Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.
220k – 260k/yr
Remote7+ YOESecurity Engineering
About the role
What you'll do
Own security problems end to end: navigate ambiguity to decide what matters, build it, ship it independently.
Find the real risks and build the most direct controls that take them off the table.
Build secure-by-default libraries, guardrails, and tooling so dozens of engineers can move fast without footguns.
Define and implement strict least-privilege guardrails across all services to safeguard sensitive patient information and health metrics.
Harden developer machines to minimize the risk of supply chain attacks and Whatever Comes Next from AI.
Partner with compliance to turn control objectives into real controls, and help focus effort on the requirements that genuinely reduce risk and unlock new commercial opportunities (HITRUST, health plan requirements, etc.).
Who you are
Strong track record of making organizations measurably safer through risks closed, not tickets opened.
Can tell signal from noise, and spend time on the risks that actually move the needle.
Builder first: 7+ years of software engineering with production-grade code (Kotlin, Java, Python, Go, C# or similar).
Real security depth — threat modeling, identity and auth flows, the OWASP Top 10, cloud and supply-chain security.
Instinct is to understand the actual threat and build the most direct fix — not to go shopping for a product that claims to handle it.
Looking for room to own more over time — and the type to take it, not wait for it.
Nice-to-haves
Built in healthcare and understand HIPAA and HITRUST — and how to satisfy them without drowning engineering in process.
Experience with Google Cloud Platform and a modern product stack.
Built internal developer platforms or secure-by-default tooling that other engineers actually adopted.
Worked in a fast-paced, product-oriented startup.
Compensation and Benefits
Expected base salary range: $220,000-$260,000. Eligible for equity.
Comprehensive Health, Dental, and Vision coverage for employees and their families.
High deductible Health Plans with Health Savings Account (HSA) options.
Flexible Spending Account (FSA).
Equity grant participation.
401(k) program.
Competitive vacation policy.
16 weeks paid parental leave.
Fully remote work flexibility (within the US).
Skills
Threat Modelingidentity and authenticationowasp top 10Cloud Securitysupply chain securityKotlinJavaPythonGoC#GCPHIPAAhitrust
Conduct original research on security and privacy for frontier AI systems at Perplexity's Secure Intelligence Institute. Develop threat models, novel defenses, evaluation frameworks for AI-native products, and translate research into production security improvements. Requires PhD and publications at top security conferences.
220k – 405k/yr
On-siteSecurity Engineering
Staff Engineer, Security
Grow TherapyNew York, NY +2
Lead security engineering as the most senior hands-on engineer, shaping multi-year roadmap and building secure-by-default infrastructure including auth, data security, and vulnerability management.
220k – 240k/yr
Remote7+ YOESecurity Engineering
Staff Software Engineer - Security
SkydioSan Mateo, CA
As a Staff Software Engineer - Security, you will design, review, and build systems to secure Skydio's cloud and corporate environments. You will partner with cross-functional teams on architectural decisions and build internal security tooling, playing a key role in protecting commercial, government, and DoD customers.
220k – 270k/yr
Hybrid7+ YOESecurity Engineering
Staff Software Engineer, Product Security
HarveySan Francisco, CA +1
Staff Software Engineer builds security into AI platform, owns product security roadmap, reviews critical code like authentication/access control, leads cross-functional initiatives, and mentors engineers on secure practices. Requires 8+ years in product/application/offensive security with proven vulnerability remediation track record.
220k – 330k/yr
Hybrid8+ YOESecurity Engineering
Senior Staff Software Engineer - IAM
DatabricksSeattle, WA +1
Leads IAM and security engineering to secure Databricks' data platform, plugging infrastructure gaps and building scalable systems. Requires 9+ years in data security, 15+ years in distributed systems, and MS/PhD.