SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer - Encryption & PHI

StackAI - San Francisco, CA, USA - In-office - posted 2026-09-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

StackAI is an enterprise AI transformation platform (owned by Asana) that enables organizations to build, deploy, govern, and scale AI agents for regulated and complex operations. The platform supports 100+ enterprise integrations and can be deployed in multi-tenant cloud, customer VPC, or on-premises environments. You will join the Core Engineering team as a Senior Python engineer focused on security-critical systems. Your primary responsibilities include designing and implementing encryption and key-management systems that work across hosted, VPC, and on-premises deployments; building controls to detect, transform, and safely handle PHI, PII, and sensitive data across workflows, connectors, model calls, logs, and storage; protecting customer credentials from storage through runtime use; strengthening product trust boundaries including tenant isolation, signing/verification, and service-to-service authentication; creating shared security foundations via Python services and libraries; and safely evolving live systems through migrations, staged rollouts, and observability. This is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python, take projects from investigation and design through implementation, migration, rollout, and operation. The systems you build directly determine which sensitive and regulated workloads enterprises can run on StackAI. Required: 4+ years building and operating production backend systems; strong professional Python experience in substantial production codebases; hands-on experience implementing and operating security-critical product systems; depth in at least one area (encryption/key management, signing/authentication/sessions/tokens, multi-tenant isolation, sensitive-data processing, or secure credential storage); practical knowledge of applied cryptography; experience safely changing critical systems without disrupting customers; strong judgment around trust boundaries and failure modes; ability to take ambiguous technical problems from investigation through production rollout. Bonus: HashiCorp Vault, cloud KMS, HSMs, envelope encryption, key rotation; PHI/PII detection, redaction, pseudonymization, tokenization; PKI, certificate systems, cryptographic signing; multi-tenant SaaS with sensitive data; healthcare, payments, identity, or financial infrastructure experience; self-hosted/VPC/on-premises/air-gapped deployments; AI-agent, LLM, or connector-based architecture; startup or growth-stage product experience.

Similar roles