Staff Security Engineer
Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.
About the job
What you'll do
- Own security problems end to end: navigate ambiguity to decide what matters, build it, ship it independently.
- Find the real risks and build the most direct controls that take them off the table.
- Build secure-by-default libraries, guardrails, and tooling so dozens of engineers can move fast without footguns.
- Define and implement strict least-privilege guardrails across all services to safeguard sensitive patient information and health metrics.
- Harden developer machines to minimize the risk of supply chain attacks and Whatever Comes Next from AI.
- Partner with compliance to turn control objectives into real controls, and help focus effort on the requirements that genuinely reduce risk and unlock new commercial opportunities (HITRUST, health plan requirements, etc.).
Who you are
- Strong track record of making organizations measurably safer through risks closed, not tickets opened.
- Can tell signal from noise, and spend time on the risks that actually move the needle.
- Builder first: 7+ years of software engineering with production-grade code (Kotlin, Java, Python, Go, C# or similar).
- Real security depth — threat modeling, identity and auth flows, the OWASP Top 10, cloud and supply-chain security.
- Instinct is to understand the actual threat and build the most direct fix — not to go shopping for a product that claims to handle it.
- Looking for room to own more over time — and the type to take it, not wait for it.
Nice-to-haves
- Built in healthcare and understand HIPAA and HITRUST — and how to satisfy them without drowning engineering in process.
- Experience with Google Cloud Platform and a modern product stack.
- Built internal developer platforms or secure-by-default tooling that other engineers actually adopted.
- Worked in a fast-paced, product-oriented startup.
Compensation and Benefits
- Expected base salary range: $220,000-$260,000. Eligible for equity.
- Comprehensive Health, Dental, and Vision coverage for employees and their families.
- High deductible Health Plans with Health Savings Account (HSA) options.
- Flexible Spending Account (FSA).
- Equity grant participation.
- 401(k) program.
- Competitive vacation policy.
- 16 weeks paid parental leave.
- Fully remote work flexibility (within the US).
Skills
Threat Modeling, Identity And Authentication, Owasp Top 10, Cloud Security, Supply Chain Security, Kotlin, Java, Python, Go, C#, GCP, HIPAA, Hitrust
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.