Product Security Engineer
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Overview
Modern Health is a mental health benefits platform for employers. We offer employees access to one-on-one, group, and self-serve digital resources for emotional, professional, social, financial, and physical well-being—all within a single platform. We guide people to the right care at the right time and work to empower companies to support their employees on their mental health journeys.
Modern Health is backed by investors such as Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures. The company has raised more than $170 million in under two years and is a fast-growing, female-founded organization. We value an inclusive culture and are committed to diversity and mental well-being in the workplace.
The RoleMaintaining the security and privacy of our users is paramount. As a member of the security team, you will have organization-wide visibility to support and monitor our commitment to privacy, security, and compliance. This role offers an opportunity to apply engineering and security skills to make a direct impact on people’s lives. You will mitigate risk by increasing automation in security domains and work with engineers to securely release and maintain software, infrastructure, and an information security management system, while improving our security and compliance posture.
This role is part of the Product Security (Prod Sec) team, reports to the Head of Security, and can be based anywhere in the United States.
This position is not eligible to be performed in Hawaii. If you are a passionate developer or software engineer with AWS experience and an interest in security, you are encouraged to apply.
What You’ll Do- Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations with engineering teams.
- Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to health tech.
- Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices.
- Develop and advocate for cost-effective solutions to address complex security challenges.
- Implement adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions.
- Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
- Guide engineering teams in applying secure coding standards and provide actionable feedback to foster a security culture.
- Deploy, optimize, and manage security tooling (SAST, DAST, Hashi Corp Vault, and other industry tools).
- Participate in threat modeling initiatives for new features and services, ensuring proactive risk identification and reduction.
- Conduct secure code reviews on services and applications built with modern frameworks and technologies.
- Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release.
- Collaborate on IT security initiatives with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and IT hygiene.
- Engage with Cloud Security efforts by partnering with Dev Ops and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls for secure deployment and operation of applications and services.
- You are a passionate and confident team member who takes pride and ownership in your work.
- You are deeply familiar with secure software development practices, security-focused architecture, and infrastructure aligned with product objectives and business needs.
- You support the adoption of application and product security best practices across engineering teams and contribute to security initiatives.
- You have hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard security tools.
- You have hands-on experience with at least one scripting language (Python and/or Bash preferred).
- You thrive in fast-paced, collaborative environments and work closely…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).