Senior Security Engineer
Job description
About the role
Security Engineer
Headway exists to create a mental health system that is accessible to everyone. One in four people in the United States live with a treatable mental health condition. The majority of providers do not accept insurance, and therapy remains too expensive for most people. Headway builds technology to solve this problem. We created the first national network of providers who accept insurance. We use software to help people find therapists and to support the practices those therapists run.
Our team runs over 75,000 provider practices in all 50 states. More than one million patients use our platform. We are a Series D company with over $325 million in funding. Our investors include a16z, Accel, Spark Capital, and others. We are growing quickly and looking for talented people to join us.
We are building the best tools for therapists to run their entire practice. We are reimagining how people find care. We are investing in the platform foundations that enable this at scale. We are not only a billing system. We are becoming the platform where care happens.
The Security team at Headway protects our customers. This includes therapists, patients, and payers such as insurance companies and health systems. As an early member of this team, you will build our in-house product and application security engineering capabilities. You will work closely with product and engineering teams. You will help ensure that every feature is designed and developed securely. This maintains the trust of our customers.
What You Will Do
You will partner with product and engineering teams on new product launches. These products contain rich data and will transform the industry. You will work during the design and development phases. You will implement features securely. You will perform security reviews. You will help with product design decisions. You will audit our current products and surface vulnerabilities.
You will build agentic security tooling. You will move past rules-based automation. You will create workflows that address code problems at scale. You will help define what AI-native product security looks like at Headway.
You will make the secure path the easy path. You will define and build application guardrails. Developers will be able to build securely by default. You will also foster a culture of secure development across engineering.
You will assist in ongoing security operations. You will work with the security and privacy team. You will help with incident response, vulnerability management, and penetration testing. You will communicate clearly with stakeholders. You will ensure our security program operates at a world-class level.
Tools We Use
We use Lacework for cloud security. Our languages are Python 3 and TypeScript. Our libraries include FastAPI, SQLAlchemy, and React. Our datastore options are Postgres and Redis. We operate on AWS infrastructure, including Fargate, ECS, and S3. We use Spark and Kafka for data streaming. We monitor our systems with Datadog and PagerDuty. We manage our code in GitHub. We find vulnerabilities using Snyk and Semgrep.
What You Need
You must have 5 or more years of experience. You should have a background in security or software engineering. You must have hands-on experience implementing security projects. You should have a history of working on security initiatives or as a security generalist.
You must have strong cross-functional experience. You enjoy partnering with other teams to achieve shared goals.
You must have strong technical depth and breadth. You have experience building secure systems. You understand cloud services on AWS. You write Python or TypeScript safely. You can evaluate risks and design secure architectures. You communicate clearly with partners. You have experience with identity, authentication, and authorization systems.
Experience with healthcare data and compliance frameworks is preferred.
Practical Details
This is a full-time role based in New York, New York. The compensation range is $180,000 to $240,000 per year. The work schedule is typically Monday through Friday, from 9:00 a.m. to 5:00 p.m. EST. Some travel relevant to the role may occur. You must be eligible to work in the United States without sponsorship for this position.
About Headway
 Founded in 2015, Headway was born out of a passion to bring entrepreneurial ideas to market and keep them there. We work holistically with our client partners as a true extension of their product team, not just as an execution arm of their business.
What You'll Do
You will partner with product and engineering teams on new product launches that contain rich data and will transform the industry. You will work during the design and development phases to implement features securely and perform security reviews that inform product design decisions. You will audit our current products and surface vulnerabilities to reduce the attack surface. You will build agentic security tooling that moves past rules-based automation to create workflows that address code problems at scale. You will define and build application guardrails that make the secure path the easy path for developers. You will foster a culture of secure development across all engineering teams while protecting the trust of our customers. You will assist in ongoing security operations by working with the security and privacy team on incident response, vulnerability management, and penetration testing. You will communicate clearly with stakeholders to ensure our security program operates at a world-class level. You will help define what AI-native product security looks like at Headway as we invest in platform foundations. You will foster a culture of secure development across engineering to maintain the trust of our customers.
Requirements
You must have 5 or more years of professional experience in security or software engineering roles. You must have hands-on experience implementing security projects and a history of working on security initiatives or as a security generalist. You must have strong cross-functional experience and enjoy partnering with other teams to achieve shared goals. You must possess strong technical depth and breadth with experience building secure systems in production environments. You must have practical experience with cloud services on AWS, including Fargate, ECS, and S3. You must write Python or TypeScript safely and understand how to evaluate risks and design secure architectures. You must communicate clearly with technical and non-technical partners and have experience with identity, authentication, and authorization systems. Experience with healthcare data and compliance frameworks such as HIPAA is preferred for this role.
Nice to have
Experience with healthcare data and compliance frameworks is preferred.
Practical details
This is a full-time role based in New York, NewY ork. The standard work schedule is Monday through Friday, from 9:00 a.m. to 5:00 p.m. EST. Some travel relevant to the role may occur. You must be eligible to work in the United States without sponsorship for this position.
About Headway
 Founded in 2015, Headway was born out of a passion to bring entrepreneurial ideas to market and keep them there. We work holistically with our client partners as a true extension of their product team, not just as an execution arm of their business.