> Markdown version of [/jobs/ext/503859-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/503859-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - **Company:** Candid Health - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $240,000.0 - $310,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Data Integrity, Distributed Systems, Information Systems Security Architecture Professional - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c902c22e3c248c82 ## About the Role Do you have experience in Threat Modeling (Architecture security)?, * An Elite Technical Leader: You have 10+ years of experience in security engineering, with a proven track record of architecting secure systems across complex technical surface areas in both startup and scaled enterprise environments. * A Practitioner, Not Just a Theorist: You have driven security outcomes at scale. You know how to balance pragmatism with bulletproof defense-in-depth, and you excel at navigating the technical trade-offs required in a fast-moving engineering organization. * A Security Expert: You possess a deep, native understanding of sensitive, highly regulated datasets and the unique, high-stakes challenges of handling protected critical information * A Force Multiplier: You know how to code, architect, and influence. You are equally comfortable writing secure infrastructure-as-code, threat-modeling a distributed system, or standing in front of an enterprise customer's CISO to defend Candid's security posture. ## Description You will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance checklist-you will architect, build, and scale the technical systems that protect our customers and their patients. Operating as a high-influence individual contributor, you will partner directly with Engineering and Product leadership to ensure we ship features rapidly while maintaining an ironclad promise of data integrity. This is a role for a heavy-hitting technical leader who wants to set the security blueprint for a fast-growing health-tech platform. What You'll Do * Architect and Guide the Security Landscape: Serve as the ultimate technical authority for security at Candid. While you won't be managing HR lines, you will set the technical bar, mentor engineers, and help scale a world-class security engineering culture. * Design the Enterprise-Grade Roadmap: Lead the technical transition from a foundational security posture to a best-in-class, resilient enterprise architecture capable of defending complex healthcare data workflows. * Drive Strategy at the Leadership Level: Act as the subject matter expert who translates complex technical risks into business priorities. You will partner with executive leadership to stack-rank risks and embed security directly into Candid's overarching business strategy. * Bake Trust & Compliance into the Architecture: Translate rigorous frameworks like HIPAA, SOC2, SOC1, PCI, and HITRUST into concrete engineering requirements. You will ensure compliance is a living, automated process built into our code and infra, and you'll regularly serve as the expert technical voice in the room with our largest enterprise customers. * Evangelize a "Secure-by-Design" Culture: Level up our 200+ employees. Through threat modeling, secure coding practices, and cross-functional collaboration, you will embed a security-first mindset across every team from engineering to legal. * Own Vulnerability & Vendor Deep Dives: Oversee third-party penetration testing, dissect vendor architectures before integration, and ensure our production environments undergo continuous automated and manual scrutiny. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Best Practices for AI-Assisted Development of Distributed Systems](https://www.wearedevelopers.com/videos/100200-best-practices-for-ai-assisted-development-of-distributed-systems) - [Exploring 5 Key Applications of AI Abundance with Blockchain Assurance](https://www.wearedevelopers.com/videos/971-exploring-5-key-applications-of-ai-abundance-with-blockchain-assurance) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Your Distributed System Just Got a Brain. Now What?](https://www.wearedevelopers.com/videos/100017-your-distributed-system-just-got-a-brain-now-what) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)