GoodRx Logo

GoodRx

Security Engineer II (Enterprise)

Posted An Hour Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in USA
96K-205K Annually
Junior
Remote or Hybrid
Hiring Remotely in USA
96K-205K Annually
Junior
The Security Engineer II will secure applications, manage vulnerabilities, conduct threat modeling, and enhance security systems, collaborating with engineering teams.
The summary above was generated by AI

GoodRx is the leading prescription savings platform in the U.S. Trusted by more than 25 million consumers and 750,000 healthcare professionals annually, GoodRx provides access to savings and affordability options for generic and brand-name medications at more than 70,000 pharmacies nationwide, as well as comprehensive healthcare research and information. Since 2011, GoodRx has helped consumers save nearly $75 billion on the cost of their prescriptions.

Our goal is to help Americans find convenient and affordable healthcare. We offer solutions for consumers, employers, health plans, and anyone else who shares our desire to provide affordable prescriptions to all Americans.

About the Role

GoodRx is looking for a Security Engineer II to join our Security Team (Production Engineering). This team focuses on securing all organizational applications and services. This role works closely with engineering teams to embed security within the SLDC and ensures our services are crafted with the highest security standards and quality. You will help design, build and review security controls across our applications and pipelines, improve detection and remediation of vulnerabilities, and partner with teams across the company to reduce risk and protect our users.

As part of the Security team (Production Engineering), you will help drive security visibility, automation, and process maturity by leveraging industry best tooling. You’ll contribute to threat modeling, architecture reviews, and penetration testing, while partnering with engineers to remediate vulnerabilities and deliver secure, reliable applications.

This role is ideal for someone with strong technical skills, a developer’s mindset, and a passion for securing modern applications and cloud services.

Responsibilities:

  • Embed security controls into application architecture and code reviews.

  • Own vulnerability management for applications and microservices.

  • Provide guidance on secure authentication, authorization, secrets management, and data security.

  • Perform risk analysis across the production environment to identify internal and external threats.

  • Provide security systems technology support as it applies to the implementation, installation and maintenance of security tooling, processes, procedures and runbooks.

  • Evaluate, enhance, and improve the implementation of application security automation within CI/CD pipelines to detect and remediate security issues early

  • Monitor, analyze, and triage alerts and logs from  various security platforms such as Falcon, Palo Alto, Fortinet, Cisco, Snort, Proofpoint, Google Workspace, MS365 GCP, and AWS.

  • Stay current on emerging threats, vulnerabilities, and threat actor behaviors, and apply this knowledge to improve detection and response.

  • Investigate potential threats and participate in incident response activities, including root cause analysis and remediation.

  • Evaluate, enhance and support internal threat modeling and penetration testing programs.

  • Provide security oversight in engineering architecture reviews and development processes.

  • Collaborate with Engineering, IT, Infrastructure, and Compliance teams to implement security controls aligned with frameworks like NIST, HiTrust, and CIS.

  • Research and support onboarding of new tools and systems into our security stack.

  • Maintain production security procedures and metrics.

  • Develop, research and facilitate regular security training.

  • Ability to work independently to ensure goals set by leadership are reached, and a team player.

  • Triage, remediate, and escalate security alerts / events / reports.

  • Support all required controls and participate in the audit process for assigned areas of responsibility.

  • Vulnerability scanning, monitoring, and remediation tracking for applications, services, containers, and cloud infrastructure.

  • Drive continuous improvement by identifying automation opportunities, integrating emerging best practices, and enhancing detection and response capabilities.

Required Technical and Professional Expertise:

  • Minimum 2 years experience in application security, or similar security roles.

  • Expertise in cloud environments.

  • Development experience in any modern programming language (Python, Go, etc.)

  • Familiarity with software development lifecycle (SDLC) processes and source control technologies.

  • Experience with supply chain security (dependency management, SBOMs).

  • Exposure to container and CI/CD security (Kubernetes, GitHub Actions, etc.).

  • Exposure to offensive security expertise and penetration testing certifications, such as (OSWE, OSCP+, etc.) are highly desirable

  • Comfortable writing detection queries and scripts.

  • Familiarity with regulatory frameworks such as SOC 2, CIS, or HiTrust.

  • Knowledge of common attack vectors and MITRE ATT&CK framework.

  • Problem-solving skills and the ability to thrive in a fast-paced, collaborative environment.

  • Experience with SSO platforms, such as Okta and SAML are a plus.

  • Experience with AWS, GCP, CDN/edge security tools and services are a plus

  • Availability to travel if needed.

  • Experience with automation frameworks or scripting in Python, PowerShell, or Bash.

  • Security certifications such as  Security +, GCIA, GCIH, CEH, or Palo Alto PCNSE.

Security is responsible for implementing security measures, monitoring suspicious activity, and taking immediate action against cyber threats through the incident response process and vulnerability management program. Additionally, Security monitors GoodRx’s organizational systems for end users’ activities from an information security perspective and correlates / analyzes logs to detect potential Events and Incidents. Lastly, the team works collaboratively with other departments to improve the organization’s security posture.

At GoodRx, pay ranges are determined based on work locations and may vary based on where the successful candidate is hired. The pay ranges below are shown as a guideline, and the successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, and other relevant business and organizational factors. These pay zones may be modified in the future. Please contact your recruiter for additional information.

San Francisco and Seattle Offices:

$128,000.00 - $205,000.00

New York Office:

$118,000.00 - $188,000.00

Santa Monica Office:

$107,000.00 - $171,000.00

Other Office Locations:

$96,000.00 - $154,000.00

GoodRx also offers additional compensation programs such as annual cash bonuses or commission, and annual equity grants for most positions as well as generous benefits. Our great benefits offerings include medical, dental, and vision insurance, 401(k) with a company match, an ESPP, unlimited vacation, 13 paid holidays, and 72 hours of sick leave. GoodRx also offers additional benefits like mental wellness and financial wellness programs, fertility benefits, generous parental leave, pet insurance, supplemental life insurance for you and your dependents, company-paid short-term and long-term disability, and more!

We’re committed to growing and empowering a more inclusive community within our company and industry. That’s why we hire and cultivate diverse teams of the best and brightest from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has a seat at the table and the tools, resources, and opportunities to excel.

With that said, research shows that women and other underrepresented groups apply only if they meet 100% of the criteria. GoodRx is committed to leveling the playing field, and we encourage women, people of color, those in the LGBTQ+ communities, individuals with disabilities, and Veterans to apply for positions even if they don’t necessarily check every box outlined in the job description. Please still get in touch - we’d love to connect and see if you could be good for the role!

GoodRx is committed to providing reasonable accommodations for candidates with disabilities during our recruiting process. If you need any assistance or accommodations due to a disability, please reach out to us at [email protected].

We prioritize candidate safety. Please be aware that all official communication will only be sent from @goodrx.com or [email protected] addresses.

GoodRx is America's healthcare marketplace. The company offers the most comprehensive and accurate resource for affordable prescription medications in the U.S., gathering pricing information from thousands of pharmacies coast to coast, as well as a tele-health marketplace for online doctor visits and lab tests. Since 2011, Americans with and without health insurance have saved $60 billion using GoodRx and million consumers visit goodrx.com each month to find discounts and information related to their healthcare. GoodRx is the #1 most downloaded medical app on the iOS and Android app stores. For more information, visit www.goodrx.com.

Top Skills

AWS
Cisco
Falcon
Fortinet
GCP
Github Actions
Go
Google Workspace
Kubernetes
Ms365
Palo Alto
Proofpoint
Python
Snort
HQ

GoodRx Santa Monica, California, USA Office

Our award-winning office space at the Pen Factory in Santa Monica was completed in 2020. We’re right across the street from Bergamot Station, making it an easy ride by metro from across town.

Similar Jobs at GoodRx

21 Hours Ago
Remote or Hybrid
USA
96K-205K Annually
Junior
96K-205K Annually
Junior
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
The Enterprise Security Engineer II identifies threats, manages security tools, conducts risk analysis, and supports security protocols in collaboration with various teams.
Top Skills: AWSBashCiscoCloudEdr PlatformsFortinetGCPGoogle WorkspaceIncident ResponseJIRAMs365Palo AltoPowershellProofpointPythonSecurity OperationsServicenowSnortSplunkSumo LogicZero Trust
3 Hours Ago
Remote or Hybrid
USA
169K-361K Annually
Senior level
169K-361K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
As an Engineering Manager, you will oversee technical challenges, drive architectural design, hire staff, and coordinate team priorities to achieve business goals.
Top Skills: AWSAzureC#CodefreshDatadogGCPGoGoogle AnalyticsJavaJenkinsPython
21 Hours Ago
Remote or Hybrid
USA
96K-205K Annually
Junior
96K-205K Annually
Junior
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
The Enterprise Security Engineer II identifies threats, manages security tools, conducts risk analysis, and supports security protocols in collaboration with various teams.
Top Skills: AWSBashCiscoCloudEdr PlatformsFortinetGCPGoogle WorkspaceIncident ResponseJIRAMs365Palo AltoPowershellProofpointPythonSecurity OperationsServicenowSnortSplunkSumo LogicZero Trust

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account