Software Engineer - Encryption & PHI

STACK.AI, LLC
United States
4 days ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$248,000.0 - $282,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Applications Architecture Software as a Service Customer Data Management Python (Programming Language) Key Management Public Key Infrastructure Tokenization Data Processing Large Language Models Amazon Virtual Private Cloud (VPC)
+2 more
Backend Hashicorp

Job description

We are looking for a senior Python engineer who has built security-critical product systems.

You will join the Core Engineering team and build the systems that determine how StackAI encrypts customer data, manages keys and signatures, handles PHI and PII, protects customer credentials, and enforces tenant and authentication boundaries.

We’re looking for an engineer who brings strong security judgment to the software they build: someone who can move between architecture and implementation, reason carefully about trust boundaries, and turn security requirements into reliable product capabilities.

This is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python and take projects from initial investigation and design through implementation, migration, rollout, and operation.

The systems you build will shape which sensitive and regulated workloads enterprises can run on StackAI and how confidently they can put them into production. What you’ll do

  • Build encryption and key-management systems. Design and evolve how customer data is encrypted, how keys are scoped and rotated, and how these systems work across hosted, VPC, and on-premises deployments.
  • Protect sensitive data. Build the controls that detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage.
  • Secure customer credentials. Protect the credentials and tokens customers provide to StackAI, from storage and access control through their use at runtime.
  • Strengthen product trust boundaries. Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication.
  • Create shared security foundations. Build Python services, libraries, and APIs that make security-critical behavior consistent and straightforward for other engineers to use.
  • Evolve live systems safely. Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback., Remote or Hybrid Mid level Mid level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Manage client teams in healthcare, oversee financial reporting, provide operational improvements, and coach staff. Requires strong finance background and leadership skills. Top Skills: Bill.ComIntaactMicrosoft Office SuiteNetSuiteQuickbooks Online

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Requirements

  • 4+ years of experience building and operating production backend systems.
  • Strong professional experience with Python in a substantial production codebase.
  • Hands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees.
  • Depth in at least one of the following:
  • Encryption and key management
  • Signing, authentication, sessions, or token infrastructure
  • Multi-tenant isolation
  • Sensitive-data processing
  • Secure storage and runtime use of customer credentials
  • Practical knowledge of applied cryptography
  • Experience changing critical systems without disrupting existing customers or making previously stored data inaccessible.
  • Strong judgment around trust boundaries, failure modes, and the consequences of compromise.
  • The ability to take an ambiguous technical problem from investigation through production rollout.

You do not need to have worked in every area listed above. We are looking for a strong software engineer with meaningful depth in security-critical systems and the ability to take ownership of adjacent problems.

Prior healthcare experience is helpful but not required. We care more about your ability to understand sensitive-data requirements and turn them into reliable product behavior. Bonus points

  • Experience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation
  • PHI or PII detection, redaction, pseudonymization, or tokenization
  • PKI, certificate systems, or cryptographic signing
  • Multi-tenant SaaS products handling sensitive customer data
  • Experience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain
  • Self-hosted, VPC, on-premises, or air-gapped deployments
  • AI-agent, LLM, or connector-based application architecture
  • Startup or growth-stage product experience

Benefits & conditions

Build and operate security-critical backend systems in Python, including encryption, key management, sensitive-data controls, credential protection, tenant isolation, authentication, signing, and token handling. Own projects end to end from investigation and architecture through implementation, migration, staged rollout, observability, and recovery. The role requires applied cryptography, strong trust-boundary judgment, and experience safely evolving systems handling sensitive or regulated data across cloud, VPC, and on-premises deployments. The summary above was generated by AI About StackAI, 5 Minutes Ago Remote or Hybrid 106K-160K Annually Senior level 106K-160K Annually Senior level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Manage tax compliance engagements, maintain client relationships, review tax documents, provide training and supervision, and ensure professional standards are met. Top Skills: AccountingCpaTax Compliance Wipfli

Manager, Accounting Advisory - Skilled Nursing Industry Clients

5 Minutes Ago Remote or Hybrid 109K-147K Annually Mid level 109K-147K Annually Mid level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Manage accounting advisory services for skilled nursing clients, provide financial insights, support budgeting and forecasting, mentor teams, and ensure high-quality reporting. Top Skills: Bill.ComIntaactMicrosoft Office SuiteNetSuiteQuickbooks Online Wipfli

About the company

StackAI is the enterprise AI transformation platform for organizations with regulated and complex operations. It gives teams one place to build, deploy, govern, and scale AI agents that can analyze data, connect to business systems, and carry out business-critical workflows.

Those agents need to work wherever an enterprise’s data and systems live. StackAI supports more than 100 enterprise integrations and can be deployed in our multi-tenant cloud, in a customer’s VPC, or on-premises-allowing organizations to bring AI into sensitive operational work while retaining control over where their agents and data run.

StackAI is an Asana company and continues to operate as its own product and brand.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:42 min

Deploying real-world tokens using developer portals and open-source studios

Luke Forrest Luke Forrest · World Congress 2026 Europe

4:18 min

Prioritizing communication and structural awareness over strict tool mastery

Liam Hurrel +1 · World Congress 2021

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · World Congress 2024

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all