Search...

Staff Software Engineer - Product Security

NextGen logo
NextGen

Stealth

Distributed
View jobs by NextGen

Skills

About the Role

You will design and implement scalable security infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance. You will build and maintain identity, authentication, and access management systems, implement observability and anomaly detection, and establish Zero Trust principles. You will create self-service security tools integrated with developer workflows, automate onboarding/offboarding, access reviews, SAST/DAST scans, and compliance verification. You will lead threat modeling and security architecture reviews, embed secure-by-default design patterns, ensure encryption and secure handling of PHI workflows, and contribute to incident response. As a technical authority for security engineering, you will mentor peers, promote secure coding practices, and partner cross-functionally with Engineering, Compliance, Clinical, and Legal teams to align on security strategy.

Requirements

  • 8+ years of software engineering experience, including 3+ in security infrastructure or application security
  • Proven ability to design and implement large-scale, distributed, cloud-native systems
  • Strong coding proficiency in Python, TypeScript, Go and/or Rust
  • Deep understanding of cloud security (GCP preferred; AWS/Azure welcome)
  • Experience with Kubernetes, containers, and infrastructure-as-code (Terraform)
  • Familiarity with security testing frameworks and secure SDLC principles
  • Excellent communication and documentation skills
  • Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention (preferred)
  • Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) (preferred)
  • Background in data security telemetry and threat detection (preferred)
  • Familiarity with AI/ML security and AI-assisted analysis tools (preferred)
  • Exposure to supply-chain security and CI/CD pipeline hardening (preferred)
  • Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus

Responsibilities

  • Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance
  • Build and maintain systems for identity, authentication, and access management
  • Implement observability and anomaly detection across microservices, data stores, and SaaS platforms
  • Establish Zero Trust principles and enforce least-privilege access company-wide
  • Develop compliance observability dashboards and automated evidence collection
  • Create self-service security tools that integrate with developer workflows
  • Automate onboarding/offboarding, access reviews, and approvals
  • Integrate software-supply-chain security (SBOM, dependency scanning)
  • Develop or adopt AI-assisted security tooling to proactively identify risks
  • Automate policy enforcement, SAST/DAST scans, and compliance verification
  • Lead threat modeling and security architecture reviews for new products and services
  • Partner with product and data teams to embed secure-by-default design patterns
  • Ensure encryption, access tracking, and secure data handling across PHI workflows
  • Contribute to incident response, post-mortems, and continual improvement of security posture
  • Act as the technical authority for security engineering
  • Mentor peers and promote secure coding and architecture practices
  • Partner cross-functionally to align on security strategy

Benefits

  • Employer-covered health, dental, and insurance plan options
  • Maven for Mavens: access to the full platform and specialists, including mental health, reproductive health, family planning and pediatrics care
  • Wellness partnerships
  • Hybrid work, in-office meals, and work together days
  • 16 weeks 100% paid parental leave and new parent stipend (for employees with 1+ year tenure)
  • Annual professional development stipend and access to a personal career coach
  • 401K matching for US-based employees with immediate vesting
  • Equity