> Markdown version of [/jobs/ext/1216925-security-engineer](https://www.wearedevelopers.com/jobs/ext/1216925-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Echo Neurotechnologies Corporation - **Location:** San Francisco, CA, United States - **Salary:** $175,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Database, Cyber Security, Computer Programming, Databases, Federal Information Processing Standards (FIPS), Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Public Key Infrastructure, Windows PowerShell, Proprietary Software, Role-Based Access Control, Secure Coding, EndPointSecurity, Wi-Fi Technology, Google Cloud, Transport Protocols, Security Orchestration, Automation & Response - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=918354cd68f5631e ## About the Role * Security Architecture: Strong foundations in secure architecture across cloud environments (AWS, Azure, GCP), API layers, and client-side applications (mobile/desktop) utilizing modern IAM, RBAC/ABAC, secret management and industry security best practices. * Device Security: Proven experience designing security controls for local device connections (BLE, Wi-Fi, USB) and executing device-level access controls, utilizing PKI for secure device provisioning and identity management. * Network & Data: Deep understanding of secure transport protocols (HTTPS/TLS) and data cryptography algorithms (e.g., ECDH, ECDSA, AES-GCM) for data at-rest and in-transit. * Lifecycle Risk & Threat Modeling: Hands-on experience executing threat modeling (STRIDE, Attack Trees), assessing vulnerability severity via CVSS, and monitoring threat databases (NIST NVD, CISA KEV) to mitigate risks. * Security Automation: Proficient in programming (e.g., Python, Bash, or PowerShell) to identify and address security gaps, automate security workflows and build custom tooling. * Cross-Functional Leadership & Education: Proven ability to lead cross-functional engineering teams, mentor developers, and communicate technical designs, risks, and mitigations clearly to stakeholders., * Experience working with PHI / PII * Prior experience securing connected physical devices or embedded systems * Hands-on experience with security controls in the Azure ecosystem. * Experience working within a formal Quality Management System (QMS) and following strict procedures for traceabilities, design inputs, and risk documentation. * Familiarity with medical device cybersecurity frameworks, risk management standards, and regulations (e.g., FDA Section 524B, ISO 14971, FIPS-3) ## Description We are seeking an experienced Security Engineer to lead security architecture, implementation, and maintenance of our cloud-based data platform, applications and medical devices. In this role, you will act as the primary technical expert working alongside our internal quality stakeholders and external security vendors. Your mission is to identify, implement, automate and monitor the various security aspects of our systems in a highly regulated environment. You will ensure our platform, application, and devices are secure and strictly adhere to our corporate standards and government regulations., * Own Overall Portfolio Security: Lead security across our portfolio of devices, including establishing security review processes for all new products and features. * Architect Security Posture: Establish a balanced, pragmatic approach to security architecture and overall defense posture. * Drive Product Lifecycle Security: Guide security features through the complete product lifecycle, from developing requirements and threat modeling to managing cybersecurity documentation, vulnerability tracking, and continuous monitoring. * Prototype & Educate: Prototype security requirements and educate the broader engineering team on secure coding best practices. * Collaborate Cross-Functionally: Work cross-functionally with internal software, hardware, quality, and regulatory teams. Own and manage relationships with external security vendors (e.g., penetration testing partners). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)