Senior Software Engineer; Trust Foundations
Listed on 2025-12-16
-
Software Development
Software Engineer, Senior Developer
Senior Software Engineer (Trust Foundations)
New York, New York, United States;
San Francisco, California, United States;
Seattle, Washington, United States
Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance.
1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept insurance, making therapy too expensive for most people. Headway is building a new mental healthcare system that everyone can access by making it easy for therapists to accept insurance and scale their practice.
Headway was founded in 2019. Since then, we’ve grown into a diverse, national network of over 60,000 mental healthcare providers across all 50 states who run their practice on our software and have served over 1 million patients. We’re a Series D company with over $325m in funding from a16z (Andreessen Horowitz), Accel, GV (formerly Google Ventures), Spark Capital, Thrive Capital, Forerunner Ventures and Health Care Service Corporation.
We want your time here to be the most meaningful experience of your career.
Join us, and help change mental healthcare for the better.
Building for trust is non‑negotiable in our mission of making mental healthcare more accessible and affordable across the US: patients share sensitive information, payers demand demonstrably strong controls, and providers depend on reliable, secure infrastructure.
Trust Foundations is responsible for instilling confidence in our products by safeguarding our user’s data. We achieve this by developing out-of-the-box identity, access, and secure-data platforms for other engineering teams to utilize. Our mission is to make the most secure path the most efficient path, enabling clinicians, patients, and payers to trust Headway implicitly.
This team is growing and we are hiring for multiple roles at both mid/senior levels. As a Software Engineer/Senior Software Engineer on our Trust Foundations team, you’ll write production code every day while shaping the long‑term vision for trust will translate open standards - OAuth
2.0/OIDC, RBAC/ABAC, envelope encryption - into scalable building blocks; embed privacy‑by‑design and reliability principles into everything we build; and mentor engineers across the company in Trust first thinking.
- Design, build, and operate core trust primitives - authentication providers, authorization engines, stratified encrypted data stores, and tamper‑evident telemetry.
- Embed security & privacy by design - Codify guardrails in linting rules and CI, and partner with Legal/Compliance to translate regulatory language into concrete engineering controls.
- Scale our identity rails - Design and evolve multi‑tenant authentication & authorization services that handle millions of sessions daily with high availability expectations.
- Deliver scalable, secure platform foundations - Build shared services that embed security‑by‑default (least‑privilege access, encryption in transit and at rest, audit hooks) and expose intuitive APIs so product teams can move quickly without compromising trust.
- Turn ambiguous requirements into incremental delivery plans - Lead architecture reviews; break large problems into testable milestones; and make pragmatic build‑vs‑buy decisions in a regulated domain.
- Champion operational excellence - Instrument services, tune alerting, own on‑call runbooks, and drive post‑incident hardening.
- Elevate engineering culture - Mentor teammates, document patterns, and help recruit the next generation of Headway engineers.
- 5+years of professional software engineering with a strong command of at least one modern language (we use Python3 and Type Script).
- Proven systems‑architecture leadership - you have shaped requirements, led cross‑team roadmaps, and delivered complex backend or platform services at scale.
Deep expertise in one of two focus areas:
- Identity and Access - demonstrated experience working with third party IdPs, expertise with OAuth
2…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).