Senior Product Security Engineer

Function HealthAustin, TX

About The Position

Function Health is building out a dedicated product security team to protect our members and platform as we scale. As a Senior Product Security Engineer, you'll work shoulder-to-shoulder with engineering and product teams to embed security into every stage of development: design, code, test, and deploy. This role is hands-on and impact-driven. You'll be expected to identify risks, build guardrails, and ship tools that raise the security bar without slowing teams down. Our engineering org is moving toward AI-first code review, autonomous adversarial testing, and security gates that run without human approval for low-risk changes. You'd be building the systems that make that possible and safe. If you've been waiting for a security role where the answer to "can we automate this?" is usually yes, this is it. We're looking for someone who thrives on solving hard technical problems, knows how to build security into systems the right way, and is excited about what AI-assisted engineering means for the future of the discipline.

Requirements

  • 5+ years of experience in product or application security, software engineering, or a combination of both.
  • You've built or operated AI-assisted security tooling, whether that's an agent doing code review, an automated triage pipeline, or custom security automation you designed from scratch.
  • Strong Python experience.
  • Deep fluency in identifying and exploiting web, API, and application vulnerabilities, well beyond OWASP Top 10.
  • Experience embedding security into CI/CD, not just recommending it.
  • You can guide engineers through secure design decisions without slowing them down.
  • You write documentation and design docs without being asked.

Nice To Haves

  • Familiarity with FastAPI, LangChain, or agentic frameworks is a plus.
  • Bonus: experience with HIPAA or healthcare data, red teaming, or security architecture at scale.

Responsibilities

  • Design and deploy AI-powered security agents into CI/CD: automated code review, risk classification, escalation logic, and where possible, auto-remediation.
  • Build and operate the security tooling layer across our pipelines: SAST, SCA, secrets scanning, IaC validation, and supply chain integrity checks.
  • Conduct threat modeling, secure design reviews, and manual security assessments across our apps, APIs, and infrastructure.
  • Find vulnerabilities through proactive testing, not just scanner output, and drive them to remediation.
  • Partner with engineering teams across our product pillars as the embedded security voice in the room, without being a blocker.
  • Own the rollout of secure-by-default development frameworks and controls.
  • Connect application-level telemetry to detection and response systems.
  • Contribute to incident response and postmortems when product security is involved.
  • Shape our long-term product security strategy and roadmap.

Benefits

  • competitive salary
  • benefits package
  • flexible working hours
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service