-as-Code engines

  • Background in software development, DevOps, or platform engineering.

  • Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).

 
Bereit, sich bei Candid Health zu bewerben?
Bei Candid Health bewerben

Ähnliche Jobs

Higgsfield
IT Security Engineer (SF Bay Area)
Higgsfield
⚡ Früh bewerben San Francisco Bay Area, USA Hybrid $165,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Higgsfield
Security Infrastructure Engineer (SF Bay Area)
Higgsfield
⚡ Früh bewerben San Francisco Bay Area, USA Vor Ort $165,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Candid Health
Product Security Engineer
Candid Health
⚡ Früh bewerben San Francisco (CA), Denver (C... Vor Ort $180,000–$258,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Astranis
Senior Product Security Engineer (Applications)
Astranis
⚡ Früh bewerben San Francisco Hybrid $180,000–$285,000
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
Astranis
Product Security Engineer
Astranis
⚡ Früh bewerben San Francisco Vor Ort $130,000–$215,000
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
Sierra
Software Engineer, Security
Sierra
⚡ Früh bewerben San Francisco, CA Vor Ort $230,000–$390,000
● Neu 👁 Gesehen ✓ Beworben vor 12 Std.
Sierra
Security Engineer
Sierra
⚡ Früh bewerben San Francisco, CA Vor Ort $230,000–$390,000
● Neu 👁 Gesehen ✓ Beworben vor 12 Std.
AN
Lead SoC Security Software Engineer
Anodize
⚡ Früh bewerben San Francisco or Los Altos, CA... · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 15 Std.
Anthropic
Platform Security Engineer, DRTM / Secure Launch
Anthropic
⚡ Früh bewerben San Francisco, CA | New York C... Vor Ort $320,000–$405,000
● Neu 👁 Gesehen ✓ Beworben vor 15 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Candid Health

Alle Jobs bei Candid Health ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos