Modern Health logo
Modern Health·

Product Security Engineer - Modern Health

Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digital resources for their emotional, professional, social, financial, and physical well-being needs—all within a single platform.

Modern Health is backed by top investors like Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures and has raised over $170 million, making us the fastest entirely female-founded company in the U.S. to reach Unicorn status.

Modern Health is a fully remote workforce. US-based team members living outside the Pacific time zone are expected to work at least six hours between 8:00 AM and 5:00 PM Pacific Time each workday.

The Role

Maintaining the security and privacy of our users is paramount to Modern Health’s mission. As a member of the Product Security (ProdSec) team reporting to the Head of Security, you will have organization-wide visibility to support and monitor our commitment to privacy, security, and compliance.

This role can be based anywhere in the United States and offers a unique opportunity to lay the foundation for product security at Modern Health.

What You'll Do

  • Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations with engineering teams.
  • Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques in health tech.
  • Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC.
  • Develop and advocate for cost-effective solutions to address complex application and product security challenges.
  • Implement adoption of product security standards and best practices across the organization.
  • Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations.
  • Guide engineering teams in applying secure coding standards and provide actionable feedback.
  • Deploy, optimize, and manage security tooling such as SAST, DAST, HashiCorp Vault, and other AppSec solutions.
  • Participate in collaborative threat modeling initiatives for new features and evolving services.
  • Conduct secure code reviews on services and applications built with modern frameworks.
  • Assist in planning and executing targeted penetration tests on new features.
  • Collaborate on IT security initiatives (device management, endpoint protection, access management, IT hygiene).
  • Engage with Cloud Security efforts alongside DevOps and Infrastructure teams to assess and improve cloud architecture, IAM, and cloud-native controls.

What You'll Bring

  • 2–4 years of experience in product/application security, OR 1–3 years in security-focused software engineering.
  • Hands-on experience with vulnerability management, secure code review, threat modeling, and application security tooling.
  • Hands-on experience with at least one scripting language (Python and/or Bash preferred).
  • Deep familiarity with secure software development practices, security-focused architecture, and cloud infrastructure (specifically AWS IAM, network segmentation, detection, CI/CD, and Terraform controls).
  • Experience integrating security into agile product delivery and conducting code reviews with software engineers.
  • Experience applying security controls for AI systems and using AI tools to enhance security workflows.
  • Excellent written and verbal communication skills with the ability to assess and prioritize projects independently.
  • Work Authorization: Applicants must be able to maintain US work authorization for the duration of employment without employer sponsorship.

Tech Stack

  • Cloud & Hosting: AWS (ECS)
  • CI/CD: GitLab
  • Languages & Frameworks: Python (Django, Flask, aiohttp)
  • Data: PostgreSQL, Redis
  • Monitoring: Datadog, Sentry
  • IaC: Terraform, Packer

Bonus Points

  • Experience at a high-growth startup
  • Experience building SaaS software or working in Health Tech
  • Hands-on software engineering background

Benefits & Compensation

  • Fundamentals: Medical, Dental, Vision, Disability, Life Insurance, HSA/FSA options, Flexible Time Off, Company Pause Days
  • Mental Health: Direct access to coaches and therapists through Modern Health's platform
  • Family Support: Paid Parental Leave, Carrot Family-Forming benefit, UrbanSitter benefit
  • Professional Growth: Annual Professional Development Stipend
  • Financial Wellness: 401(k), Origin Financial Planning, Company Equity Program
  • Perks: Annual Wellness Stipend, New Hire WFH Setup Stipend, Monthly Cell Phone Reimbursement

Annual Base Salary Ranges

  • Zone 1 (SF Bay Area, NYC Metro): $119,300 — $140,400 USD
  • Zone 2 (Other CA locations, Seattle, WA): $119,300 — $140,400 USD
  • Zone 3 (Other NY/WA, DC, Austin, CT, IL, MA, NH, NJ, OR, RI, VT): $107,370 — $126,360 USD
  • Zone 4 (All other US locations): $101,405 — $119,340 USD

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Modern Health

Similar remote roles