Candid Health
Security Engineer, GRC
About this role
Build an automated, engineering-driven GRC program from scratch at a healthcare fintech company. You'll transform compliance from manual processes into continuous monitoring systems using infrastructure-as-code, API automation, and real-time dashboards across GCP, identity systems, and CI/CD pipelines.
What you'll do
- Develop automated compliance evidence collection scripts and API integrations to replace manual documentation
- Build infrastructure-as-code and policy enforcement rules to enforce security baselines automatically
- Create live compliance dashboards with real-time alerts for configuration drift and policy violations
- Map regulatory frameworks (SOC 2, HiTrust, PCI, HIPAA) to technical controls and eliminate redundancy
- Lead technical audit readiness and external audit engagements using programmatic evidence
- Automate vendor risk management and build continuous risk tracking tools with live telemetry
What they're looking for
- Python and TypeScript programming
- API integration and log parsing
- SQL and database querying
- Google Cloud Platform (GCP)
- Infrastructure-as-Code (Terraform)
- CI/CD pipelines and Git workflows
- Compliance frameworks (SOC 2, HIPAA, HiTrust, PCI)
- Cloud security and container environments (Docker/Kubernetes)
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Candid Health
Candid Health builds healthcare billing software designed to improve billing operations and customer experiences through scalable, reliable systems. The company is hiring Software Engineers, Data Engineers, Product Security Engineers, Forward Deployed Engineers, and Engineering Leaders to develop its platform infrastructure, data solutions, and customer-facing features.
- Website
- candid.health
Likely interview questions
- Walk us through a time you automated a manual compliance process—what was the biggest technical challenge and how did you overcome it?
- Describe your approach to mapping overlapping compliance frameworks (e.g., SOC 2 and HIPAA) to shared technical controls to avoid duplication.