Senior Product Security Engineer

Function HealthCanada, KS

About The Position

Function Health is building out a dedicated product security team to protect its members and platform as it scales. As a Senior Product Security Engineer, you will work closely with engineering and product teams to embed security into every stage of development: design, code, test, and deploy. This role is hands-on and impact-driven, requiring you to identify risks, build guardrails, and ship tools that enhance security without hindering team velocity. The engineering organization is moving towards AI-first code review, autonomous adversarial testing, and security gates that operate without human approval for low-risk changes. You will be instrumental in building the systems that make these advancements possible and safe. This is an opportunity for someone who thrives on solving complex technical problems, knows how to integrate security effectively into systems, and is excited about the future of AI-assisted engineering in the security domain.

Requirements

  • 5+ years of experience in product or application security, software engineering, or a combination of both.
  • Experience building or operating AI-assisted security tooling, such as an agent for code review, an automated triage pipeline, or custom security automation designed from scratch.
  • Strong Python experience.
  • Deep fluency in identifying and exploiting web, API, and application vulnerabilities, well beyond OWASP Top 10.
  • Experience embedding security into CI/CD, not just recommending it.
  • Ability to guide engineers through secure design decisions without slowing them down.
  • Proactively writes documentation and design docs.

Nice To Haves

  • Familiarity with FastAPI, LangChain, or agentic frameworks.
  • Experience with HIPAA or healthcare data.
  • Red teaming experience.
  • Experience with security architecture at scale.

Responsibilities

  • Design and deploy AI-powered security agents into CI/CD: automated code review, risk classification, escalation logic, and where possible, auto-remediation.
  • Build and operate the security tooling layer across our pipelines: SAST, SCA, secrets scanning, IaC validation, and supply chain integrity checks.
  • Conduct threat modeling, secure design reviews, and manual security assessments across our apps, APIs, and infrastructure.
  • Find vulnerabilities through proactive testing, not just scanner output, and drive them to remediation.
  • Partner with engineering teams across our product pillars as the embedded security voice in the room, without being a blocker.
  • Own the rollout of secure-by-default development frameworks and controls.
  • Connect application-level telemetry to detection and response systems.
  • Contribute to incident response and postmortems when product security is involved.
  • Shape our long-term product security strategy and roadmap.

Benefits

  • Competitive salary and benefits package
  • Flexible working hours
  • Dynamic work environment where creativity and innovation are encouraged
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service