Staff Software Engineer - Product Security
Job Overview
Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us.
Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife - improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale.
Job Description
Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women.
Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.
com An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including: TIME 100 Most Influential Companies (2023, 2026) Fortune Change the World (2024) CNBC Disruptor 50 List (2022, 2023, 2024) Fortune Best Workplaces for Millennials (2024) Fortune Best Workplaces in Health Care (2024) Fast Company Most Innovative Companies (2020, 2023) Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024) What You’ll Do Security Platform Engineering Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA) Implement observability and anomaly detection across microservices, data stores, and SaaS platforms Establish Zero Trust principles and enforce least-privilege access company-wide Develop compliance observability dashboards and automated evidence collection Security Automation & Tooling Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform) Automate onboarding/offboarding, access reviews, and approvals Integrate software-supply-chain security (SBOM, dependency scanning) Develop or adopt AI-assisted security tooling to proactively identify risks Automate policy enforcement, SAST/DAST scans, and compliance verification Application & Data Security Lead threat modeling and security architecture reviews for new products and services Partner with product and data teams to embed secure-by-default design patterns Ensure encryption, access tracking, and secure data handling across PHI workflows Contribute to incident response, post-mortems, and continual improvement of security posture Leadership & Collaboration Act as Maven’s technical authority for security engineering Mentor peers and promote secure coding and architecture practices Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy Champion an engineering culture of transparency, accountability, and continuous improvement What You’ll Bring Required 8+ years of software engineering experience, including 3+ in security infrastructure or application security Proven ability to design and implement large-scale, distributed, cloud-native systems Strong coding proficiency in Python, TypeScript, Go and/or Rust Deep understanding of cloud security (GCP preferred; AWS/Azure welcome) Experience with Kubernetes, containers, and infrastructure-as-code (Terraform) Familiarity with security testing frameworks and secure SDLC principles Excellent communication and documentation skills Preferred Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) Background in data security telemetry and threat detection Familiarity with AI/ML security and AI-assisted analysis tools Exposure to supply-chain security and CI/CD pipeline hardening Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus What Makes You a Great Fit You take a pragmatic, automation-first approach to solving security problems You balance rigor with velocity, enabling teams to move quickly without compromising trust You communicate clearly with both technical and non-technical stakeholders You’re curious, adaptable, and eager to lead initiatives from concept to production You care deeply about our mission-building safer, smarter healthcare for women and families The base salary range for this role is $221,000 - $260,000 per year.
You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset. Maven embraces a flexible hybrid work model.
Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA.
For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week (Tuesday, Wednesday, Thursday).
Key Responsibilities
- Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife - improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale.
- Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital.
- Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work.
- Learn more at mavenclinic.com An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including: TIME 100 Most Influential Companies (2023, 2026) Fortune Change the World (2024) CNBC Disruptor 50 List (2022, 2023, 2024) Fortune Best Workplaces for Millennials (2024) Fortune Best Workplaces in Health Care (2024) Fast Company Most Innovative Companies (2020, 2023) Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024) What You’ll Do Security Platform Engineering Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA) Implement observability and anomaly detection across microservices, data stores, and SaaS platforms Establish Zero Trust principles and enforce least-privilege access company-wide Develop compliance observability dashboards and automated evidence collection Security Automation & Tooling Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform) Automate onboarding/offboarding, access reviews, and approvals Integrate software-supply-chain security (SBOM, dependency scanning) Develop or adopt AI-assisted security tooling to proactively identify risks Automate policy enforcement, SAST/DAST scans, and compliance verification Application & Data Security Lead threat modeling and security architecture reviews for new products and services Partner with product and data teams to embed secure-by-default design patterns Ensure encryption, access tracking, and secure data handling across PHI workflows Contribute to incident response, post-mortems, and continual improvement of security posture Leadership & Collaboration Act as Maven’s technical authority for security engineering Mentor peers and promote secure coding and architecture practices Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy Champion an engineering culture of transparency, accountability, and continuous improvement What You’ll Bring Required 8+ years of software engineering experience, including 3+ in security infrastructure or application security Proven ability to design and implement large-scale, distributed, cloud-native systems Strong coding proficiency in Python, TypeScript, Go and/or Rust Deep understanding of cloud security (GCP preferred; AWS/Azure welcome) Experience with Kubernetes, containers, and infrastructure-as-code (Terraform) Familiarity with security testing frameworks and secure SDLC principles Excellent communication and documentation skills Preferred Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) Background in data security telemetry and threat detection Familiarity with AI/ML security and AI-assisted analysis tools Exposure to supply-chain security and CI/CD pipeline hardening Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus What Makes You a Great Fit You take a pragmatic, automation-first approach to solving security problems You balance rigor with velocity, enabling teams to move quickly without compromising trust You communicate clearly with both technical and non-technical stakeholders You’re curious, adaptable, and eager to lead initiatives from concept to production You care deeply about our mission-building safer, smarter healthcare for women and families The base salary range for this role is $221,000 - $260,000 per year.
- You will also be entitled to receive equity and benefits.
- If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.
- Benefits That Work For You Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally.
- Maven Clinic will never ask for sensitive information to be delivered over email or phone.
Required Skills and Qualifications
- Learn more at mavenclinic.com An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including: TIME 100 Most Influential Companies (2023, 2026) Fortune Change the World (2024) CNBC Disruptor 50 List (2022, 2023, 2024) Fortune Best Workplaces for Millennials (2024) Fortune Best Workplaces in Health Care (2024) Fast Company Most Innovative Companies (2020, 2023) Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024) What You’ll Do Security Platform Engineering Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA) Implement observability and anomaly detection across microservices, data stores, and SaaS platforms Establish Zero Trust principles and enforce least-privilege access company-wide Develop compliance observability dashboards and automated evidence collection Security Automation & Tooling Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform) Automate onboarding/offboarding, access reviews, and approvals Integrate software-supply-chain security (SBOM, dependency scanning) Develop or adopt AI-assisted security tooling to proactively identify risks Automate policy enforcement, SAST/DAST scans, and compliance verification Application & Data Security Lead threat modeling and security architecture reviews for new products and services Partner with product and data teams to embed secure-by-default design patterns Ensure encryption, access tracking, and secure data handling across PHI workflows Contribute to incident response, post-mortems, and continual improvement of security posture Leadership & Collaboration Act as Maven’s technical authority for security engineering Mentor peers and promote secure coding and architecture practices Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy Champion an engineering culture of transparency, accountability, and continuous improvement What You’ll Bring Required 8+ years of software engineering experience, including 3+ in security infrastructure or application security Proven ability to design and implement large-scale, distributed, cloud-native systems Strong coding proficiency in Python, TypeScript, Go and/or Rust Deep understanding of cloud security (GCP preferred; AWS/Azure welcome) Experience with Kubernetes, containers, and infrastructure-as-code (Terraform) Familiarity with security testing frameworks and secure SDLC principles Excellent communication and documentation skills Preferred Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) Background in data security telemetry and threat detection Familiarity with AI/ML security and AI-assisted analysis tools Exposure to supply-chain security and CI/CD pipeline hardening Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus What Makes You a Great Fit You take a pragmatic, automation-first approach to solving security problems You balance rigor with velocity, enabling teams to move quickly without compromising trust You communicate clearly with both technical and non-technical stakeholders You’re curious, adaptable, and eager to lead initiatives from concept to production You care deeply about our mission-building safer, smarter healthcare for women and families The base salary range for this role is $221,000 - $260,000 per year.
- Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.
- At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals.
- If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.
Benefits and Perks
- Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work.
- Learn more at mavenclinic.com An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including: TIME 100 Most Influential Companies (2023, 2026) Fortune Change the World (2024) CNBC Disruptor 50 List (2022, 2023, 2024) Fortune Best Workplaces for Millennials (2024) Fortune Best Workplaces in Health Care (2024) Fast Company Most Innovative Companies (2020, 2023) Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024) What You’ll Do Security Platform Engineering Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA) Implement observability and anomaly detection across microservices, data stores, and SaaS platforms Establish Zero Trust principles and enforce least-privilege access company-wide Develop compliance observability dashboards and automated evidence collection Security Automation & Tooling Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform) Automate onboarding/offboarding, access reviews, and approvals Integrate software-supply-chain security (SBOM, dependency scanning) Develop or adopt AI-assisted security tooling to proactively identify risks Automate policy enforcement, SAST/DAST scans, and compliance verification Application & Data Security Lead threat modeling and security architecture reviews for new products and services Partner with product and data teams to embed secure-by-default design patterns Ensure encryption, access tracking, and secure data handling across PHI workflows Contribute to incident response, post-mortems, and continual improvement of security posture Leadership & Collaboration Act as Maven’s technical authority for security engineering Mentor peers and promote secure coding and architecture practices Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy Champion an engineering culture of transparency, accountability, and continuous improvement What You’ll Bring Required 8+ years of software engineering experience, including 3+ in security infrastructure or application security Proven ability to design and implement large-scale, distributed, cloud-native systems Strong coding proficiency in Python, TypeScript, Go and/or Rust Deep understanding of cloud security (GCP preferred; AWS/Azure welcome) Experience with Kubernetes, containers, and infrastructure-as-code (Terraform) Familiarity with security testing frameworks and secure SDLC principles Excellent communication and documentation skills Preferred Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST) Background in data security telemetry and threat detection Familiarity with AI/ML security and AI-assisted analysis tools Exposure to supply-chain security and CI/CD pipeline hardening Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus What Makes You a Great Fit You take a pragmatic, automation-first approach to solving security problems You balance rigor with velocity, enabling teams to move quickly without compromising trust You communicate clearly with both technical and non-technical stakeholders You’re curious, adaptable, and eager to lead initiatives from concept to production You care deeply about our mission-building safer, smarter healthcare for women and families The base salary range for this role is $221,000 - $260,000 per year.
- You will also be entitled to receive equity and benefits.
- This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.
- Benefits That Work For You Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally.
- We remain focused on providing a competitive benefits package for our employees.
USA Jobs Today role summary
Role Summary
Staff Software Engineer - Product Security at Maven Clinic is a remote United States position and is listed as Full Time.
Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women.
Review the employer's original description and official application page before applying; USA Jobs Today organizes source-supported details for readability without changing stated requirements.
Application Checklist
- Review the stated qualifications, including: Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.
- Confirm that the official application page still lists the role as open.
- Verify the work location and any United States eligibility or work-authorization requirements.
- Tailor your resume to the responsibilities and qualifications stated by Maven Clinic.
- Apply only through the official link shown on this page and never pay USA Jobs Today to submit an application.
Original job information is provided by the hiring organization or listed source. USA Jobs Today organizes source-supported details for readability without inventing salary, benefits, qualifications, sponsorship, or remote eligibility.
Work Location and Schedule
This role is listed as Remote USA with location information shown as Remote USA. The employment type is Full Time.
About the Company
Maven Clinic is the organization connected with this listing. USA Jobs Today displays this opportunity for job discovery only, so applicants should verify company details, application instructions, and eligibility on the official employer website.
Application Notes
This job was reviewed for USA-only relevance. Always apply through the official employer website, review the full job details carefully, and avoid sharing sensitive personal or payment information outside a trusted application process.
Report this job if it looks expired, suspicious, inaccurate, or unsafe.More USA job search options
Related resources for this job seeker
Use these links to browse more USA jobs, compare related categories, prepare your resume, and read USA job search guidance before applying.
