Back to Jobs
Modern Health
Engineering & Architecture Just now

Security Engineer (Product Security) at Modern Health

Modern Health
United StatesUnited States
Full-time
{"Zone 1 (San Francisco Bay Area and New York City Metro)": "$119,300 - $140,400 USD", "Zone 2 (All other California locations and Seattle, WA)": "$119,300 - $140,400 USD", "Zone 3 (All other New York locations, Washington locations, Washington DC, Austin, TX, CT, IL, MA, NH, NJ, OR, RI, VT)": "$107,370 - $126,360 USD", "Zone 4 (All other Texas locations, AL, AK, AZ, AR, CO, DE, FL, GA, HI, ID, IN, IA, KS, KY, LA, ME, MD, MI, MN, MS, MO, MT, NE, NV, NM, NC, ND, OH, OK, PA, SC, SD, TN, UT, VA, WV, WI, WY)": "$101,405 - $119,340 USD"}
Mid-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
Python2h 41mFree Trial ✨
Start 10-Day Free Trial
CybersecuritySecure CodingThreat ModelingAWSCloud SecuritySASTDAST

Want to know if you're a match for this job?

Calculate My Match Score

Maintaining the security and privacy of users is critical to Modern Health’s mission. As a member of the security team, you will have organization-wide visibility to continuously support and monitor our commitment to privacy, security, and compliance.

This is a unique opportunity to use your engineering and security skills to make a direct impact on people’s lives. We need a security engineer who can quickly grasp complex technical areas, mitigate risk by increasing automation in security domains, and collaborate with engineers to securely release and maintain software, infrastructure, and an information security management system, while continuously improving our security and compliance posture.

This role will be part of the Product Security (ProdSec) team, reporting to the Head of Security, and can be based anywhere in the United States. This is a chance to be a security leader at a fast-growing company, with the work done by this position laying the foundation for security at Modern Health for years to come.

Key Responsibilities:

  • Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations in collaboration with engineering teams.
  • Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to the evolving health tech landscape.
  • Partner with Engineering and Product stakeholders to integrate security at every stage of the Software Development Life Cycle (SDLC), championing secure development practices and agile delivery.
  • Develop and advocate for cost-effective solutions to address complex application and product security challenges.
  • Implement the adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions.
  • Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
  • Guide engineering teams in applying secure coding standards, providing resources and actionable feedback to foster a culture of security.
  • Deploy, optimize, and manage security tooling such as SAST, DAST, Hashicorp Vault, and other industry-leading application security solutions.
  • Participate in collaborative threat modeling initiatives for new features and evolving services, ensuring proactive risk identification and reduction.
  • Conduct secure code reviews on services and applications built with modern frameworks and technologies.
  • Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release.
  • Collaborate on IT security initiatives, partnering with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and overall IT hygiene.
  • Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations of applications and services.

Role Requirements:

  • You are a passionate and confident team member who takes pride and ownership in the work you do.
  • You are deeply familiar with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs.
  • You support the adoption of application and product security best practices across engineering teams and contribute to business-wide security initiatives.
  • You have hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security.
  • You have hands-on experience with at least one scripting language (Python and/or Bash preferred).
  • You thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications.
  • You are able to assess, prioritize, and execute on projects independently.
  • You are comfortable working in a fast-paced environment.
  • You have excellent written and verbal communication skills.
  • You bring 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering.
  • You have experience integrating security into agile product delivery.
  • You have experience reviewing code changes with software engineers and giving security feedback in the review process.
  • You have experience building or applying security controls for AI systems and using AI to improve day-to-day security engineering workflows, including code review, threat modeling, vulnerability management, and security assessments.
  • You have experience assessing and improving AWS cloud posture through IAM and access reviews, network and environment segmentation, vulnerability management, centralized logging, detection, and secure CI/CD or Terraform controls.

How would you rate this job post?

See what other professionals think about this role.

banner

Modern Health is a premier, enterprise-grade mental health and wellness powerhouse engineered to orchestrate massive-scale employee-support ecosystems and intelligent, frictionless care-delivery workflows. Operating as a global "mental health benefits" hub, the company eliminates the operational friction of traditional, legacy Employee Assistance Programs (EAPs)—which frequently suffer from low engagement, clinical-support silos, and disconnected professional-growth pipelines—by seamlessly deploying advanced "Adaptive Care" telemetry, rigorous evidence-based assessment architectures, and cohesive cross-modality integration frameworks. Moving beyond rigid legacy wellness paradigms, Modern Health empowers global enterprises—including leaders like Pixar, SoFi, and Okta—to dynamically synchronize their 1:1 coaching, clinical therapy, and self-guided digital-resource pipelines with elite, scalable, and audit-ready execution. Under the hood, their sophisticated proprietary operational infrastructure—bolstered by a network spanning 100+ countries and deep domain-expertise in clinical-outcomes research—natively manages complex global multi-region data ingestion, instantaneous automated care-routing, and compliance-hardened wellness-reporting workflows, providing the necessary operational foundation to support the modern, high-velocity human-capital economy. What sets Modern Health apart is its uncompromising dedication to frictionless "mental-wellbeing-orchestration"; by bridging the gap between highly technical, performance-intensive clinical demands and accessible, high-velocity mobile-centric interfaces, the firm empowers modern commercial organizations to radically accelerate their workforce-resilience velocity, eliminate systemic burnout-bottlenecks, and build an unassailable foundation for continuous commercial and institutional success in the modern, AI-transformed global-healthcare landscape.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More