Responsibilities
- Build encryption and key-management systems across hosted, VPC, and on-premises deployments.
- Develop controls to detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage.
- Secure customer credentials and tokens from storage and access control through runtime use.
- Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication.
- Create shared Python services, libraries, and APIs that standardize security-critical behavior.
- Lead migrations, compatibility periods, staged rollouts, observability, recovery, and rollback for live systems.
- Own projects end to end from investigation and design through implementation, rollout, and production operation.
Requirements
- 4+ years of experience building and operating production backend systems.
- Strong professional experience with Python in a substantial production codebase.
- Hands-on experience implementing and operating security-critical product systems, including the code enforcing their guarantees.
- Depth in at least one area including encryption and key management; signing, authentication, sessions, or token infrastructure; multi-tenant isolation; sensitive-data processing; or secure customer credential storage and runtime use.
- Practical knowledge of applied cryptography and strong judgment about trust boundaries, failure modes, and compromise consequences.
- Experience changing critical systems without disrupting existing customers or making stored data inaccessible.
- Ability to take ambiguous technical problems from investigation through production rollout.
- Prior healthcare experience is helpful but not required.
- Bonus qualifications include HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, key rotation, PHI or PII detection and redaction, pseudonymization, tokenization, PKI, certificate systems, cryptographic signing, sensitive-data SaaS, healthcare, payments, identity, financial infrastructure, self-hosted or air-gapped deployments, AI-agent or LLM architectures, and startup experience.
About StackAI
Enterprise AI trusted by Finance, Risk and Operations teams. Power your AI transformation strategy with StackAI. Backed by YC and Google. We are a small dedicated team of insanely talented individuals relentlessly pushing the boundaries of what’s possible with AI. We are pioneering a new horizontal platform allowing anyone to build and deploy AI agents and automations. Companies across industries—including healthcare, legal, financial, logistics, and defense—use StackAI make their organizations faster, more efficient, and scalable, leveraging the power of AI. With strong backing from YC and Google, we're set to double our team size in 2026. This is an exciting time to join if you want to build a category-defining product with strong customer momentum. We're looking for user-centric, craft-focused, creative minds who work hard but don't take themselves too seriously. We're ambitious yet pragmatic. We move fast, but care about the important details. We're hiring for a range of roles. Reach out if you'd like to learn more!
