Abby Care

Senior Security Analyst

Abby Care · USA

Full-TimeLeadPythonAWSGCPAzure

🔥6 people viewed this job

About the Role

About Abby Care: Powering the future of care at home for all of America. Abby Care is building the leading AI-native platform for family-led care. America is facing a growing care crisis. Millions more people need care at home than ever. Over 50 million family caregivers support loved ones without the tools, training, or recognition they deserve. We believe families are the largest untapped caregiving workforce in America, and that technology can help them deliver better care while driving stronger outcomes and greater transparency across the healthcare system. Abby Care combines clinical oversight with an AI-powered platform to train, enable, and support family caregivers in delivering high-quality care at home. Our platform helps health plans and government partners better understand, verify, and improve care in the home. We expand access to care, reduce reliance on higher-cost settings, and help ensure public dollars are spent effectively. We are proud to partner with leading health plans, providers, and community organizations and are backed by top VCs. We envision a future where family-led care is a core part of the healthcare system. Abby Care is building that future. Join us in solving one of the most important challenges of our time. The Opportunity: We're looking for a Senior Security Analyst to strengthen our security operations, threat detection, and risk management program. This role reports into the Director of IT, Information & Security. You'll take the lead on incident response, vulnerability management, and security monitoring across our cloud, endpoint, and identity infrastructure, while mentoring junior analysts and driving continuous improvement of our security posture. This role is a strong fit for someone who thinks like an attacker, communicates like a partner, and enjoys turning alerts into action. This is a Full-Time Remote opportunity based in the United States, with the expectation to work PST hours. What you'll work on: Security Operations & Incident Response • Lead end-to-end incident response, threat hunting, and root cause analysis across SIEM, EDR (SentinelOne), and cloud security tooling. • Develop and maintain incident response playbooks, runbooks, and tabletop exercises. Vulnerability & Risk Management • Own the vulnerability management lifecycle, partnering with IT and Engineering to remediate scan, pen test, and audit findings. • Maintain the risk register, conduct third-party/vendor risk assessments, and communicate technical risks to business stakeholders. Identity, Endpoint & Compliance Oversight • Partner with IT to audit and enforce security controls across Okta (RBAC/MFA), Google Workspace (DLP/logs), JAMF, and SentinelOne. • Drive evidence collection and remediation for compliance audits (SOC 2, ISO 27001, HIPAA, PCI DSS) while aligning policies with NIST CSF and CIS frameworks. Security Engineering & Automation • Automate detection, response, and reporting workflows via SOAR, scripting, and APIs to improve alert quality and efficiency. • Mentor team members and contribute to cross-functional security knowledge sharing. AI Security & Governance • Establish guardrails and acceptable-use policies for enterprise AI tools (e.g., GenAI, Claude), mitigating shadow AI, data leakage, and third-party vendor risks alongside IT, Legal, and Compliance. • Partner with Product and Engineering to assess and remediate AI/LLM-specific vulnerabilities, including prompt injection, model abuse, and data exposure. • Pilot and evaluate AI-powered security capabilities (e.g., AI-assisted SIEM/EDR triage and anomaly detection) to boost response speed and operational efficiency. What you'll have: • 8+ years of experience in security operations, leading incident response end-to-end from detection through remediation. • Associate's or Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent practical experience. • Prior experience working in the healthcare or health tech industry, with an understanding of industry-specific security and data privacy requirements (e.g., HIPAA). • Hands-on experience with SIEMs, EDR/XDR (e.g., SentinelOne), vulnerability scanners, cloud security, and core IAM concepts (SSO, MFA, RBAC). • Working knowledge of security frameworks (SOC 2, ISO 27001, NIST, CIS) with strong analytical skills to translate technical risk to business stakeholders. • Familiarity with emerging AI/LLM risks and an interest in evaluating AI capabilities for security use cases. • Excellent communication skills with the ability to prioritize competing incidents and operate calmly under pressure. Nice to have: • Hands-on experience with Okta, JAMF, or Google Workspace, alongside Infrastructure as Code (Terraform) for access/security policy management. • Scripting experience (Python, Bash), SOAR exposure, and familiarity with CSPM tools or native cloud security platforms (AWS/GCP/Azure).

Abby Care has 1 open position on Remote Vibe Coding Jobs.

💬 Developer Questions

Ask the team a question — answers show up here

🎯

What does the interview process look like?

🤖

What AI/vibe coding tools does the team use daily?

👥

How big is the engineering team?

⏰

Is the team fully async or are there required meetings?

🚀

What does onboarding look like for remote hires?

🔧

Can you share more about the tech stack and architecture?

📈

What does career growth look like in this role?

📅

What does a typical day look like?

💰

Is there a salary range you can share?

📊

Is equity or stock options part of the package?

🌍

Are there timezone requirements or preferences?

🛂

Do you sponsor work visas?

🏢 Is this your listing? Claim it to answer questions

Similar Jobs

Helpful resources

Hiring for a similar role? Post your job here — it's free →