SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 101,405 - 140,400 / annual
Modern Health is a mental health benefits platform for employers offering one-on-one, group, and self-serve digital resources for emotional, professional, social, financial, and physical well-being. The company is backed by Kleiner Perkins, Founders Fund, and other top-tier investors, raised $170M+ in under two years, and is the fastest entirely female-founded company to reach unicorn status.
As a Product Security Engineer on the Product Security (ProdSec) team, you will report to the Head of Security and play a foundational role in building security practices at a fast-growing healthtech company. You will have organization-wide visibility into security, privacy, and compliance initiatives.
Key responsibilities include:
- Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations with engineering teams
- Research emerging vulnerabilities and threats relevant to health tech, and report on mitigation techniques
- Partner with Engineering and Product to integrate security throughout the SDLC, championing secure development practices
- Develop cost-effective solutions for application and product security challenges
- Implement product security standards and best practices across the organization
- Test, audit, and assess security posture of applications and cloud infrastructure
- Guide engineering teams in secure coding standards and provide actionable feedback
- Deploy and manage security tooling (SAST, DAST, Hashicorp Vault, etc.)
- Participate in threat modeling for new features and services
- Conduct secure code reviews on modern frameworks and technologies
- Assist in planning and executing penetration tests on new features
- Collaborate on IT security initiatives with infrastructure and operations teams
- Partner with DevOps and Infrastructure on cloud security, AWS architecture, and cloud-native controls
The role is fully remote within the US with overlapping hours required (at least 6 hours between 8am-5pm Pacific for non-Pacific team members). Modern Health is a hyper-growth company with a culture centered on high empathy, high accountability, and a drive to win.
Requirements:
- 2-4 years of experience in product/application security OR 1-3 years in security-focused software engineering
- Deeply familiar with secure software development practices, security-focused architecture, and infrastructure
- Hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard application security tools
- Hands-on experience with at least one scripting language (Python and/or Bash preferred)
- Experience integrating security into agile product delivery
- Experience reviewing code changes and providing security feedback in code review
- Experience building or applying security controls for AI systems and using AI to improve security workflows (code review, threat modeling, vulnerability management, assessments)
- Experience assessing and improving AWS cloud posture through IAM, access reviews, network segmentation, vulnerability management, centralized logging, detection, and secure CI/CD or Terraform controls
- Ability to assess, prioritize, and execute projects independently
- Excellent written and verbal communication skills
- Comfortable in fast-paced environments and collaborative settings
- Must be able to maintain work authorization without employer sponsorship (no immigration sponsorship available)
Bonus experience: high-growth startups, SaaS software, health tech, software engineering background.
Tech stack: AWS (ECS), GitLab CI/CD, Python (Django, Flask, aiohttp), PostgreSQL, Redis, Datadog, Sentry, Terraform, Packer.