
Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digital resources for their emotional, professional, social, financial, and physical well-being needs—all within a single platform.
Modern Health is backed by top investors like Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures and has raised over $170 million, making us the fastest entirely female-founded company in the U.S. to reach Unicorn status.
Modern Health is a fully remote workforce. US-based team members living outside the Pacific time zone are expected to work at least six hours between 8:00 AM and 5:00 PM Pacific Time each workday.
The Role
Maintaining the security and privacy of our users is paramount to Modern Health’s mission. As a member of the Product Security (ProdSec) team reporting to the Head of Security, you will have organization-wide visibility to support and monitor our commitment to privacy, security, and compliance.
This role can be based anywhere in the United States and offers a unique opportunity to lay the foundation for product security at Modern Health.
What You'll Do
- Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations with engineering teams.
- Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques in health tech.
- Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC.
- Develop and advocate for cost-effective solutions to address complex application and product security challenges.
- Implement adoption of product security standards and best practices across the organization.
- Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
- Guide engineering teams in applying secure coding standards and provide actionable feedback.
- Deploy, optimize, and manage security tooling such as SAST, DAST, HashiCorp Vault, and other AppSec solutions.
- Participate in collaborative threat modeling initiatives for new features and evolving services.
- Conduct secure code reviews on services and applications built with modern frameworks.
- Assist in planning and executing targeted penetration tests on new features.
- Collaborate on IT security initiatives (device management, endpoint protection, access management, IT hygiene).
- Engage with Cloud Security efforts alongside DevOps and Infrastructure teams to assess and improve cloud architecture, IAM, and cloud-native controls.
What You'll Bring
- 2–4 years of experience in product/application security, OR 1–3 years in security-focused software engineering.
- Hands-on experience with vulnerability management, secure code review, threat modeling, and application security tooling.
- Hands-on experience with at least one scripting language (Python and/or Bash preferred).
- Deep familiarity with secure software development practices, security-focused architecture, and cloud infrastructure (specifically AWS IAM, network segmentation, detection, CI/CD, and Terraform controls).
- Experience integrating security into agile product delivery and conducting code reviews with software engineers.
- Experience applying security controls for AI systems and using AI tools to enhance security workflows.
- Excellent written and verbal communication skills with the ability to assess and prioritize projects independently.
- Work Authorization: Applicants must be able to maintain US work authorization for the duration of employment without employer sponsorship.
Tech Stack
- Cloud & Hosting: AWS (ECS)
- CI/CD: GitLab
- Languages & Frameworks: Python (Django, Flask, aiohttp)
- Data: PostgreSQL, Redis
- Monitoring: Datadog, Sentry
- IaC: Terraform, Packer
Bonus Points
- Experience at a high-growth startup
- Experience building SaaS software or working in Health Tech
- Hands-on software engineering background
Benefits & Compensation
- Fundamentals: Medical, Dental, Vision, Disability, Life Insurance, HSA/FSA options, Flexible Time Off, Company Pause Days
- Mental Health: Direct access to coaches and therapists through Modern Health's platform
- Family Support: Paid Parental Leave, Carrot Family-Forming benefit, UrbanSitter benefit
- Professional Growth: Annual Professional Development Stipend
- Financial Wellness: 401(k), Origin Financial Planning, Company Equity Program
- Perks: Annual Wellness Stipend, New Hire WFH Setup Stipend, Monthly Cell Phone Reimbursement
Annual Base Salary Ranges
- Zone 1 (SF Bay Area, NYC Metro): $119,300 — $140,400 USD
- Zone 2 (Other CA locations, Seattle, WA): $119,300 — $140,400 USD
- Zone 3 (Other NY/WA, DC, Austin, CT, IL, MA, NH, NJ, OR, RI, VT): $107,370 — $126,360 USD
- Zone 4 (All other US locations): $101,405 — $119,340 USD
Timezone overlap
UTC-8–-4
Benefits
Equity, Health, Dental, Vision, Mental health, PTO, Parental leave, Learning, 401k, Wellness, Home office, Internet, Commission, Bonus
Open to
US
Sign in to track applications and earn points.