Product Security Engineer
Job description
Product Security Engineer at Candid Health.
About the role
You will act as the primary security champion for our product engineering organization, embedding security into every phase of the product lifecycle. You will own the security strategy for new features, ensuring that risk is identified and mitigated before code is written. You will partner directly with development squads to translate complex security concepts into practical, actionable guidance. You will automate security gates to remove friction while maintaining a high bar for safety. You will build the tools and standards that allow engineers to build securely by default. You will investigate security incidents to ensure root causes are addressed in the architecture. You will own the security of our software supply chain from the ground up.
Key facts
What you'll do
Perform threat modeling and risk analysis during the architectural design phase of new features to identify potential security risk vectors early in the development process.
Drive the adoption of a "Shift Left" security practice by integrating SAST, DAST, and SCA tooling directly into developer workflows and CI/CD pipelines.
Triage, prioritize, and remediate vulnerabilities discovered in application code, third-party libraries, and cloud infrastructure in collaboration with engineering teams.
Build, maintain, and tune security automation tools to reduce developer friction and enforce high-security standards across the organization.
Develop and deliver training, secure coding patterns, and security guardrails to help engineering teams construct resilient, secure-by-default products.
Assist in identifying the root cause of product-related security incidents and contribute to post-incident remediation and architectural improvements.
Build out processes and automation to ensure the ongoing security and integrity of open-source dependencies and third-party components.
Establish metrics and reporting mechanisms to track the security posture of products and the effectiveness of implemented controls.
Collaborate with cross-functional teams to ensure security requirements are considered in product roadmaps and feature specifications.
Champion security best practices and foster a culture where security is viewed as a shared responsibility across all engineering teams.
Lead the evaluation and adoption of new security technologies and frameworks to improve the efficiency and effectiveness of the security program.
Partner with legal and compliance stakeholders to ensure product security aligns with industry standards and regulatory requirements.
Design and implement secure authentication, authorization, and cryptographic flows to protect sensitive user data and system integrity.
Continuously refine the security toolchain to balance developer productivity with the enforcement of critical security policies.
Requirements
You have 5+ years of experience in software engineering or security engineering, specifically focusing on product security or application security within a fast-paced environment.
You possess a deep technical understanding of modern web and cloud architectures, including APIs, microservices, Kubernetes, and major cloud platforms like AWS, GCP, or Azure.
You are proficient in at least one programming language, such as Python, Go, Java, or JavaScript, allowing you to review code and develop secure tooling.
You have extensive knowledge of the OWASP Top 10 and common exploitation techniques used to attack web and software applications.
You have a proven track record of influencing engineering teams and collaborating effectively without hindering development velocity or agility.
You demonstrate strong analytical skills to evaluate complex systems and design innovative, practical, and scalable security solutions.
You have experience working with Infrastructure as Code (IaC) security tools and methodologies to secure cloud infrastructure and provisioning processes.
You understand the principles of secure software supply chain management, including the assessment and mitigation of risks in open-source dependencies.
Nice to have
You have experience with Infrastructure as Code (IaC) security, such as Terraform or CloudFormation.
You have experience designing cryptographic implementations or secure authentication and authorization flows, including OAuth, OIDC, and JWT.
You have knowledge of compliance frameworks relevant to the healthcare industry, such as SOC2, ISO27001, or HIPAA.
Practical notes
This role is full-time.
The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job-related skills, experience, qualifications, interview performance, and market data. Total compensation for this position may also include equity, sales incentives, and employee benefits. Given Candid Health's funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.