← Back to jobs

Senior Product Security Engineer (Application Security & Cloud Security)

Location
New York City, NY
Work type
Full Time
Posted
2026-08-03

Job description

What You’ll Be Working On

The engineering organization builds cloud-native software that processes sensitive healthcare information and powers mission-critical operational workflows for providers across the country.

As a Senior Product Security Engineer, you’ll help secure every stage of how software gets built and deployed, including:

Customer-facing web applications, APIs, and backend services
Cloud-native infrastructure supporting production healthcare workloads
Identity, authentication, authorization, and secrets management across distributed systems
CI/CD pipelines, infrastructure-as-code, container platforms, and developer tooling
Threat modeling for new platform capabilities and architectural initiatives
Security automation that enables engineering teams to ship software quickly without sacrificing security

About The Role

We are hiring a Senior Product Security Engineer to help design, build, and mature the security foundations of a rapidly growing healthcare technology platform.

This is a deeply hands-on engineering role for someone who enjoys partnering directly with software engineers to solve security challenges before they become production problems.

Rather than acting as a traditional security gatekeeper, you will embed with engineering teams, influence architectural decisions, improve developer workflows, and build scalable security capabilities that allow engineering teams to move quickly while maintaining a high level of trust.

The ideal candidate brings strong expertise in either Application Security or Cloud Security, with the ability and interest to operate comfortably across both domains.

What You Will Do

Influence the security architecture of new products, services, APIs, cloud infrastructure, and platform capabilities from initial design through production deployment
Lead threat modeling sessions and security architecture reviews for customer-facing systems and engineering initiatives
Partner directly with software engineers to design secure, scalable solutions without slowing product development
Review application code, APIs, cloud infrastructure, and system designs to identify meaningful security risks and practical remediation strategies
Design and improve secure authentication, authorization, identity management, API security, and secrets management practices
Improve security automation across CI/CD pipelines, infrastructure-as-code, container platforms, cloud environments, and developer tooling
Build reusable security frameworks, paved roads, and engineering standards that make secure software development easier by default
Identify, prioritize, and drive remediation of security risks across applications, infrastructure, and production environments
Partner with Engineering, Platform, Infrastructure, Product, and Leadership teams to continuously improve Product Security maturity
Balance engineering velocity, customer needs, and long-term platform security when making technical decisions
Leverage modern AI-assisted development tools such as Claude, GitHub Copilot, Cursor, and similar technologies to improve productivity and accelerate engineering workflows

What You Will Be Working On

6+ years of experience in Product Security, Application Security, Security Engineering, Cloud Security, or a closely related role
Strong experience securing modern cloud-native SaaS applications operating in production environments
Deep understanding of secure software development practices and modern application security principles
Experience reviewing application architecture, APIs, distributed systems, and cloud-native platforms
Strong knowledge of authentication, authorization, identity management, cryptography, secrets management, and secure API design
Experience securing AWS, GCP, Kubernetes, containers, infrastructure-as-code, and modern cloud environments
Experience with secure SDLC, threat modeling, vulnerability management, and developer security tooling
Comfortable reading production code and collaborating directly with engineering teams to improve software security
Strong communication skills with the ability to explain security risks, architectural decisions, and engineering tradeoffs clearly
Startup, scale-up, or high-growth technology company experience preferred

Senior Level Expectations

You have partnered directly with software engineering organizations to build secure products from design through production
You have influenced architectural decisions that improved security without slowing engineering velocity
You think beyond finding vulnerabilities and focus on building secure systems that scale
You have created reusable security frameworks, automation, and engineering patterns that improve how software gets built
You are comfortable operating in ambiguous environments where strong technical judgment is required
You balance developer experience, product delivery, and long-term platform security when making engineering decisions
You remain deeply hands-on while influencing security strategy across multiple engineering teams

Modern Development Approach

Experience using AI-assisted development tools such as Claude, GitHub Copilot, Cursor, or similar technologies
Strong engineering mindset with the ability to automate repetitive security work wherever possible
Builder mentality with an emphasis on enabling engineering teams rather than blocking them
Comfortable collaborating across Engineering, Platform, Infrastructure, Product, Compliance, and Leadership teams
Pragmatic approach to balancing security, engineering velocity, maintainability, and business priorities
Strong product thinking with the ability to connect security decisions to customer trust and business outcomes

Nice to Have

Experience building or securing customer-facing SaaS platforms
Healthcare technology experience
Experience working in regulated industries such as healthcare, fintech, or enterprise SaaS
Experience securing APIs, distributed systems, microservices, and event-driven architectures
Kubernetes, Docker, and cloud-native security expertise
Infrastructure-as-code security experience (Terraform, CloudFormation, Pulumi, or similar)
Experience implementing developer security tooling and automated security testing
Experience with GCP or multi-cloud environments
Experience incorporating AI-assisted development into secure software engineering workflows

Original source