Product Security Engineer

Modern Health
$101,405 - $140,400Remote

About The Position

Modern Health is seeking a Product Security Engineer to maintain the security and privacy of its users. This role offers organization-wide visibility and the opportunity to use engineering and security skills to make a direct impact. The engineer will analyze vulnerabilities, mitigate risks through automation, and collaborate with other engineers to securely release and maintain software, infrastructure, and an information security management system. This position is part of the Product Security (ProdSec) team, reports to the Head of Security, and can be based anywhere in the United States. It's a chance to be a security leader at a fast-growing company and lay the foundation for future security initiatives.

Requirements

  • Passionate and confident team member that takes pride and ownership in the work you do.
  • Deeply familiar with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs.
  • Support the adoption of application and product security best practices across engineering teams and contribute to business-wide security initiatives.
  • Hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security.
  • Hands-on experience with at least one scripting language (Python and/or Bash preferred).
  • Thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications.
  • Able to assess, prioritize, and execute on projects independently.
  • Comfortable working in a fast-paced environment.
  • Excellent written and verbal communication skills.
  • 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering.
  • Experience integrating security into agile product delivery.
  • Experience reviewing code changes with software engineers and giving security feedback in the review process.
  • Experience building or applying security controls for AI systems and using AI to improve day-to-day security engineering workflows, including code review, threat modeling, vulnerability management, and security assessments.
  • Experience assessing and improving AWS cloud posture through IAM and access reviews, network and environment segmentation, vulnerability management, centralized logging, detection, and secure CI/CD or Terraform controls.
  • Applicants must be able to maintain work authorization for the duration of employment without employer sponsorship or employer-provided training plans or attestations.

Nice To Haves

  • Working at a high growth startup
  • Working on SaaS software
  • Working in Health Tech
  • Software engineering experience

Responsibilities

  • Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations in collaboration with engineering teams.
  • Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to the evolving health tech landscape.
  • Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices and agile delivery.
  • Develop and advocate for cost-effective solutions to address complex application and product security challenges.
  • Implement the adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions.
  • Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
  • Guide engineering teams in applying secure coding standards, providing resources and actionable feedback to foster a culture of security.
  • Deploy, optimize, and manage security tooling such as SAST, DAST, Hashicorp Vault, and other industry-leading application security solutions.
  • Participate in collaborative threat modeling initiatives for new features and evolving services, ensuring proactive risk identification and reduction.
  • Conduct secure code reviews on services and applications built with modern frameworks and technologies.
  • Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release.
  • Collaborate on IT security initiatives, partnering with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and overall IT hygiene.
  • Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations of applications and services.

Benefits

  • Medical / Dental / Vision / Disability / Life Insurance
  • High Deductible Health Plan with Health Savings Account (HSA) option
  • Flexible Spending Account (FSA)
  • Access to coaches and therapists through Modern Health's platform
  • Flexible Time Off
  • Company-wide Collective Pause Days
  • Parental Leave Policy
  • Family Forming Benefit through Carrot
  • Family Assistance Benefit through UrbanSitter
  • Professional Development Stipend
  • 401k
  • Financial Planning Benefit through Origin
  • Annual Wellness Stipend
  • New Hire Stipend
  • ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more
  • Monthly Cell Phone Reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service