Staff-Level Product Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About The Role
Hi, I'm Megan, and I lead the Product Security team at Jane. Product Security works day to day with the developers building the software that 70,000+ clinics use to book, chart, and bill. My view of security is that it's a partnership with developers. The people who do well here can take complex insights and make them digestible for a busy team, and focus on fixing the cause, rather than repeatedly fixing the effects of an issue.
We need a staff-level engineer who can identify the themes that tie together the insights we uncover and work with product teams to improve how we build secure software at the architecture level. There's a full roadmap behind that too: changes to how our development lifecycle and GitHub workflows run, private package repositories, maturing our SCA tooling, and a security champions program. You'd lead some of those projects outright.
We also lean into AI on this team, in the back office and in the product. We're already automating reporting and reminders, and the next step is using AI for vulnerability analysis and getting closer to the code with draft fixes. If you've been somewhere that kept AI locked away and you want to build with it, or you're already securing AI features and want to do it at scale, this is a great place for that.
What Impact We're Looking For You To Make
Turn recurring AppSec findings into architectural fixes by spotting the common themes across vulnerabilities and partnering with product teams to design them out, rather than patching one instance at a time.
Lead product security projects end to end, starting with private package repositories, maturing our SCA tooling, and the changes to how our development lifecycle and GitHub workflows run.
Build AI into how the team works, moving us from automated reminders and reporting to AI-assisted vulnerability analysis and draft fixes that land closer to the code.
Champion secure development across Jane by building trusted relationships with developers, explaining risk in plain language, and helping long-tenured teams adopt new practices without friction.
Own security initiatives and represent Product Security in cross-functional groups, and mentor teammates as the team's most senior hands-on engineer.
What Experience We Need
Staff-level application security experience, including owning security initiatives end to end and working directly with development teams.
A real development background. Ruby on Rails is ideal; Python, Java, or C# with a willingness to get into a Rails codebase works too. You can read a draft PR and tell whether the fix is right.
Experience finding systemic vulnerability patterns and driving architectural fixes with engineering teams, not only reporting individual findings.
Strong relationship skills with developers and stakeholders. You make security digestible, you're comfortable pushing back kindly, and people trust you.
Hands-on experimentation with AI in your security work, ideally building automation rather than one-off use. Experience securing AI features in a product is a strong asset.
If you don't meet every single qualification but are excited about this role, we'd still love to hear from you.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Jane
Explore Top Companies in this Space
Archy
Healthcare Technology / Dental SaaS / AI Practice Management
ARB Interactive
Entertainment Software / Gaming / Social Media / Interactive Technology
Gatekeeper
Enterprise Software / Contract Management / Vendor Management / AI-Powered Automation
Lincoln Property Company
Real Estate / Property Management / Commercial Development / Investment Services
Jane (operating via jane.app) is a premier, cloud-based practice management and clinical documentation platform engineered to fundamentally eliminate the administrative friction of running allied health and multidisciplinary clinics. Founded in 2012 in North Vancouver, British Columbia, the enterprise was born out of a real-world need to manage the complex operational demands of a modern wellness clinic. Moving far beyond traditional, single-specialty electronic health records (EHR), Jane natively unifies online booking, customized charting, multi-discipline scheduling, secure telehealth, and integrated payment processing into a single, beautifully designed ecosystem. The company is trusted by over 200,000 practitioners globally, empowering physiotherapists, massage therapists, chiropractors, and mental health counselors to run their businesses efficiently and focus entirely on patient care. Under the hood, their technology core ensures strict regulatory compliance (including HIPAA and PIPEDA) while leveraging robust cloud architectures to streamline complex insurance billing, intake forms, and multi-location management. Capturing massive market acceleration and functioning as a highly intuitive operating system for the health and wellness sector, Jane remains a definitive cornerstone of modern healthcare technology, empowering the helpers to deliver exceptional care with a completely frictionless administrative backend.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

