Cloud Security Engineer responsible for administering Google Workspace, endpoint management, and cloud infrastructure. Requires hands-on experience with AWS, scripting, and security operations. Strong documentation and writing skills essential.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Company Overview
Wider Circle works with health plans and providers nationally to deliver unique community care programs that connect neighbors for better health. Centered on trusted relationships, Wider Circle connects health plan members with like-minded neighbors to inform, support and motivate one another, empowering them to be more proactive about their health. Wider Circle's trusted delivery network has been proven to drive resilience, improve member experience and engagement, and reduce inappropriate utilization and has been published in peer-reviewed literature. Today, Wider Circle offers its unique neighborhood care programs to tens of thousands of communities nationwide. To learn more, visit widercircle.com.
About The Role
Wider Circle builds technology that connects healthcare plan members with their neighbors and with the care they need. Our platform handles protected health information, we hold HITRUST certification, and we are working toward SOC 2. We are a fully remote company running on AWS and Salesforce, with a growing cloud presence.
We are looking for one person to sit at the intersection of three things that are usually three different jobs: information security, hands-on cloud engineering, and IT operations.
It is a wide role at a company small enough that you will see the whole system, and it comes with a large amount of ownership. It is also a role where a meaningful share of the work is writing things down so that they can be done the same way twice.
What You'll Work On
IT and endpoint operations
- Administer Google Workspace and our endpoint management and protection tooling across a fully remote, mixed Windows, macOS, and Chromebook fleet
- Manage device lifecycle mechanics end to end — provisioning, enrollment, policy enforcement, wipe and decommission — including the scripting that makes it repeatable at volume
- Execute hiring, personnel change, and termination access changes accurately and on time, and keep the evidence trail clean
- Improve the accuracy of our asset records through process improvement and automation
- Run our recurring vulnerability management cycles across cloud infrastructure and employee endpoints — pull the findings, analyze what moved, collaborate with other teams on remediation, and escalate as needed
- Triage security alerts as they arrive, decide what is real, and either fix it or escalate it to whoever can
- Review cloud configuration findings against our compliance baselines and drive the ones that matter to closure
- Execute periodic access reviews across our in-scope systems and collect the evidence that they happened
- Make hands-on changes in AWS — identity and permissions, network controls, encryption, logging, storage and database configuration
- Help move our infrastructure into Terraform and reduce the amount of production that exists only as console clicks
- Own pieces of legacy cloud sprawl clean up including having conversations with system owners, testing the impact of decommissions, documenting cost savings, and making sure no orphaned components are left behind
- Turn work that currently lives in someone's head into a runbook someone else can follow
- Even when you automate, you document your automation so that your teammates can repeat your work confidently and safely
- Write and maintain procedures, standards, and technical documentation that hold up when an auditor reads them
- Collect and organize control evidence for our HITRUST and SOC 2 programs
Interested in remote work opportunities in Devops? Discover Devops Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Roughly three to five years of hands-on experience spanning at least two of security operations, cloud infrastructure, and IT systems administration — and genuine curiosity about the third. Specifically:
- Real production experience. You have made changes in a production AWS account and/or Google Workspace, understood the blast radius before you made them, and know your way around the tools available. When something isn't working as expected, you know where to start investigating
- Scripting fluency. Python or Bash at the level of automating a repetitive task, parsing a messy export, and reconciling two systems that disagree. You do not need to be a software engineer
- Systems administration depth in an identity provider/endpoint management platform — Google Workspace and/or any mainstream MDM or EDR is ideal, but the transferable skill matters more than the specific product
- Writing that a stranger can follow. This is a requirement, not a nice-to-have. Clear, plain, specific technical writing
- An ownership and completion instinct. A finding is not closed because a ticket was raised. Someone has to own cross-functional remediation to completion, and in this role it is you
- Comfort in an environment with real consequences. We handle health information for people who are often elderly or vulnerable. Getting it right matters, and getting it wrong has victims, not just tickets
Nice to have, and things we're glad to teach
- Infrastructure as code, particularly Terraform
- Responsibility for HIPAA, HITRUST, SOC 2, or any audited control environment
- Container and CI/CD familiarity, and experience with vulnerability scanning or code analysis tooling
- Salesforce platform administration
- Certifications are welcome and none are required. We care what you can do
- It is not a purely advisory security role. You will be making changes, not writing recommendations for someone else to implement
- It is not a specialist track. If your goal for the next two years is to go deep in one discipline, you will be happier somewhere with a bigger team
- It is not a role where documentation is the part you do afterwards if there is time. It is a substantial and permanent share of the work
- It is not a help desk role, though you will do help desk work. The aim is to reduce our help desk toil through automation and process
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
First 90 days
You can independently run at least one of our recurring reporting cycles end to end from the existing runbook. You have working knowledge of our AWS estate and our endpoint fleet, and you know who to ask about what. You have contributed to runbooks where they can be sharpened — you will often be the first person outside of the author following a process, you are the QA.
First year
Recurring operations run on procedures you own, and they do not stop when any single person is unavailable. You have taken a piece of the environment that was undocumented and made it legible. You are trusted to design production changes on your own judgment, and you have opinions about what we should fix next.
Benefits
Compensation
As a venture-backed company, Wider Circle offers competitive compensation including:
- Performance-based incentive bonuses
- Opportunity to grow with the company
- Comprehensive health coverage including medical, dental, and vision
- 401(k) Plan
- Paid Time Off
- Employee Assistance Program
- Health Care FSA
- Dependent Care FSA
- Health Savings Account
- Voluntary Disability Benefits
- Basic Life and AD&D Insurance
- Adoption Assistance Program
- Training and Development
- Starting salary: $100,000-$110,000
Wider Circle is proud to be an equal-opportunity employer that does not tolerate discrimination or harassment of any kind. Our commitment to Diversity & Inclusion supports our ability to build diverse teams and develop inclusive work environments. We believe in empowering people and valuing their differences. We are committed to equal employment opportunity without consideration of race, color, religion, ethnicity, citizenship, political activity or affiliation, marital status, age, national origin, ancestry, disability, veteran status, sexual orientation, gender identity, gender expression, sex or gender, or any other basis protected by law.
Similar Jobs
Explore other opportunities that match your interests