Pomelo Care

Transforming outcomes for moms and babies through personalized, accessible, evidence-based virtual care.

Senior Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

9 hours ago

Salary

$175K - $200K / year

PythonGoKotlinOWASP Top 10Google Cloud PlatformGit Hub Advanced SecuritySentryFullstoryStytchHIPAASOC 2HITRUSTData DE IdentificationData AnonymizationThreat ModelingSASTDependency ManagementAuthenticationAuthorization

Job Description

About us

Pomelo Care is the national leader in evidence-based healthcare for women and children. We deliver personalized, high-quality clinical interventions from reproductive care and pregnancy, infant care and pediatrics, to hormonal health through perimenopause and menopause, with long-term preventive care and condition management. Our model delivers 24/7 multispecialty care to address the medical, behavioral, and social factors that most significantly impact outcomes for women and children. We partner with payers, employers, and providers to expand access to quality healthcare across the system.

What you'll do

As our first Product Security Engineer, you will sit at the intersection of Security and Software Engineering. Reporting directly to the CISO, you will be a "Security Builder": embedded within our engineering teams with the autonomy needed to build the automation, tools, and workflows that make security a seamless part of the software development lifecycle.

You aren't just finding bugs; you are building the systems that prevent and fix them at scale. Your work will be centered on three core strategic pillars:

  • Secure architecture and auth: you will design and implement auth enhancements such as magic link improvements and access/audit log features to monitor access and improve transparency.
  • Privacy engineering: you will lead the privacy engineering initiatives including DSAR integration, building automated data deletion capabilities directly into the Pomelo mobile app and our internal platform to ensure seamless compliance. You will also help improve privacy-preserving data de-identification and anonymization as needed.
  • Full-cycle remediation: you will own the end-to-end pentest-to-fix lifecycle. This means you don't just triage reports; you write the code to fix penetration test findings, remediate SAST issues, and build greenkeeping systems for high-volume dependency patching with regression testing.

Beyond these pillars, you will serve as a high-leverage engineering partner to the broader InfoSec team by:

  • Building secure-by-default libraries: reducing the load on core Software Engineering by creating internal libraries and patterns that make security the default path.
  • Threat modeling: partnering with engineering leads to conduct threat modeling and ensure secure design at the earliest stages of the development process.
  • Scaling through collaboration: as a security resource embedded in our engineering teams, you will help engineering squads navigate complex security use cases, translating GRC requirements into elegant code rather than manual checklists.

Who you are

You’re an enthusiastic and collaborative engineer who enjoys solving meaningful problems through code. You view security as a product challenge, and you believe the best way to secure a system is to make the "secure way" the "easy way." In particular, you:

  • Are a builder first: Have 5+ years of software engineering experience with a strong foundation in computer science and a track record of shipping production-grade code (Python, Go, Kotlin or similar).
  • Have a security mindset: You understand the OWASP Top 10, identity flows and prompt injections, but you’d rather build a system that eliminates a class of vulnerability than manually triage individual alerts. You believe security expertise should be embedded into the development process, not bolted on at the end.
  • Are an automation enthusiast: you enjoy tackling complex problems with practical automation and are keeping up with trends in LLM agents to multiply your engineering impact.
  • Navigate ambiguity: as a floating resource across various engineering teams, you are comfortable context-switching and can quickly build rapport with different engineering teams to understand their needs.

We’ll be super excited if you

  • Have experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.
  • Have prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.
  • Have experience building data infrastructure that supports AI/ML workloads,internal developer platforms and privacy preserving data de-identification and anonymization techniques.
  • Have previously worked in a fast-paced, product-oriented startup environment.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We also offer:

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $175,000 to $200,000. We expect most candidates to fall in the middle of the range.

 

#LI-Remote

Potential Fraud Warning


Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information.

Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com.

If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at careers@pomelocare.com  to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.

Job Requirements

  • 5+ years of software engineering experience with a strong foundation in computer science.
  • Track record of shipping production-grade code (Python, Go, Kotlin or similar).
  • Understanding of the OWASP Top 10, identity flows, and prompt injections.
  • Experience with automation and keeping up with trends in LLM agents.
  • Comfortable context-switching and building rapport with different engineering teams.
  • Experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.
  • Prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.
  • Experience building data infrastructure that supports AI/ML workloads, internal developer platforms, and privacy-preserving data de-identification and anonymization techniques.
  • Previous work in a fast-paced, product-oriented startup environment.

Benefits

  • Competitive healthcare benefits.
  • Generous equity compensation.
  • Unlimited vacation.
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship).

Related Categories

Related Job Pages

More Security Engineer Jobs

Senior Security Engineer

Flex

Flex splits your bills into smaller, stress-free payments throughout the month. Start today with your rent bill!

Security Engineer9 hours ago
Full TimeRemoteTeam 201-500Since 2019H1B Sponsor

This role involves owning product security reviews end-to-end, including threat modeling and architecture review for new features, and driving the secure development lifecycle across engineering teams. Responsibilities also include performing security assessments, investigating incidents, and building security automation tooling to scale reviews.

Application securityThreat modelingOWASP Top 10API securityAWSSASTDASTPenetration testingIncident responseSDLCSecure codingAuthenticationAuthorizationSOC 2PCI DSSNYDFSCode review
United States
$132K - $195K / year

Cybersecurity Specialist

Abbott

Abbott is a global healthcare leader that helps people live more fully at all stages of life. Our portfolio of life-changing technologies spans the spectrum of healthcare, with leading businesses and products in diagnostics, medical devices, nutritionals and branded generic medicines. Our 115,000 colleagues serve people in more than 160 countries.

Security Engineer9 hours ago
Full TimeRemoteTeam 10,001+Since 1888H1B Sponsor

Cybersecurity Specialist managing security risks for Abbott's diabetes management technologies

AWSCloudCyber SecurityKubernetesLinux
United States
$78K - $156K / year

Security Architect

Tebra

We empower independent practices to bring modernized care to patients everywhere.

Security Engineer9 hours ago
Full TimeRemoteTeam 501-1,000H1B Sponsor

Security Architect designing security for hybrid and cloud environments at Tebra

BigQueryCloudCyber SecurityGoogle Cloud PlatformKubernetesPython
United States
$178.5K - $203.5K / year
Full TimeRemoteTeam 10,001+Since 2020H1B No Sponsor

Senior Manager overseeing security for Raytheon’s international operations

Massachusetts
$132.4K - $251.6K / year