Senior Software Engineer - Encryption & PHI

StackAISan Francisco, CA
$248,000 - $282,000

About The Position

We are looking for a senior Python engineer who has built security-critical product systems. You will join the Core Engineering team and build the systems that determine how StackAI encrypts customer data, manages keys and signatures, handles PHI and PII, protects customer credentials, and enforces tenant and authentication boundaries. We’re looking for an engineer who brings strong security judgment to the software they build: someone who can move between architecture and implementation, reason carefully about trust boundaries, and turn security requirements into reliable product capabilities. This is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python and take projects from initial investigation and design through implementation, migration, rollout, and operation. The systems you build will shape which sensitive and regulated workloads enterprises can run on StackAI and how confidently they can put them into production.

Requirements

  • 4+ years of experience building and operating production backend systems.
  • Strong professional experience with Python in a substantial production codebase.
  • Hands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees.
  • Depth in at least one of the following: Encryption and key management, Signing, authentication, sessions, or token infrastructure, Multi-tenant isolation, Sensitive-data processing, Secure storage and runtime use of customer credentials
  • Practical knowledge of applied cryptography
  • Experience changing critical systems without disrupting existing customers or making previously stored data inaccessible.
  • Strong judgment around trust boundaries, failure modes, and the consequences of compromise.
  • The ability to take an ambiguous technical problem from investigation through production rollout.

Nice To Haves

  • Prior healthcare experience is helpful but not required. We care more about your ability to understand sensitive-data requirements and turn them into reliable product behavior.
  • Experience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation
  • PHI or PII detection, redaction, pseudonymization, or tokenization
  • PKI, certificate systems, or cryptographic signing
  • Multi-tenant SaaS products handling sensitive customer data
  • Experience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain
  • Self-hosted, VPC, on-premises, or air-gapped deployments
  • AI-agent, LLM, or connector-based application architecture
  • Startup or growth-stage product experience

Responsibilities

  • Build encryption and key-management systems. Design and evolve how customer data is encrypted, how keys are scoped and rotated, and how these systems work across hosted, VPC, and on-premises deployments.
  • Protect sensitive data. Build the controls that detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage.
  • Secure customer credentials. Protect the credentials and tokens customers provide to StackAI, from storage and access control through their use at runtime.
  • Strengthen product trust boundaries. Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication.
  • Create shared security foundations. Build Python services, libraries, and APIs that make security-critical behavior consistent and straightforward for other engineers to use.
  • Evolve live systems safely. Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback.

Benefits

  • As part of Asana, you will be able to draw on established security and infrastructure teams when a problem crosses application and platform boundaries.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service