[![Image](https://upload.wikimedia.org/wikipedia/commons/8/82/Telegram_logo.svg) Fresh remote jobs, sorted by category — join Jobicy on Telegram  › Fresh remote jobs on Telegram  ›](https://t.me/JobicyJobs) [All remote jobs](https://jobicy.com/jobs.md)Open role[![Maven Clinic logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/c4b2d5ecf34b-221.webp)](https://jobicy.com/company/maven-clinic.md)Remote opportunity at[Maven Clinic](https://jobicy.com/company/maven-clinic.md)

# Staff Software Engineer – Product Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/maven-clinic.md)Share31 Aug 2026Published33Listing views1Application actions30 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryMaven Clinic is seeking a Staff Software Engineer to serve as a senior technical authority for product security in a cloud-native healthcare platform. The role combines security-platform engineering, identity and access management, security automation, application security, threat modeling, and compliance observability for HIPAA, SOC 2, and ISO 27001. The engineer will build developer-integrated controls across GCP, Kubernetes, Terraform, GitLab CI/CD, and software supply-chain tooling while protecting PHI workflows. This is a highly collaborative leadership role partnering with engineering, data, compliance, clinical, and legal teams. Success requires pragmatic secure-by-default architecture, strong automation skills, and the ability to raise security standards without slowing product delivery.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a staff-level security engineering position requiring broad technical depth across cloud infrastructure, application security, IAM, compliance automation, and distributed systems. The role also carries organization-wide technical leadership responsibilities in a regulated healthcare environment.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$240,500US market range$210k–$285k0$314k

AI insightThe disclosed base-salary midpoint is $240,500 USD yearly, calculated from the stated $221,000 to $260,000 annual range. This is competitive for a US-based Staff Product Security Engineer, particularly in New York, San Francisco, Seattle, and other major technology hubs. The estimated broader US market base-salary range for a comparable staff-level cloud and product-security role is approximately $210,000 to $285,000 annually; equity and benefits may add meaningful total compensation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Product Security](https://jobicy.com/jobs?search_keywords=Product%20Security.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[GCP](https://jobicy.com/jobs?search_keywords=GCP.md)[Identity and Access Management](https://jobicy.com/jobs?search_keywords=Identity%20and%20Access%20Management.md)[Zero Trust](https://jobicy.com/jobs?search_keywords=Zero%20Trust.md)[Kubernetes](https://jobicy.com/jobs?search_keywords=Kubernetes.md)[Terraform](https://jobicy.com/jobs?search_keywords=Terraform.md)[Secure SDLC](https://jobicy.com/jobs?search_keywords=Secure%20SDLC.md)[HIPAA Compliance](https://jobicy.com/jobs?search_keywords=HIPAA%20Compliance.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)

Sample interview questionsHow would you implement a scalable least-privilege access model across GCP, Okta, and SaaS tools?I would establish a centralized identity source with role- and attribute-based access controls, automate provisioning and deprovisioning through approved workflows, and use short-lived credentials where possible. I would define access roles around job functions, enforce periodic access reviews, log all privileged activity, and continuously measure exceptions to improve the model.

Describe how you would embed security controls into a GitLab CI/CD and Terraform workflow without creating excessive developer friction.

I would provide reusable pipeline templates and Terraform modules that make secure defaults the easiest path. Controls would include secret scanning, dependency and SBOM generation, SAST, IaC scanning, policy checks, and risk-based gates, with clear remediation guidance and an exception process for urgent cases. I would monitor false positives and deployment impact so the controls remain trusted and practical.

How would you approach threat modeling for a new workflow handling protected health information?

I would begin by mapping data flows, trust boundaries, identities, external dependencies, and storage locations. With the product and engineering teams, I would identify threats using a structured framework, prioritize risks by likelihood and impact, and convert mitigations into architecture decisions and testable requirements. I would also ensure encryption, auditability, retention, and access controls align with HIPAA obligations.

What security telemetry would you prioritize for detecting anomalous access to sensitive healthcare data?

I would prioritize identity events, privileged access changes, authentication anomalies, API access patterns, database query activity, data-export events, and CI/CD or infrastructure changes. Correlating these sources with asset criticality and user context enables detection of unusual access volume, impossible travel, permission escalation, and atypical PHI retrieval. Alerts should be tuned to support a documented incident-response process.

How do you balance compliance requirements with engineering velocity?

I treat compliance as an engineering design constraint rather than a separate manual process. By automating evidence collection, policy enforcement, access reviews, and security testing in the developer workflow, teams can meet controls continuously instead of preparing for audits through disruptive efforts. I also communicate risk in business terms and focus first on controls that materially reduce exposure.

Maven Clinic is the world’s largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women’s and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife — improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company’s Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com

An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including:

* TIME 100 Most Influential Companies (2023, 2026)
* Fortune Change the World (2024)
* CNBC Disruptor 50 List (2022, 2023, 2024)
* Fortune Best Workplaces for Millennials (2024)
* Fortune Best Workplaces in Health Care (2024)
* Fast Company Most Innovative Companies (2020, 2023)
* Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024)

### What You’ll Do

### Security Platform Engineering

* Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance
* Build and maintain systems for identity, authentication, and access management (Okta / GCP IAM / Auth0/ OPA)
* Implement observability and anomaly detection across microservices, data stores, and SaaS platforms
* Establish Zero Trust principles and enforce least-privilege access company-wide
* Develop compliance observability dashboards and automated evidence collection

### Security Automation & Tooling

* Create self-service security tools that integrate with developer workflows (GitLab CI/CD, Terraform)
* Automate onboarding/offboarding, access reviews, and approvals
* Integrate software-supply-chain security (SBOM, dependency scanning)
* Develop or adopt AI-assisted security tooling to proactively identify risks
* Automate policy enforcement, SAST/DAST scans, and compliance verification

### Application & Data Security

* Lead threat modeling and security architecture reviews for new products and services
* Partner with product and data teams to embed secure-by-default design patterns
* Ensure encryption, access tracking, and secure data handling across PHI workflows
* Contribute to incident response, post-mortems, and continual improvement of security posture

### Leadership & Collaboration

* Act as Maven’s technical authority for security engineering
* Mentor peers and promote secure coding and architecture practices
* Partner cross-functionally (Engineering, Compliance, Clinical, Legal) to align on security strategy
* Champion an engineering culture of transparency, accountability, and continuous improvement

### What You’ll Bring

### Required

* 8+ years of software engineering experience, including 3+ in security infrastructure or application security
* Proven ability to design and implement large-scale, distributed, cloud-native systems
* Strong coding proficiency in Python, TypeScript, Go and/or Rust
* Deep understanding of cloud security (GCP preferred; AWS/Azure welcome)
* Experience with Kubernetes, containers, and infrastructure-as-code (Terraform)
* Familiarity with security testing frameworks and secure SDLC principles
* Excellent communication and documentation skills

### Preferred

* Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention
* Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST)
* Background in data security telemetry and threat detection
* Familiarity with AI/ML security and AI-assisted analysis tools
* Exposure to supply-chain security and CI/CD pipeline hardening
* Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus

### What Makes You a Great Fit

* You take a pragmatic, automation-first approach to solving security problems
* You balance rigor with velocity, enabling teams to move quickly without compromising trust
* You communicate clearly with both technical and non-technical stakeholders
* You’re curious, adaptable, and eager to lead initiatives from concept to production
* You care deeply about our mission—building safer, smarter healthcare for women and families

The base salary range for this role is $221,000 – $260,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.

Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.

At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.

Benefits That Work For You

Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally. We remain focused on providing a competitive benefits package for our employees. On top of standards such as employer-covered health, dental, and insurance plan options, we offer an inclusive approach to benefits:

* Maven for Mavens: access to the full platform and specialists, including care for mental health, reproductive health, family planning and pediatrics.
* Whole-self care through wellness partnerships
* Hybrid work, in office meals, and work together days
* 16 weeks 100% paid parental leave and new parent stipend (for Mavens who’ve been with us for 1 year+)
* Annual professional development stipend and access to a personal career coach through Maven for Mavens
* 401K matching for US-based employees, with immediate vesting

These benefits are applicable to Maven Clinic Co., US-based, full-time employees only. 1099/Contract Providers are ineligible for these benefits.

Maven is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Maven is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Maven Clinic interview requests and job offers only originate from an @mavenclinic.com email address (e.g jsmith@mavenclinic.com). Maven Clinic will never ask for sensitive information to be delivered over email or phone. If you receive a scam issue or a security issue involving Maven Clinic please notify us at: [security@mavenclinic.com](mailto:security@mavenclinic.com). For general and additional inquiries, please contact us at [careers@mavenclinic.com](mailto:careers@mavenclinic.com).

Show more

[Apply now >](https://jobicy.com/jobs/152250-staff-software-engineer-product-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Zscaler logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/b3234031-221.png)
Zscaler  Aug 31

### [Director, Specialist Sales Engineering – Data Security](https://jobicy.com/jobs/152257-director-specialist-sales-engineering-data-security.md)

About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the…

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Staff Product Security Engineer](https://jobicy.com/jobs/152256-staff-product-security-engineer.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Senior Security Operations Engineer](https://jobicy.com/jobs/152254-senior-security-operations-engineer-2.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Senior Application Security Engineer](https://jobicy.com/jobs/152253-senior-application-security-engineer-2.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Senior Security Engineer, AI Security](https://jobicy.com/jobs/152252-senior-security-engineer-ai-security.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Security Operations Lead (SecOps)](https://jobicy.com/jobs/152249-security-operations-lead-secops.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Engineering Manager, Security Detection & Response](https://jobicy.com/jobs/152248-engineering-manager-security-detection-response.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![YipitData logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/e1bee9df-221.jpg)
YipitData  Aug 31

### [Product Security Engineer](https://jobicy.com/jobs/152175-product-security-engineer.md)

About Us: YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B….

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs  Aug 31

### [Senior Cyber Threat Intelligence Analyst](https://jobicy.com/jobs/152158-senior-cyber-threat-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs  Aug 31

### [Staff Cyber Threat Intelligence Analyst](https://jobicy.com/jobs/152155-staff-cyber-threat-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…