Ro
Senior Security Engineer
Job Summary
The Senior Security Engineer role at Ro involves engineering, maintaining, and automating the company's security infrastructure to protect systems and patient data. The role requires collaboration with teams like SOC, IT, and Product Security to implement cloud- and SaaS-native security technologies. Key responsibilities include managing security tools such as EDR and Cloudflare Zero Trust, and developing automation workflows for security controls. Candidates should have extensive experience with security systems, cloud environments, and security operations, as well as a proactive, collaborative approach to security challenges.
Required Skills
Benefits
Job Description
Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient, end-to-end healthcare experience spanning from diagnosis, to delivery of medication, to ongoing care. Since 2017, Ro has helped millions of patients, including one in every county in the United States, and in 98% of primary care deserts.
Ro has been recognized as a Fortune Best Workplace in New York and Health Care for four consecutive years (2021-2024). In 2023, Ro was also named Best Workplace for Parents for the third year in a row. In 2022, Ro was listed as a CNBC Disruptor 50.
As a Senior Security Engineer, you will be a key member of the team responsible for engineering, maintaining, and automating Ro’s security infrastructure. You will collaborate closely with the SOC, IT, Product Security, GRC, and Infrastructure teams to implement cloud- and SaaS-native security technologies that protect Ro’s systems and patients. Your work will directly support our ability to detect, investigate, and respond to security threats. This role demands strong technical expertise, an automation-first mindset, and a proactive, collaborative approach to building scalable, resilient security solutions.
- Lead the management, configuration, and automation of EDR and vulnerability management technologies, with a strong focus on fully leveraging CrowdStrike Falcon and its full suite of capabilities.
- Support the daily management and operations of policies and configurations for Cloudflare Zero Trust Gateway solutions.
- Partner closely with Security Operations, Product Security, IT, and other stakeholders to design and implement practical, risk-informed security controls.
- Monitor industry trends and emerging threats to ensure security controls remain effective and modern.
- Develop and maintain infrastructure-as-code and automation workflows for deploying and managing security controls at scale.
- Take ownership of critical security tooling, drive continuous improvements that reduce risk and alert fatigue, and foster strong cross-functional partnerships to advance key security initiatives.
- 5+ years of experience in a Security Engineering role where you were directly responsible for engineering, maintaining and configuring security systems such as EDR, SWG, VPN, CASB, CSPM, and email security
- 2 + years of in-depth hands-on experience with a modern EDR platform, including deployment, policy tuning, threat hunting, real-time response.
- Hands-on experience operating and tuning Secure Access Service Edge (SASE) or Secure Web Gateway (SWG) solutions in an enterprise environment, including practical experience with CASB and DLP for monitoring, enforcing policies and supporting incident response efforts.
- Deep familiarity and hands on-experience with Splunk, including log ingestion, data parsing, content creation, detection engineering, and noise reduction.
- Proven ability to take ownership of systems and projects, driving progress with minimal guidance—even in the absence of clear documentation or established processes.
- An outgoing and collaborative teammate who prioritizes “getting it right over being right”. You thrive in environments that value open communication, shared learning, and a positive team culture.
- 2+ years experience configuring AWS and other cloud environments.
- Relevant GIAC Certifications (GCIH, GWAPT, GPEN, etc) or equivalent are a plus.
- Full medical, dental, and vision insurance + OneMedical membership
- Healthcare and Dependent Care FSA
- 401(k) with company match
- Flexible PTO
- Wellbeing + Learning & Growth reimbursements
- Paid parental leave + Fertility benefits
- Pet insurance
- Student loan refinancing
- Virtual resources for mindfulness, counseling, and fitness
The target base salary for this position ranges from $152,200-186,500 in addition to a competitive equity and benefits package (as applicable). When determining compensation, we analyze and carefully consider several factors, including location, job-related knowledge, skills and experience. These considerations may cause your compensation to vary.
Ro recognizes the power of in-person collaboration, while supporting the flexibility to work anywhere in the United States. For our Ro’ers in the tri-state (NY) area, you will join us at HQ on Tuesdays and Thursdays. For those outside of the tri-state area, you will be able to join in-person collaborations throughout the year (i.e., during team on-sites).
At Ro, we believe that our diverse perspectives are our biggest strengths — and that embracing them will create real change in healthcare. As an equal opportunity employer, we provide equal opportunity in all aspects of employment, including recruiting, hiring, compensation, training and promotion, termination, and any other terms and conditions of employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, familial status, age, disability and/or any other legally protected classification protected by federal, state, or local law.
See our California Privacy Policyhere.
Ro
Ro is a telehealth company connecting patients with US-licensed professionals entirely online. Get treatment now for weight loss, sexual health, hair loss, fertility, and more.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.