Senior Software Engineer, Security
Builds and secures backend systems for APIs, EHR integrations, and payments infrastructure. Leads threat modeling, vulnerability remediation, and security tooling integration in AWS/Google Cloud environments. Requires 5+ years engineering with security focus.
What You’ll Do
- Design and build secure systems across our APIs, EHR integrations, payments infrastructure, and SaaS products
- Lead threat modeling and security design reviews for new features — embedded in the development process, not bolted on at the end
- Identify and remediate vulnerabilities in application code, dependencies, and infrastructure
- Improve authentication, authorization, and access control systems across our platform (OAuth, RBAC, service-to-service auth)
- Integrate and maintain security tooling in our CI/CD pipelines — SAST, DAST, dependency scanning
- Contribute to secure coding standards, internal libraries, and developer-facing security frameworks
- Support HIPAA and SOC 2 compliance through strong system design and documentation
- Help raise the security bar across the engineering org through code reviews, education, and pairing with developers
What You’ll Bring
- 5+ years of software engineering experience, with 1–3+ years focused on application or product security
- Experience building and securing backend systems in Python, Go, Java, or similar languages
- Solid understanding of common vulnerabilities and mitigations (OWASP Top 10 and beyond)
- Hands-on experience securing APIs and implementing authentication/authorization systems (OAuth 2.0, JWT, RBAC)
- Experience working in cloud environments — we run on AWS and Google Cloud
- Familiarity with security tooling: SAST, DAST, dependency scanning
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience
Compensation
Base salary: $165,000—$230,000 USD
Benefits:
- Full Medical, Dental, and Vision (up to 100% covered)
- 401K and commuter benefits
- Flexible PTO
Senior Privacy Engineer
Lead privacy engineering projects protecting user data across search, browser, and AI features. Own major privacy components, participate in audits, and mentor engineers using Go, Node.js, Python, or Perl.
Product Security Engineer
Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.
Senior Product Security Engineer II
Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.
Senior Security Engineer, GRC
Senior GRC engineer owning customer security questionnaires, compliance automation, risk assessments, and policy management across SOC 2, ISO 27001, and HIPAA. Requires 8+ years experience, scripting skills, and strong customer-facing communication.