Skip to content
HeadwayHeadway

Senior Security Engineer

Senior Security Engineer partnering with product and engineering teams to design and implement secure features, build AI-native/agentic security tooling, create developer guardrails, and handle security operations at a mental healthcare platform company. Requires 5+ years in security/software engineering, strong technical depth, and excitement about AI in security.

About the job

What you’ll do at Headway

  • Partner with Product and Engineering on new product launches with rich data components: participate in implementation efforts, conduct security reviews, help with product design decisions, audit and surface vulnerabilities in current products.
  • Build Agentic Security Tooling: develop agentic workflows (beyond rules-based automation) to address code problems at scale across the growing codebase; define what AI-native product security looks like.
  • Make the safe way the easy way: define and build application guardrails so developers build securely by default; instill a culture of secure development across engineering.
  • Assist in ongoing security operations: incident response, vulnerability management, penetration testing, security reviews, and other operational tasks to maintain a world-class security program.

You’ll be great for this role if you have

  • 5+ years experience in security and/or software engineering roles with a demonstrated history of working on security-related projects or with responsibilities as a security generalist (0→1 security experience).
  • Strong cross-functional experience partnering with other teams.
  • Strong technical depth and breadth: experience building secure platforms and products, performing security design and code reviews, understanding and improving security systems for efficiency and scalability.
  • Excited by AI’s potential to reshape product security and desire to be at the forefront.
  • Thrive in ambiguity in a fast-paced environment with an optimistic attitude.
  • Seek opportunities to lead the industry in implementing latest security and privacy technologies.
  • Results driven with deep care for creating impact.
  • Mission driven by increasing access to high quality mental health care.

Tools we use

  • Cloud Security: Lacework
  • Languages: Python 3, TypeScript
  • Libraries: FastAPI, SQLAlchemy, React
  • Datastores: Postgres, Redis
  • Infrastructure: AWS (Fargate, ECS, S3, and more), Spark and Kafka
  • Monitoring: Datadog, PagerDuty
  • Version Control: Github
  • Vulnerability Management: Snyk, Semgrep

Compensation & Benefits

Expected base pay range: $218,500 - $273,125 (based on qualifications, experience, and location). Eligible for equity grant. Comprehensive benefits include medical, dental, vision, HSA/FSA, 401K, work-from-home stipend, therapy reimbursement, 16-week parental leave, Carrot Fertility, 13 paid holidays + Holiday Break, flexible PTO, EAP, training and professional development.

Skills

Security Engineering, Application Security, Product Security, Python, TypeScript, AWS, Lacework, Snyk, Semgrep, FastAPI, React, Incident Response, Vulnerability Management, Penetration Testing

Imprint

Imprint

San Francisco, CA
Senior Engineering Manager, Security
$220k+/yrHybrid8+ YOESecurity Engineering

Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Spade

Spade

United States
Senior Platform Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.

Snowflake

Snowflake

Menlo Park, CA
Senior Software Engineer - Cloud Security
$200k+/yrHybrid5+ YOESecurity Engineering

Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.

Atomicmachines

Atomicmachines

Emeryville, CA
Senior Manager - Network and Information Security
$200k+/yrOn-site10+ YOESecurity Engineering

Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.