SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 210,000 - 250,000 / annual
Midi Health is the largest virtual care clinic for women navigating perimenopause, menopause, and hormonal transitions. The company combines expert clinicians, evidence-based protocols, and modern technology to deliver historically underserved care.
As Staff Security Engineer, you will set the security architecture and strategy for Midi's entire platform, protecting sensitive healthcare and patient data (PHI) in a HIPAA-regulated environment. You will design secure architecture primitives, lead application security, cloud security, and threat modeling, and partner with platform and product engineering to embed security by default without sacrificing developer velocity.
Key responsibilities:
- Set technical direction for security priorities across AppSec, InfraSec, SecOps, vendor integrations, and related concerns
- Lead high-impact, cross-cutting initiatives across IT, Platform Engineering, and Product Engineering to materially mitigate risk
- Define and enforce security and compliance foundations for a HIPAA environment
- Treat product engineers as customers; raise the security bar across the org through tooling and education
- Partner with engineering leadership on capacity, hiring, and platform/security roadmap
- Mentor engineers and grow security engineering competency across the organization
- Lead how engineering leverages AI tooling for improving security
The company operates hybrid by design with two days per week in-office (Tuesday/Thursday) in Palo Alto or San Francisco. The culture emphasizes AI-native engineering (fluency with Claude Code, Cursor, Copilot), low-ego collaboration, and outcome-oriented execution.
Requirements:
- 10+ years of experience writing secure software and security tooling
- Seasoned hands-on engineer who still writes meaningful code (Python, Go, TypeScript, or similar)
- Strong knowledge of application and cloud infrastructure (AWS/GCP)
- Deep domain expertise in Application Security, Infrastructure Security, Threat Modeling, and Cloud Security
- Track record of measurably improving security through tooling without sacrificing developer velocity
- Leadership in AI-assisted engineering; ability to define how platform teams adopt and benefit from it
- Seasoned mentor with a track record of growing security and platform engineers
- Strong communicator with product, security, and executive stakeholders
Nice to have:
- Direct experience with HIPAA, HITRUST, SOC 2 Type II certifications, and medical device/digital health compliance
- Prior experience as Security Lead, CISO staff, or founding Security Engineer at a high-growth healthcare or fintech startup
- Relevant security certifications (CISSP, CISM, CCSP) or offensive security experience (pen-testing, bug bounty)