> Markdown version of [/jobs/ext/2851115-security-engineer](https://www.wearedevelopers.com/jobs/ext/2851115-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Metriport Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Audit Trail, User Authentication, Cloud Computing Security, Cyber Security, Continuous Integration, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Identity and Access Management, Virtual Private Networks (VPN), Network Architecture, Scrum Methodology, Role-Based Access Control, RSA (Cryptosystem), Transport Layer Security, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/0bd03c22-0c8d-473a-82ba-a2c5642669c9/senior-security-engineer ## About the Role In a nutshell, we're looking for a security engineer with the following specific qualities: * You're entrepreneurial-minded, with an olympian-level work ethic (nearly our entire engineering team consists of former founders). * You are passionate about security and are excited to own security related projects within the company end-to-end. * You are confident in your ability to build scalable systems across the full stack, and people usually come to you for technical guidance. * You believe you can solve any problem that comes at you, and don't shy away from diving deep into areas where you may lack domain expertise. * You have a strong sense of ownership over your work, and have demonstrated ability to lead others. * You know how to move fast - while still maintaining a strong security posture. * You care more about the end result and delivering value, rather than what new and frilly tech is being used under the hood for a given feature. * When someone scopes out a project with an ETA of 3 weeks, you ask yourself "why can't it be done in 3 days?". * You're a hacker at heart, and have a good sense of what rules should, and shouldn't, be broken., * You have 6+ years experience in security engineering and information security. * You're located in San Francisco or the Bay Area (or willing to relocate). * Familiar with HIPAA compliant environments. * Experience rolling out and maintaining security frameworks like SOC 2, NIST, HITRUST, FedRAMP, etc. * Experience rolling out data protection technologies like SSO, MFA, VPN, FIPS, etc. * Experience with organizational secret management. * Experience implementing SCA, SAST, DAST in CICD workflows. * Experience with Mobile Device Management (MDM). * Proficiency in cloud security & networking on AWS - IAM, WAF, KMS, etc. * Proficiency in authentication, cryptography, encryption, and security protocols such as: mTLS, RSA, SSL, HMAC, RBAC, etc. * Bonus: experience with IHE profiles (ATNA, CT, XUA). ## Description After quickly ramping up using our comprehensive onboarding materials to get familiar with our domain, product, and codebase, the goal would be to get you shipping product directly to customers as quickly as possible. Specifically, day to day, this looks like: * Evangelizing security across Metriport's growing team - we will look to you for guidance, and training. * Driving full-stack security projects , big and small, end-to-end from ideation to production rollout.These projects could include things like: + Implement an enterprise-grade audit logging solution for a new national healthcare network infrastructure stack. + Implement fine grained RBAC on the API key access layer, and more robust roles on our UIs. + Help us revamp our internal security policies and put tools in place to keep the platform, and employees, secure while still allowing the team to be efficient. * Helping the engineering team with PR reviews with a security-focused lens. * Work with the Go to Market team to complete customer security assessments and questionnaires. * Work with the engineering team to harden security across the development lifecycle - think secret management, access controls, and vulnerability scanning. * Managing your own work in Linear. * Participating in bi-weekly sprint planning / retro sessions, and quarterly planning sessions. * Attending a daily 30 minute remote stand-up at 7:30am PST Mon-Fri (our only regular mandatory meeting). ## Related Videos - [Coffee with Developers - Cassidy Williams - ](https://www.wearedevelopers.com/videos/912-coffee-with-developers-cassidy-williams) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Systems Thinking for Performance: How to Diagnose and Fix Slow Systems without Guessing](https://www.wearedevelopers.com/videos/2103-systems-thinking-for-performance-how-to-diagnose-and-fix-slow-systems-without-guessing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)