CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Security Engineer

Calahealth • United States

Job Description

<div class="content-intro"><p><span style="font-size: 18pt;">About Cala</span></p> <p>At Cala, we’re working to free people from the burden of chronic disease. We began by creating the first non-invasive prescription therapy for hand tremor. After years of careful fine-tuning and improvements, we released Cala kIQ — our most sophisticated therapy yet. Our products have empowered thousands of people to get back to their lives with confidence and ease.</p> <p>But we won’t stop there. Our pioneering technology can be applied across neurology, cardiology, and so much more. It’s all part of our mission to help people in their struggle with chronic disease. We’re only just getting started.</p></div><p><strong>The Opportunity </strong></p> <p>We are seeking a skilled and proactive <strong>Security Engineer</strong> to join our cybersecurity team. In this role, you will be responsible for safeguarding our organization’s digital assets, infrastructure, and applications. You will play a critical part in identifying vulnerabilities, managing risks, orchestrating incident responses, and fostering a strong culture of security awareness across our engineering teams.</p> <p>The ideal candidate is a blend of a technical defender and a strategic thinker—someone who can dive deep into dependency graphs today and lead a high-stakes tabletop simulation tomorrow.</p> <p><strong>Title:</strong> Security Engineer<br><strong>Reports to: </strong>Staff DevOps Engineer<strong><br>Location: </strong>Remote, Hybrid if local to our San Mateo, CA headquarters<strong><br>Employment type: </strong>Full-Time, Exempt<br><strong>Pay range: </strong>$155,000 - $190,000<br><br><strong>**Final compensation is based on experience, skills, market benchmarks, and internal equity, with potential adjustments for candidate location.**</strong></p> <h3><strong><br>A Day in the Life</strong></h3> <h3>Vulnerability & Dependency Management</h3> <ul> <li><strong>Monitor and manage open-source and third-party dependencies</strong> using Software Composition Analysis (SCA) tools to identify and mitigate supply chain risks.</li> <li>Track and prioritize Common Vulnerabilities and Exposures (CVEs) affecting our tech stack.</li> <li>Collaborate with development teams to automate dependency updates and integrate security scanning into the CI/CD pipeline.</li> </ul> <h3><br>Penetration Testing & Vulnerability Assessment</h3> <ul> <li><strong>Manage end-to-end scope, execution, and tracking of external Penetration Tests</strong> and bug bounty programs.</li> <li>Analyze penetration testing reports, validate findings, and translate complex technical vulnerabilities into actionable remediation plans for engineering teams.</li> <li>Conduct internal vulnerability scanning and architectural risk assessments.</li> </ul> <h3><br>Security Remediation & Engineering</h3> <ul> <li><strong>Own and drive security remediation tasks</strong> across infrastructure, networks, and applications.</li> <li>Provide hands-on technical guidance and code/configuration reviews to developers to ensure secure coding practices are met.</li> <li>Implement security controls and guardrails (e.g., IAM policies, network segmentation, secrets management) to proactively reduce our attack surface.<br><br></li> </ul> <h3>Incident Response & Threat Hunting</h3> <ul> <li><strong>Serve as a core member of the Incident Response (IR) team</strong>, participating in an

Job Reference ID: CF-168202 • Posted on CloudFrame Job Scanner