All roles

[Remote] Staff Software Engineer - Product Security

Remote · USA Full-time New today

Note: The job is a remote job and is open to candidates in USA. Maven Clinic is the world's largest virtual clinic for women and families, committed to improving healthcare access and outcomes. They are seeking a Staff Software Engineer specializing in Product Security to design and implement scalable security infrastructure, automate security processes, and lead security architecture reviews while collaborating cross-functionally to enhance the company's security posture.

Responsibilities

  • Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance
  • Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA)
  • Implement observability and anomaly detection across microservices, data stores, and SaaS platforms
  • Establish Zero Trust principles and enforce least-privilege access company-wide
  • Develop compliance observability dashboards and automated evidence collection
  • Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform)
  • Automate onboarding/offboarding, access reviews, and approvals
  • Integrate software-supply-chain security (SBOM, dependency scanning)
  • Develop or adopt AI-assisted security tooling to proactively identify risks
  • Automate policy enforcement, SAST/DAST scans, and compliance verification
  • Lead threat modeling and security architecture reviews for new products and services
  • Partner with product and data teams to embed secure-by-default design patterns
  • Ensure encryption, access tracking, and secure data handling across PHI workflows
  • Contribute to incident response, post-mortems, and continual improvement of security posture
  • Act as Maven’s technical authority for security engineering
  • Mentor peers and promote secure coding and architecture practices
  • Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy
  • Champion an engineering culture of transparency, accountability, and continuous improvement

Skills

  • 8+ years of software engineering experience, including 3+ in security infrastructure or application security
  • Proven ability to design and implement large-scale, distributed, cloud-native systems
  • Strong coding proficiency in Python, TypeScript, Go and/or Rust
  • Deep understanding of cloud security (GCP preferred; AWS/Azure welcome)
  • Experience with Kubernetes, containers, and infrastructure-as-code (Terraform)
  • Familiarity with security testing frameworks and secure SDLC principles
  • Excellent communication and documentation skills
  • Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention
  • Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST)
  • Background in data security telemetry and threat detection
  • Familiarity with AI/ML security and AI-assisted analysis tools
  • Exposure to supply-chain security and CI/CD pipeline hardening
  • Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus

Benefits

  • Equity
  • Benefits
  • Employer-covered health, dental, and insurance plan options
  • Maven for Mavens: access to the full platform and specialists, including care for mental health, reproductive health, family planning and pediatrics.
  • Whole-self care through wellness partnerships
  • Hybrid work, in office meals, and work together days
  • 16 weeks 100% paid parental leave and new parent stipend (for Mavens who've been with us for 1 year+)
  • Annual professional development stipend and access to a personal career coach through Maven for Mavens
  • 401K matching for US-based employees, with immediate vesting

Company Overview

  • Maven is a digital health platform that works with health plans and employers to offer virtual services for women’s and family health. It was founded in 2014, and is headquartered in New York, New York, USA, with a workforce of 201-500 employees. Its website is http://www.mavenclinic.com.
  • Company H1B Sponsorship

  • Maven Clinic has a track record of offering H1B sponsorships, with 5 in 2025, 5 in 2024, 8 in 2023, 2 in 2022. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    Related roles

    [Remote] Senior Director, Product Management & Patient Experience

    Remote · USA Full-time

    [Remote] Senior Manager, Revenue Accounting (USA - Remote)

    Remote · USA Full-time

    [Remote] Technical Account Consultant (Payroll)

    Remote · USA Full-time

    [Remote] Account Executive, LE GBS/Sales Practice

    Remote · USA Full-time

    [Remote] Account Executive, LE, GBS

    Remote · USA Full-time

    [Remote] Implementation Consultant

    Remote · USA Full-time

    [Remote] Parts Global Sales Account Manager

    Remote · USA Full-time

    [Remote] Sr. Principal Program Manager - AI Transformation

    Remote · USA Full-time

    [Remote] Project Setup Accountant

    Remote · USA Full-time

    [Remote] Lead Machine Learning Engineer

    Remote · USA Full-time

    Experienced Customer Service Representative – Remote Work Opportunity with arenaflex for Delivering Exceptional Travel Experiences

    Remote · USA Full-time

    Experienced Remote Live Chat Support Specialist - Flexible Hours, Competitive Pay, and Career Growth Opportunities at blithequark

    Remote · USA Full-time

    Dedicated and Results-Driven Customer Service Representative for blithequark Amazon Store – Delivering Exceptional Customer Experiences and Driving Business Growth

    Remote · USA Full-time

    Strategic Account Executive, National Accounts

    Remote · USA Full-time

    [Remote] Marine Engineer (Diesel)

    Remote · USA Full-time

    Experienced Scheduling and Customer Service Agent - Virtual Sales and Customer Experience Expert

    Remote · USA Full-time

    Experienced Virtual Chat Assistant – Delivering Exceptional Customer Service in a Dynamic Remote Environment

    Remote · USA Full-time

    SOC Engineer (Incident Response)

    Remote · USA Full-time

    Experienced Home Sewer Work from Home Specialist – Urgent Hire for Industrial Sewing and Textile Production

    Remote · USA Full-time

    Vegetation Management Ground Person

    Remote · USA Full-time