> Markdown version of [/jobs/ext/1101552-staff-security-engineer](https://www.wearedevelopers.com/jobs/ext/1101552-staff-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff, Security Engineer - **Company:** Sprinter Health - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Continuous Integration, Amazon DynamoDB, Identity and Access Management, Python (Programming Language), Key Management, Network Security, Node.Js, Systems Development Life Cycle, Role-Based Access Control, Security Information and Event Management, Software Engineering, TypeScript, Software Vulnerability Management, Privacy Controls, Data Processing, Google Cloud, Cloud Platform System, Okta, Software Security, Model Validation, AWS AppSync, Cloudformation, Kubernetes, Infrastructure Automation Frameworks, Graphql, React Native, Functional Programming, Terraform, Devsecops, Serverless Computing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/be9c71eb-c802-4d45-a180-4efde4d5fa4d ## About the Role * Spent 8+ years in security engineering, cloud security, application security, infrastructure security, DevSecOps, or related roles * Built or meaningfully scaled a security function, security program, or major security domain in a high-growth environment * Operated as a senior technical owner for security across engineering, infrastructure, product, IT, and compliance stakeholders * Worked hands-on with cloud security in AWS, Google Cloud Platform, or similar cloud environments * Implemented security controls that support compliance frameworks such as HIPAA, SOC 2, HITRUST, ISO 27001, or similar * Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments * Partnered with engineering teams to embed security into architecture, development, CI/CD, and production operations * Worked with identity and access management systems such as Okta, Auth0, SSO, MFA, RBAC, or related tooling * Evaluated, selected, or implemented security tools such as SIEM, DAST, vulnerability scanners, CSPM, endpoint security, or monitoring platforms * Used scripting or infrastructure-as-code tools such as Python, Bash, Terraform, or similar to automate security workflows * Communicated security risks, tradeoffs, and priorities clearly to technical and non-technical stakeholders * Made practical risk decisions in environments where speed, ambiguity, compliance, and security all matter, * You have deep experience with HIPAA, SOC 2, HITRUST, or healthcare security and privacy requirements * You've supported customer, partner, or enterprise security reviews in a B2B or healthcare environment * You've helped prepare for or lead security audits and compliance assessments * You have experience with AI security, including secure AI application development, model risk, data privacy, adversarial risk, or AI governance * You've worked closely with product and engineering teams to make security usable, scalable, and developer-friendly * You have experience with container security, Kubernetes, network security, endpoint security, or encryption standards * You hold certifications such as CISSP, CISM, AWS Certified Security Specialty, CEH, or similar ## Description We're looking for a Staff Security Engineer to be Sprinter's first dedicated security hire and help build the foundation for how security scales across the company. This is a high-ownership role for someone who can operate strategically and hands-on. You'll define our security roadmap, strengthen our cloud and application security posture, support HIPAA, SOC 2, and HITRUST readiness, and partner closely with engineering, product, IT, legal, operations, and leadership to make security a core part of how we build and operate. As our first security function hire, you will not just execute against an existing program. You'll help decide what the program should be. That includes designing controls, implementing tools, driving vulnerability management, supporting partner security reviews, improving IAM, embedding security into the SDLC, and helping Sprinter make smart risk decisions as we scale. This role is ideal for someone who wants to build a security function from the ground up in a high-growth, mission-driven healthcare company. Office Location We are a hybrid company based in the Bay Area with offices in both San Francisco and Menlo Park. For this role, we are also open to considering remote candidates. We will give priority to candidates who are based in or open to working from the San Francisco Bay Area. What you will do * Build and lead Sprinter's security program as the company's first dedicated security hire * Define and execute a practical security roadmap across cloud infrastructure, application security, compliance, identity, vendor risk, and incident readiness * Design, implement, and maintain security controls that support HIPAA, SOC 2, and HITRUST requirements * Partner with legal, product, IT, engineering, and operations teams to ensure ongoing audit readiness and compliance maturity * Improve security across AWS and Google Cloud Platform environments, including IAM, networking, encryption, secrets management, and cloud-native application security * Evaluate and implement security tooling for vulnerability management, cloud security posture management, security monitoring, DAST, and related needs * Lead vulnerability management efforts across applications, infrastructure, cloud environments, and third-party systems * Coordinate penetration testing efforts, work with external security partners, and drive remediation with engineering teams * Embed security into the software development lifecycle through secure design reviews, CI/CD checks, developer guidance, and pragmatic security standards * Own or support partner, customer, and vendor security reviews, including questionnaires, risk assessments, and remediation planning * Strengthen identity and access management across internal systems, applications, and cloud environments * Develop clear security policies, procedures, documentation, and reporting for internal teams and senior leadership * Advise on AI security best practices as Sprinter adopts and builds AI-enabled systems, including data handling, model risk, application security, and privacy controls * Build strong working relationships across teams so security is viewed as a partner to the business, not a blocker, * AWS * Google Cloud Platform * Terraform and infrastructure-as-code tooling * TypeScript * Python * Bash * CI/CD systems * Okta * Auth0 * SIEM, DAST, vulnerability management, and cloud security tooling * Identity, access, and secrets management systems * Cloud networking and infrastructure tooling * Container and deployment systems * Serverless AWS, including AppSync, DynamoDB, Lambda, Amplify, CloudFormation, and Node * GraphQL * React Native and React Native for Web Equal Opportunity Statement Sprinter Health is an equal opportunity employer. We value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected classes. Beware of recruitment fraud and scams that involve fictitious job descriptions followed by false job offers. ## Related Videos - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [GraphQL + Apollo + Next.js: A Lovely Trio](https://www.wearedevelopers.com/videos/311-graphql-apollo-next-js-a-lovely-trio) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)