Lead Security Engineer
Listed on 2026-02-16
-
IT/Tech
Cybersecurity
Overview
Millions of people across the country are navigating mental health conditions, substance use disorders, and eating disorders, but too often, they’re met with barriers to care. From limited local options and long wait times to treatment that lacks personalization, behavioral healthcare can leave people feeling unseen and unsupported.
Charlie Health exists to change that. Our mission is to connect the world to life-saving behavioral health treatment. We deliver personalized, virtual care rooted in connection—between clients and clinicians, care teams, loved ones, and the communities that support them. By focusing on people with complex needs, we’re expanding access to meaningful care and driving better outcomes from the comfort of home.
As a rapidly growing organization, we re reaching more communities every day and building a team that’s redefining what behavioral health treatment can look like. If you re ready to use your skills to drive lasting change and help more people access the care they deserve, we’d love to meet you.
About the RoleCharlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will be the subject matter expert on application security, guiding the business in building secure, scalable and HIPAA-compliant software solutions.
We’re a team of passionate, forward-thinking professionals eager to take on the challenge of the mental health crisis and play a formative role in providing life-saving solutions. If you’re inspired by our mission and energized by the opportunity to increase access to mental healthcare and impact millions of lives in a profound way, apply today.
Responsibilities- Security Integration & Guidance
- Collaborate with product and IT engineering teams to design secure applications and features.
- Educate developers on secure coding practices and security testing.
- Serve as a subject matter expert on internal application security and SDLC controls.
- Assessment & Threat Modeling
- Conduct code reviews, threat models and risk assessments to identify and mitigate vulnerabilities early.
- Perform internal penetration testing and support incident response for application-level issues.
- Continuously monitor the threat landscape to proactively adjust defenses and strategies.
- Tooling & Automation
- Develop and implement tools and frameworks to integrate security into CI/CD pipelines.
- Work with teams to build and enforce secure SDLC controls in a fast-paced agile environment.
- Own and enhance application vulnerability management and remediation processes.
- Collaboration & Policy
- Lead implementation of security policies, standards and remediation processes.
- Work cross-functionally to balance security risks with business objectives and product timelines.
- Participate in security incident response, forensic investigations and security incident postmortems related to applications and systems.
- 5+ years of experience in application security, secure software development, or related roles.
- Bachelor’s degree in Computer Science or related field, or equivalent experience.
- Proficiency in secure coding practices and languages such as Type Script, Node, Python, Java, C++ or similar.
- Ability to contribute code changes to production applications as needed, including debugging, fixing security vulnerabilities, and collaborating with engineering teams on secure feature development.
- Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler).
- Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc.
- Experience implementing security in CI/CD pipelines such as Git Hub Action and agile development workflows.
- Familiarity with management and deployment of SAST, DAST, and SCA tooling
- Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications
- Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences.
- Please note: candidates…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).