SECTION I · THE BRIEF
Brief #91068Updated 18 AUG 2026REMOTELeverGREYLOCK
Employbl Company Profile

Senior Security Operations Engineer

Included Health is a concierge healthcare platform focused on raising care equality for your LGBTQ+ employees.

Location
Remote
Company size
1,000–5,000
Posted
2w ago
Via
Lever
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Included Health logo

Senior Security Operations Engineer · Included Health

View company profile
Job title
Senior Security Operations Engineer
Job location
Remote
Job description

The Senior Security Operations Engineer is responsible for designing, implementing, and improving Data Loss Prevention (DLP) protections across Included Health's corporate and cloud environments. You will lead hands-on deployment and tuning of DLP controls, including endpoint, network, and SaaS. You will investigate and respond to potential data exfiltration events. Additionally, you will drive remediation and hardening based on real-world incidents and detections.

You will own the operational lifecycle of our DLP stack. It involves building and refining policies, partnering with stakeholders to validate business-safe controls, automating response playbooks, and turning signals from alerts and logs into durable security improvements. You will also contribute to adjacent security operations functions, including incident response and vulnerability management, where they intersect with data protection.

You will play a crucial role within the Security Engineering team, reporting directly to the Senior Manager, Security Engineering. This is a remote role.

Responsibilities:
  • Lead the response to DLP and data security incidents, including investigation, containment, remediation, and root cause analysis for suspected data exfiltration or improper data handling.

  • Own the deployment, configuration, and continuous tuning of DLP controls across endpoints, network egress, SaaS applications, and cloud storage to protect PHI, PII, PCI, and other sensitive data.

  • Develop and maintain DLP policies, rules, and classifications that balance security, usability, and regulatory/client requirements.

  • Build and refine automated response playbooks and workflows that enrich, triage, and respond to alerts, reducing manual effort and mean time to respond.

  • Perform proactive hunting for anomalous data movement, including unusual destinations, channels, or volumes.

  • Define and track key DLP metrics (coverage, detection quality, MTTD/MTTR, false positive rate) and communicate progress to security leadership and cross-functional partners.

Qualifications:
  • Minimum 5+ years of hands-on experience in security operations, incident response, or security engineering roles, with a strong emphasis on data protection and DLP.

  • Direct, hands-on experience deploying, tuning, and operating

    • DLP tools (endpoint, network, SaaS, and/or cloud)

    • Cloud Access Security Broker (CASB) or similar SaaS security controls in a production environment.

    • DLP signals into SIEM/SOAR workflows (e.g., CrowdStrike, Splunk, Sentinel)

    • Advanced scripting/automation skills (e.g., Python, PowerShell, KQL/SQL) used to enrich, tune, and report on DLP/IR telemetry at scale.

    • Experience designing and maintaining data classification and policy frameworks for PHI, PII, PCI, and other sensitive data types.

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Included Health headquarters

New York, NY

Company size

1,0005,000 employees

Founded

2020

Total raised

$346,280,003

View company profile ↗

Funding rounds