CareerPlanGet AI match score →

Staff Software Engineer - Product Security

💼 Full-time🗓 2026-06-24

Core

Design and implement scalable security infrastructure, automation tooling, and compliance systems for a cloud-native environment.

Role type

Staff Software Engineer - Product Security

Builds

Security platforms, identity management systems, compliance dashboards, and automated security tooling.

Domain

Cloud Security / Infrastructure Security / Compliance

Deliverable

production ML models | infrastructure

Required skills

Python, TypeScript, Go, Rust, Kubernetes, Terraform, Cloud Security (GCP/AWS/Azure), Security Testing Frameworks, Secure SDLC

Preferred skills

Zero Trust architectures, Authentication/Authorization frameworks, Data-loss prevention, Security compliance automation, Data security telemetry, AI/ML security, Supply-chain security

Technologies

Okta, GCP IAM, Auth0, OPA, GitLab CI/CD, Terraform, Kubernetes, SAST/DAST tools

Responsibilities

Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance; Build and maintain systems for identity, authentication, and access management; Implement observability and anomaly detection across microservices; Create self-service security tools that integrate with developer workflows; Lead threat modeling and security architecture reviews for new products; Mentor peers and promote secure coding and architecture practices.

Seniority

Staff, technical authority & mentorship

Rewrite
## About the role What You'll Do Security Platform Engineering - Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance - Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA) - Implement observability and anomaly detection across microservices, data stores, and SaaS platforms - Establish Zero Trust principles and enforce least-privilege access company-wide - Develop compliance observability dashboards and automated evidence collection Security Automation & Tooling - Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform) - Automate onboarding/offboarding, access reviews, and approvals - Integrate software-supply-chain security (SBOM, dependency scanning) - Develop or adopt AI-assisted security tooling to proactively identify risks - Automate policy enforcement, SAST/DAST scans, and compliance verification Application & Data Security - Lead threat modeling and security architecture reviews for new products and services - Partner with product and data teams to embed secure-by-default design patterns - Ensure encryption, access tracking, and secure data handling across PHI workflows - Contribute to incident response, post-mortems, and continual improvement of security posture Leadership & Collaboration - Act as Maven's technical authority for security engineering - Mentor peers and promote secure coding and architecture practices - Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy - Champion an engineering culture of transparency, accountability, and continuous improvement ## What You'll Bring ### Required - 8+ years of software engineering experience, including 3+ in security infrastructure or application security - Proven ability to design and implement large-scale, distributed, cloud-native systems - Strong coding proficiency in Python, TypeScript, Go and/or Rust - Deep understanding of cloud security (GCP preferred; AWS/Azure welcome) - Experience with Kubernetes, containers, and infrastructure-as-code (Terraform) - Familiarity with security testing frameworks and secure SDLC principles - Excellent communication and documentation skills ### Preferred - Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention - Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) - Background in data security telemetry and threat detection - Familiarity with AI/ML security and AI-assisted analysis tools - Exposure to supply-chain security and CI/CD pipeline hardening - Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus ## What Makes You a Great Fit - You take a pragmatic, automation-first approach to solving security problems - You balance rigor with velocity, enabling teams to move quickly without compromising trust - You communicate clearly with both technical and non-technical stakeholders - You're curious, adaptable, and eager to lead initiatives from conception
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗