This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Bamboo Health Information Security Team is seeking a motivated Information Security Engineer to join our Security Operations team. In this role, you will be a key partner throughout the software development lifecycle, helping secure our customer-facing and internal applications. Your work will focus on vulnerability management, including web application penetration testing, along with cloud security, security automation, and digital forensics and incident response (DFIR). You will also participate in the team’s incident response on-call rotation. This position offers exposure to all aspects of a mature, multi-layered information security program and provides the opportunity to continually expand your skillset.
Job Responsibility:
Manage infrastructure, container, web, API, and mobile application vulnerabilities through dynamic application security testing (DAST), penetration testing, threat modeling, and risk analysis
Secure applications hosted in cloud environments and highly automated Kubernetes platforms
Support incident response processes, including event monitoring, forensics, containment, and remediation
Develop and maintain security automation to streamline operations, including detection engineering and tooling
Contribute to internal security awareness initiatives and promote adoption of security best practices across the organization
Partner with development teams to embed and advocate for security best practices throughout the software development lifecycle (SDLC)
Participate in an on-call rotation to escalate, investigate, and remediate security incidents
Requirements:
Bachelor’s degree in Computer Science, Information Security, IT, or a related discipline, or 5+ years of equivalent professional experience in Information Security
Hands-on experience with vulnerability management, including identification, analysis, and remediation
Practical experience with web application security testing such as DAST and/or penetration testing
Intermediate proficiency with Linux, macOS, and Windows operating systems
Foundational knowledge of cloud platforms such as AWS, Azure, or GCP
Familiarity with incident response, digital forensics, endpoint security, and securing cloud-centric or Kubernetes environments
Strong written and verbal communication skills
Working knowledge of tools commonly used for vulnerability management, endpoint protection, and/or SIEM operations
Understanding of incident response processes and best practices
Experience supporting or participating in security audits and working with compliance frameworks (e.g., SOC 2, HIPAA, HITRUST, ISO 27001)
Intermediate understanding of scripting languages such as Python, PowerShell, or Base
Ability to work effectively in a remote-first environment
Nice to have:
Security or cloud certifications, or other evidence of security-related achievements
What we offer:
Receive competitive compensation, including health, dental, vision and other benefits