
Staff Software Engineer - Security
Maven Clinic5 months ago
Base Salary
$221k - $260k/yr
Responsibilities
- Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance.
- Build and maintain identity, authentication, and access management systems using Okta, GCP IAM, Auth0, and OPA.
- Implement observability and anomaly detection across microservices, data stores, and SaaS platforms.
- Establish Zero Trust and least-privilege access practices across the company.
- Develop compliance observability dashboards and automate evidence collection.
- Create self-service security tools integrated with developer workflows and automate onboarding, offboarding, access reviews, and approvals.
- Integrate software supply-chain security, dependency scanning, policy enforcement, SAST/DAST scans, and compliance verification.
- Lead threat modeling and security architecture reviews for products and services.
- Partner with product and data teams to implement secure-by-default design patterns and secure PHI data handling.
- Contribute to incident response, post-mortems, and continuous improvement of Maven's security posture.
- Serve as Maven's technical authority for security engineering, mentor peers, and promote secure coding and architecture practices.
- Partner with Engineering, Compliance, Clinical, and Legal teams to align security strategy.
Requirements
- At least 8 years of software engineering experience, including at least 3 years in security infrastructure or application security.
- Proven ability to design and implement large-scale, distributed, cloud-native systems.
- Strong coding proficiency in Python, TypeScript, Go, and/or Rust.
- Deep understanding of cloud security, with GCP preferred and AWS or Azure accepted.
- Experience with Kubernetes, containers, and Terraform-based infrastructure as code.
- Familiarity with security testing frameworks and secure software development lifecycle principles.
- Strong communication and documentation skills.
- Expertise in Zero Trust architectures, authentication and authorization frameworks, and data-loss prevention is preferred.
- Experience with SOC 2, ISO 27001, PCI-DSS, or NIST security compliance automation is preferred.
- Background in security telemetry and threat detection is preferred.
- Familiarity with AI/ML security, AI-assisted analysis tools, software supply-chain security, and CI/CD pipeline hardening is preferred.
- CISSP, GCP Professional Cloud Security Engineer, or OSCP certifications are a plus.
Benefits
- Flexible hybrid work model with remote options in specified locations.
- New York City employees work onsite three days per week; employees in Boston, DC, Chicago, Seattle, and San Francisco attend monthly Work Together Days.
- Employer-covered health, dental, and insurance plan options.
- Access to Maven's healthcare platform and specialists, including mental health, reproductive health, family planning, and pediatrics.
- Wellness partnerships and in-office meals.
- 16 weeks of fully paid parental leave and a new parent stipend after one year of employment.
- Annual professional development stipend and access to a personal career coach.
- 401(k) matching for US-based employees with immediate vesting.
- Benefits apply to US-based, full-time Maven Clinic employees only.
Tech Stack
Categories
About Maven Clinic
Maven Clinic builds a virtual clinic and benefits platform for women’s and family health, spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause. It sells programs to employers and health plans and offers a consumer app for 24/7 telehealth and care navigation. Founded in 2014 and headquartered in New York, this privately held company serves more than 2,000 employers and plans.