> Markdown version of [/jobs/ext/1891573-security-engineer](https://www.wearedevelopers.com/jobs/ext/1891573-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** The Modern - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Starter - **Salary:** $101,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Django Web Framework, Identity and Access Management, Mobile Application Software, Python (Programming Language), PostgreSQL, Systems Development Life Cycle, Redis, Release Management, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Datadog, Scripting, Information Security Management System, Flask (Web Framework), Software Security, AWS ECS, Gitlab, Sentry, Hashicorp, Terraform, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 1, 2026 - **Apply:** https://www.workingnomads.com/job/go/1766240/ ## About the Role * You are a passionate and confident team member that takes pride and ownership in the work you do. * You are deeply familiar with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs. * You support the adoption of application and product security best practices across engineering teams and contribute to business-wide security initiatives. * You have hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security. * You have hands-on experience with at least one scripting language (Python and/or Bash preferred). * You thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications. * You are able to assess, prioritize, and execute on projects independently. * You are comfortable working in a fast-paced environment. * You have excellent written and verbal communication skills. * You bring 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering. * You have experience integrating security into agile product delivery. * Immigration sponsorship is not available for this position. Applicants must be able to maintain work authorization for the duration of employment without employer sponsorship or employer-provided training plans or attestations (including, for example, the Form I-983 required for STEM OPT)., * Working at a high growth startup * Working on SaaS software * Working in Health Tech * Software engineering experience ## Description Maintaining the security and privacy of our users is paramount to Modern Health's mission. As a member of the security team you will have organization-wide visibility to continuously support and monitor our commitment to privacy, security, and compliance. This is a unique opportunity to use your engineering and security skills to make a direct impact in people's lives. We need a security engineer who can pick up and understand complex technical areas quickly, mitigate risk by increasing automation in security domains, and work with other engineers to securely release and maintain software, infrastructure, and an information security management system, while always working to increase our security and compliance posture. This role will be part of the Product Security (ProdSec) team, report to the Head of Security, and can be based anywhere in the United States. This is a unique opportunity to be a security leader at a fast growing company, and the work done by this position will lay the foundation for security at Modern Health for years to come! Don't have direct security experience but are a passionate developer or Software engineer with AWS experience that is interested in Security? Please apply! This position is not eligible to be performed in Hawaii., * Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations in collaboration with engineering teams. * Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to the evolving health tech landscape. * Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices and agile delivery. * Develop and advocate for cost-effective solutions to address complex application and product security challenges. * Implement the adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions. * Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations. * Guide engineering teams in applying secure coding standards, providing resources and actionable feedback to foster a culture of security. * Deploy, optimize, and manage security tooling such as SAST, DAST, Hashicorp Vault, and other industry-leading application security solutions. * Participate in collaborative threat modeling initiatives for new features and evolving services, ensuring proactive risk identification and reduction. * Conduct secure code reviews on services and applications built with modern frameworks and technologies. * Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release. * Collaborate on IT security initiatives, partnering with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and overall IT hygiene. * Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations of applications and services. *, * AWS: ECS and cloud hosting * Gitlab: CI/CD * Python: Django, Flask, aiohttp * Data: PostgreSQL, Redis * Monitoring: Datadog and Sentry * IaC: Terraform, Packer ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)