SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer, Detection & Response

Maven Clinic - New York, NY, United States - Hybrid - posted 2026-09-25

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 221,000 - 299,000 / annual

Maven Clinic is seeking a Staff Security Engineer to own the Incident Detection and Response program. You will lead a team including an AppSec-focused engineer and an infrastructure-focused engineer, providing technical direction and judgment on security matters. Key responsibilities include: **Investigation & Technical Direction**: Lead hands-on incident investigations by pulling logs, building narratives of what happened, and advising business and engineering leaders on next steps. Read production code as needed to understand actual system behavior. **Proactive Hunting & SDLC Hardening**: Hunt for bugs in the codebase and weaknesses in the SDLC where problems can slip past existing controls. Propose and implement fixes yourself or manage resolution with the right teams, whether that's a specific code fix or broader process/control changes. Partner with the Product Security Engineer on systemic gap remediation. **Detection Engineering**: Own and tune detection logic running through AI-assisted security operations tooling, validating investigations and escalations, and setting alert criteria. Close gaps in logging and visibility to ensure tooling has the right data. **Managing AI Risk**: Help understand and manage security risks from growing use of LLMs and AI tooling, both in what Maven builds and what it adopts internally. Maven Clinic is the world's largest virtual clinic for women and families, partnering with 2,300+ employers and health plans. The company has raised $425M+ from leading investors and has been recognized with numerous awards including TIME 100 Most Influential Companies and CNBC Disruptor 50. **Workplace**: Hybrid model with primary hub in New York Metro. NYC-based team members work onsite three days per week (Tue/Wed/Thu). Those in Boston, DC, Chicago, Seattle, and San Francisco attend monthly Work Together Days. **Requirements**: - 6+ years of security experience combining hands-on software or AppSec depth with detection and SIEM engineering ownership - Comfortable reading production code across multiple languages and stacks to judge exploitability of findings - Experience building threat models of codebases, reasoning about attack surface, trust boundaries, and data flow - Track record of finding and fixing systemic weaknesses through incidents or proactive review - Strong communication skills with credibility to direct investigations and influence peers informally **Strongly Preferred**: - Hands-on experience with AI-assisted security operations tooling (AI SOC platforms, LLM-based triage, agentic escalation systems) - Interest or experience securing AI and LLM-powered systems (prompt injection, model misuse, agentic tool abuse) - Prior exposure to golden-path or secure-by-default infrastructure initiatives - Experience with container or image security and patching lifecycle - Relevant certification (GCIH, GCFA, GCDA, OSCP, or CISSP)

Similar roles