Principal Security Engineer
Job description
Principal Security Engineer at Candid Health.
About the role
You will be the foundational technical pillar for security at Candid Health. In this capacity, you own the end-to-end security architecture that protects our customers and their patients. You will architect, build, and scale the technical systems that ensure data integrity across our platform. This is a role for a high-influence individual contributor who partners directly with Engineering and Product leadership. You will set the technical bar while enabling rapid, secure feature delivery. Your work will define the security blueprint for a fast-growing health-tech platform. You will operate at a strategic level, balancing deep technical execution with cross-functional leadership.
Key facts
What you'll do
- Architect and Guide the Security Landscape: Serve as the ultimate technical authority for security at Candid, mentoring engineers and setting the technical bar for a world-class security engineering culture.
- Design the Enterprise-Grade Roadmap: Lead the technical transition from a foundational security posture to a resilient enterprise architecture capable of defending complex healthcare data workflows.
- Drive Strategy at the Leadership Level: Act as the subject matter expert who translates complex technical risks into business priorities, partnering with executive leadership to stack-rank risks and embed security into Candid's overarching business strategy.
- Bake Trust & Compliance into the Architecture: Translate rigorous frameworks like HIPAA, SOC2, SOC1, PCI, and HITRUST into concrete engineering requirements, ensuring compliance is a living, automated process within our code and infrastructure.
- Evangelize a "Secure-by-Design" Culture: Level up our 200+ employees by embedding a security-first mindset across every team through threat modeling, secure coding practices, and cross-functional collaboration.
- Own Vulnerability & Vendor Deep Dives: Oversee third-party penetration testing, dissect vendor architectures before integration, and ensure production environments undergo continuous automated and manual scrutiny.
- Define and Enforce Security Standards: Establish and maintain security controls, policies, and best practices that align with industry standards and regulatory requirements.
- Lead Incident Response and Forensics: Drive the technical investigation of security incidents, ensuring timely resolution and implementing preventative measures to avoid recurrence.
- Collaborate with Product and Engineering: Partner with cross-functional teams to integrate security into the software development lifecycle from conception through deployment.
- Evaluate and Implement Security Tools: Assess, select, and manage security tooling to automate protection, detection, and response across the technology stack.
- Mentor and Influence: Guide engineers on security matters, fostering a culture of shared responsibility and continuous improvement.
- Communicate Security Posture: Regularly articulate the organization's security health to both technical and executive audiences, including our largest enterprise customers.
- Drive Security Automation: Build and maintain automated security processes to reduce manual overhead and increase resilience at scale.
- Support Audit and Assessment Activities: Serve as the primary technical resource for internal and external audits, ensuring evidence and controls are readily accessible.
- Champion Secure Development: Promote secure coding standards, code reviews, and testing practices to minimize vulnerabilities in production.
Requirements
- You have 10+ years of experience in security engineering, with a proven track record of architecting secure systems across complex technical surface areas in both startup and scaled enterprise environments.
- You have driven security outcomes at scale, balancing pragmatism with bulletproof defense-in-depth while navigating technical trade-offs in a fast-moving organization.
- You possess a deep, native understanding of sensitive, highly regulated datasets and the unique, high-stakes challenges of handling protected critical information.
- You are a force multiplier who is equally comfortable coding, architecting, and influencing stakeholders at the highest levels of an organization.
- You can write secure infrastructure-as-code, threat-model distributed systems, and confidently stand before a CISO to defend Candid's security posture.
- You have a demonstrated history of working with compliance frameworks such as HIPAA, SOC2, SOC1, PCI, and HITRUST.
- You thrive in environments with minimal hierarchy, taking ownership of broad responsibilities across engineering and security domains.
- You are truth seekers who prioritize outcomes, collaboration, and relentless curiosity in pursuit of security excellence.
Nice to have
- Preferred items are not specified for this role.
Practical notes
- Work is remote within the United States, with primary work locations in San Francisco (CA), Denver (CO), and New York (NY).
- This is a full-time engagement.
- Compensation includes a base salary range of $240,000 - $310,000 USD, with potential for equity and additional incentives.
- Candid Health has minimal hierarchy, offering broad scope for experienced professionals.
- The role requires alignment with company values, including putting customers first and maintaining a candid, kind, and committed approach.