Skip to main content

Candid Health

Security Engineer, GRC

San Francisco (Remote)fulltimemidAdded today

About this role

Build an automated, engineering-driven GRC program from scratch at a healthcare fintech company. You'll transform compliance from manual processes into continuous monitoring systems using infrastructure-as-code, API automation, and real-time dashboards across GCP, identity systems, and CI/CD pipelines.

What you'll do

  • Develop automated compliance evidence collection scripts and API integrations to replace manual documentation
  • Build infrastructure-as-code and policy enforcement rules to enforce security baselines automatically
  • Create live compliance dashboards with real-time alerts for configuration drift and policy violations
  • Map regulatory frameworks (SOC 2, HiTrust, PCI, HIPAA) to technical controls and eliminate redundancy
  • Lead technical audit readiness and external audit engagements using programmatic evidence
  • Automate vendor risk management and build continuous risk tracking tools with live telemetry

What they're looking for

  • Python and TypeScript programming
  • API integration and log parsing
  • SQL and database querying
  • Google Cloud Platform (GCP)
  • Infrastructure-as-Code (Terraform)
  • CI/CD pipelines and Git workflows
  • Compliance frameworks (SOC 2, HIPAA, HiTrust, PCI)
  • Cloud security and container environments (Docker/Kubernetes)
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Candid Health

Candid Health builds healthcare billing software designed to improve billing operations and customer experiences through scalable, reliable systems. The company is hiring Software Engineers, Data Engineers, Product Security Engineers, Forward Deployed Engineers, and Engineering Leaders to develop its platform infrastructure, data solutions, and customer-facing features.

View all jobs at Candid Health

Likely interview questions

  • Walk us through a time you automated a manual compliance process—what was the biggest technical challenge and how did you overcome it?
  • Describe your approach to mapping overlapping compliance frameworks (e.g., SOC 2 and HIPAA) to shared technical controls to avoid duplication.