SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
League is a leading healthcare experience platform serving 70+ million people through health plans and health systems (including Manulife, SCAN, Geisinger, Medibank, Baptist, and Shoppers Drug Mart). The company focuses on closing gaps in healthcare delivery—helping people complete appointments, follow prescriptions, and act on referrals.
As a Security Engineer, you will split your time between engagement and engineering work. On the engagement side, you'll conduct security reviews for new product features, participate in threat modeling exercises, assess vendor security, and review third-party vendors handling customer data. You'll also support SOC 2 Type II, HITRUST, HIPAA, and PHIPA compliance efforts.
On the engineering side, you'll write code and build tooling: automation that removes manual security review steps, checks embedded in CI/CD pipelines, and systems that make security findings easier to route, track, and close. A key focus is reviewing AI-enabled features for prompt injection, excessive agency, and unintended data exposure—this is a standing responsibility, not a specialty.
You'll bring 2+ years of professional security or software engineering experience with substantial security responsibility. You should be able to find what automated scanners miss: broken access control, tenant isolation failures, and business logic flaws. You'll have working knowledge of modern authentication/authorization (OAuth 2.0, OIDC, sessions, tokens), cloud architecture, and threat modeling. You think in systems and processes to find long-term fixes rather than quick patches. You communicate risk clearly to both engineers and leadership, and you share knowledge with peers.
League's security philosophy emphasizes security by design and a paved-road approach: building tooling that makes it easier for engineers to do the right thing. Security is everyone's responsibility, and your role is to enable the engineering team to ship high-quality, secure code multiple times daily. The company welcomes diverse backgrounds and niche expertise—if you bring unique insights or unconventional approaches to security and engineering, that's a strength.