Offering global, personalized mental health care designed to help you feel more resilient, productive, and empowered.
Product Security Engineer
Location
United States
Posted
9 days ago
Salary
Not specified
No structured requirement data.
Job Description
Role Description
This role involves maintaining the security and privacy of our users as part of the security team at Modern Health. You will have organization-wide visibility to continuously support and monitor our commitment to privacy, security, and compliance.
- Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations in collaboration with engineering teams.
- Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to the evolving health tech landscape.
- Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices and agile delivery.
- Develop and advocate for cost-effective solutions to address complex application and product security challenges.
- Implement the adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions.
- Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
- Guide engineering teams in applying secure coding standards, providing resources and actionable feedback to foster a culture of security.
- Deploy, optimize, and manage security tooling such as SAST, DAST, Hashicorp Vault, and other industry-leading application security solutions.
- Participate in collaborative threat modeling initiatives for new features and evolving services, ensuring proactive risk identification and reduction.
- Conduct secure code reviews on services and applications built with modern frameworks and technologies.
- Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release.
- Collaborate on IT security initiatives, partnering with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and overall IT hygiene.
- Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations of applications and services.
Qualifications
- 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering.
- Hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security.
- Hands-on experience with at least one scripting language (Python and/or Bash preferred).
- Familiarity with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs.
- Excellent written and verbal communication skills.
Requirements
- Experience integrating security into agile product delivery.
- Ability to assess, prioritize, and execute on projects independently.
- Comfortable working in a fast-paced environment.
- Ability to thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications.
Benefits
- Medical / Dental / Vision / Disability / Life Insurance
- High Deductible Health Plan with Health Savings Account (HSA) option
- Flexible Spending Account (FSA)
- Access to coaches and therapists through Modern Health's platform
- Flexible Time Off
- Company-wide Collective Pause Days
- Parental Leave Policy
- Family Forming Benefit through Carrot
- Family Assistance Benefit through UrbanSitter
- Professional Development Stipend
- 401k
- Financial Planning Benefit through Origin
- Annual Wellness Stipend to use on items that promote your overall well being
- New Hire Stipend to help cover work-from-home setup costs
- Monthly Cell Phone Reimbursement
Job Requirements
- 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering.
- Hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security.
- Hands-on experience with at least one scripting language (Python and/or Bash preferred).
- Familiarity with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs.
- Excellent written and verbal communication skills.
- Experience integrating security into agile product delivery.
- Ability to assess, prioritize, and execute on projects independently.
- Comfortable working in a fast-paced environment.
- Ability to thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications.
Benefits
- Medical / Dental / Vision / Disability / Life Insurance
- High Deductible Health Plan with Health Savings Account (HSA) option
- Flexible Spending Account (FSA)
- Access to coaches and therapists through Modern Health's platform
- Flexible Time Off
- Company-wide Collective Pause Days
- Parental Leave Policy
- Family Forming Benefit through Carrot
- Family Assistance Benefit through UrbanSitter
- Professional Development Stipend
- 401k
- Financial Planning Benefit through Origin
- Annual Wellness Stipend to use on items that promote your overall well being
- New Hire Stipend to help cover work-from-home setup costs
- Monthly Cell Phone Reimbursement
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Specialist – Insider Threat
Cleveland ClinicYour source for health news, tips and information from one of the nation’s top hospitals.
Cybersecurity Specialist - Insider Threat protecting Cleveland Clinic's digital assets
This role leads and supports Assessment & Authorization (A&A) activities across various environments, ensuring continuous authorization readiness, validated security control effectiveness, and compliant documentation in eMASS. Key duties include executing the Risk Management Framework (RMF), analyzing scan results, developing POA&Ms, and supporting continuous monitoring execution.
Workday HCM Compensation Consultant
Meridian PartnersMaximize your ERP and Business Intelligence investments
The consultant will be responsible for configuring and deploying Workday Compensation solutions tailored to public sector regulatory needs, translating complex processes into efficient Workday configurations. This includes leading functional workstreams during implementations and providing ongoing production support and troubleshooting post-live.
The IT Security Architect defines and governs the security architecture for enterprise technology platforms across on-site, hybrid, and cloud environments, establishing technical standards and security guardrails for engineering teams. Key duties include designing security frameworks, defining identity and cloud security standards, and leading security architecture reviews and risk assessments.