About this Information Security Engineer Lead role at Neko Health
Mission
Neko is redefining what prevention means, from treating illness when it arrives, to sustaining health before it's ever at risk. Our mission: make data-driven, preventative care accessible to more people, before symptoms appear.
In a single, non-invasive visit under an hour, proprietary technology and direct clinical care combine to deliver personalised, actionable insights. It's a team that thinks in 10x, not 10%. Every role here plays a part in building a world where prevention is the norm, and where your work genuinely helps people live longer, healthier lives.
About the role
Our Security team works to create and maintain the safest environment for Neko's members and developers. We embed security into the entire product lifecycle, from initial design and think-it through launch and beyond. In this role, you will also work with and lead software engineers to proactively identify and fix security flaws and vulnerabilities, conduct in-depth security reviews throughout the product lifecycle, build security capabilities into CI/CD pipelines, and improve detection.
Responsibilities
Conduct security reviews, research and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers.
Review and develop secure operational practices and provide security guidance for engineers and staff.
Assess designs and look for vulnerabilities, both with launch reviews and longer-term engagements.
Look for vulnerabilities with techniques including but not limited to AI, manual code review, fuzzing, and static code analysis.
Perform threat modeling of large and complex systems to quickly determine areas that warrant further investigation and direct security review.
Leverage AI tools and agents in your day-to-day work to scale your own capabilities.
Hardening and securing cloud infrastructures
Minimum qualification
5 years of experience with security assessments, security design reviews, or security engineering.
Experience in one or more general purpose languages, preferably C#, Python, C++, Javascript or Java.
Experience with cloud infrastructures like Azure, GCP or AWS
Preferred qualification
10 years of experience with security assessments, security design reviews, or security engineering.
Understanding both offensive and defensive security methods.
Experience in three or more general purpose languages, preferably C#, Python, C++, Javascript or Java.
Good knowledge and experience with breaking and securing cloud infrastructures like Azure, GCP or AWS