Staff Software Engineer - Product Security

Maven Clinic · New York, NY; Remote, US (Hub cities) · Engineering

Posted 2026-08-05

Apply for this role →

What You’ll Do

Security Platform Engineering

Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance

Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA)

Implement observability and anomaly detection across microservices, data stores, and SaaS platforms

Establish Zero Trust principles and enforce least-privilege access company-wide

Develop compliance observability dashboards and automated evidence collection

Security Automation & Tooling

Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform)

Automate onboarding/offboarding, access reviews, and approvals

Integrate software-supply-chain security (SBOM, dependency scanning)

Develop or adopt AI-assisted security tooling to proactively identify risks

Automate policy enforcement, SAST/DAST scans, and compliance verification

Application & Data Security

Lead threat modeling and security architecture reviews for new products and services

Partner with product and data teams to embed secure-by-default design patterns

Ensure encryption, access tracking, and secure data handling across PHI workflows

Contribute to incident response, post-mortems, and continual improvement of security posture

Leadership & Collaboration

Act as Maven’s technical authority for security engineering

Mentor peers and promote secure coding and architecture practices

Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy

Champion an engineering culture of transparency, accountability, and continuous improvement

What You’ll Bring

Required

8+ years of software engineering experience, including 3+ in security infrastructure or application security

Proven ability to design and implement large-scale, distributed, cloud-native systems

Strong coding proficiency in Python, TypeScript, Go and/or Rust

Deep understanding of cloud security (GCP preferred; AWS/Azure welcome)

Experience with Kubernetes, containers, and infrastructure-as-code (Terraform)

Familiarity with security testing frameworks and secure SDLC principles

Excellent communication and documentation skills

Preferred

Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention

Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST)

Background in data security telemetry and threat detection

Familiarity with AI/ML security and AI-assisted analysis tools

Exposure to supply-chain security and CI/CD pipeline hardening

Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus

What Makes You a Great Fit

You take a pragmatic, automation-first approach to solving security problems

You balance rigor with velocity, enabling teams to move quickly without compromising trust

You communicate clearly with both technical and non-technical stakeholders

You’re curious, adaptable, and eager to lead initiatives from concept to production

You care deeply about our mission—building safer, smarter healthcare for women and families

The base salary range for this role is $221,000 - $260,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.

Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week  (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.

Apply for this role →

← Back to all jobs