Modern Health logo
Modern Health

Modern Health is an award-winning mental healthcare startup offering therapy, coaching, and self-guided resources that support mental well-being for employees.

Product Security Engineer

Location

United States

Posted

101 days ago

Salary

$119.3K - $140.4K / year

Seniority

Mid Level

Job Description

Product Security Engineer

Modern Health

• Analyze security vulnerabilities in web and mobile applications, determine risk levels, and drive remediations in collaboration with engineering teams. • Research and report on potential product threats, emerging vulnerabilities, and mitigation techniques relevant to the evolving health tech landscape. • Partner with Engineering and Product stakeholders to integrate security at every stage of the SDLC, championing secure development practices and agile delivery. • Develop and advocate for cost-effective solutions to address complex application and product security challenges. • Implement the adoption of product security standards and best practices across the organization, influencing engineering and architecture decisions. • Routinely test, audit, and assess the security posture of application and cloud infrastructure configurations. • Guide engineering teams in applying secure coding standards, providing resources and actionable feedback to foster a culture of security. • Deploy, optimize, and manage security tooling such as SAST, DAST, Hashicorp Vault, and other industry-leading application security solutions. • Participate in collaborative threat modeling initiatives for new features and evolving services, ensuring proactive risk identification and reduction. • Conduct secure code reviews on services and applications built with modern frameworks and technologies. • Assist in planning and executing targeted penetration tests on new features, identifying and reporting vulnerabilities before production release. • Collaborate on IT security initiatives, partnering with infrastructure and operations teams to review security controls for device management, endpoint protection, access management, and overall IT hygiene. • Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations of applications and services.

Job Requirements

  • You bring 2-4 years of experience in product/application security or 1-3 years in security-focused software engineering.
  • You are deeply familiar with secure software development practices, security-focused architecture, and infrastructure that aligns with product objectives and business needs.
  • You support the adoption of application and product security best practices across engineering teams and contribute to business-wide security initiatives.
  • You have hands-on experience with vulnerability management, secure code review, threat modeling, and industry-standard tools for application and product security.
  • You have hands-on experience with at least one scripting language (Python and/or Bash preferred).
  • You thrive in fast-paced, collaborative environments, working closely with developers, product managers, and cross-functional stakeholders to secure web and mobile applications.
  • You are able to assess, prioritize, and execute on projects independently.
  • You are comfortable working in a fast-paced environment.
  • You have excellent written and verbal communication skills.

Benefits

  • Medical / Dental / Vision / Disability / Life Insurance
  • High Deductible Health Plan with Health Savings Account (HSA) option
  • Flexible Spending Account (FSA)
  • Access to coaches and therapists through Modern Health's platform
  • Flexible Time Off
  • Company-wide Collective Pause Days
  • Parental Leave Policy
  • Family Forming Benefit through Carrot
  • Family Assistance Benefit through UrbanSitter
  • Professional Development Stipend
  • 401k
  • Financial Planning Benefit through Origin
  • Annual Wellness Stipend to use on items that promote your overall well being
  • New Hire Stipend to help cover work-from-home setup costs
  • ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more
  • Monthly Cell Phone Reimbursement

Related Categories

Related Job Pages

More Security Engineer Jobs

DXC Technology logo

Security Researcher

DXC Technology

Delivering excellence for our customers and colleagues

Security Engineer101 days ago
OtherRemoteTeam 10,001+Since 2017H1B Sponsor

• Analyze code to identify vulnerabilities and assess security risks • Research and analyze malware samples to improve detection • Write detection rules and logic used by our security scanning tools • Analyze malware samples and emerging threats to improve detection capabilities • Work closely with engineers to turn research into product features • Clearly communicate findings to both technical and non-technical audiences • Contribute small tools or scripts to support security research when needed

United States
Job Closed
NetBox Labs logo

Director of Security – IT

NetBox Labs

We make it easier to build and manage complex networks.

Security Engineer101 days ago
OtherRemoteTeam 11-50Since 2023H1B No Sponsor

• Define and continuously evolve security architecture across our multi-tenant SaaS platform, on-prem product, and distributed agent systems. • Establish security design principles for multi-tenant isolation, IAM, secrets management, and cloud boundaries. • Embed security into engineering workflows through strong partnership with Engineering Directors and Principal Engineers. • Own governance, risk, and compliance strategy, including SOC 2 maturity and audit readiness. • Treat AI security as a first-class security domain and partner with our AI leaders to shape secure AI product strategy from inception. • Define guardrails for internal AI usage, including data access boundaries, vendor risk, model retention policies, and prompt leakage risks. • Anticipate how AI changes privilege models, data routing, and attack surface area. • Ensure AI adoption increases leverage without creating uncontrolled data exposure. • Define how security is embedded into CI/CD pipelines, infrastructure-as-code, identity systems, secrets management, and software supply chain workflows in partnership with platform and product engineering teams. • Guide the design of logging, detection, and response capabilities across our cloud and developer environments. • Oversee penetration testing programs and ensure findings translate into durable engineering improvements. • Build and grow the DevSecOps capability over time, including hiring dedicated engineers to own security tooling and automation. • Directly manage and coach the IT/InfoSec Manager and help mature the corporate IT, governance, risk, and compliance function. • Ensure endpoint security, vendor access, onboarding/offboarding, and internal systems meet strong security standards. • Align IT operations and compliance processes with engineering-driven security architecture.

United States
$215K - $230K / year
Job Closed
Johnson Controls logo

Talen Acquisition Recruiter

Johnson Controls

Transforming the buildings where people live, work, learn and play to become smarter, healthier and more sustainable.

Security Engineer101 days ago
OtherRemoteTeam 10,001+Since 1885H1B Sponsor

Build your best future with the Johnson Controls team As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience, focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard – your next great opportunity is just a few clicks away! What we offer: - Competitive salary - Paid vacation/holidays/sick time - Comprehensive benefits package including 401K, medical, dental, and vision care - On the job/cross training opportunities - Encouraging and collaborative team environment - Dedication to safety through our Zero Harm policy What you will do: The Talent Acquisition Recruiter helps support full‑cycle hiring by sourcing candidates, coordinating interviews, partnering with hiring managers, and ensuring a smooth and positive candidate experience. This role plays a key part in helping the business meet its staffing needs by managing day‑to‑day recruiting activities, communicating consistently with stakeholders, and following established processes and best practices. Success is measured by quality of candidates submitted, time to fill, responsiveness, and hiring manager and candidate satisfaction. How you will do it: Partner with Hiring Managers - Support hiring managers by gathering role requirements, understanding key skills, and aligning on interview steps and timelines. - Participate in intake discussions to clarify job responsibilities, candidate profiles, and overall hiring expectations. - Share basic labor market insights, sourcing updates, and candidate feedback to help managers make informed decisions. - Help coordinate interview feedback and ensure selection decisions follow fair, consistent practices. Deliver Full‑Cycle Recruiting Excellence - Manage job postings, review applications, screen candidates, and present qualified talent to hiring managers. - Source candidates using job boards, referrals, online platforms, and community or networking channels. - Maintain accurate candidate records in the ATS and ensure timely communication throughout the process. - Schedule interviews, prepare interviewers, and help ensure a positive and structured evaluation process. Use Data & Support Continuous Improvement - Track key metrics such as time to fill, candidate activity, and sourcing effectiveness. - Identify simple process improvements and share suggestions with the team. - Report basic hiring updates and progress to hiring managers and TA leadership. - Help adopt new tools or process changes that improve efficiency and experience. Contribute to Employer Brand & Candidate Experience - Ensure every candidate interaction is timely, respectful, and reflective of our company values. - Write clear, inclusive job postings that highlight responsibilities and requirements. - Represent the company at local events or with community partners as needed. - Help gather and share candidate feedback to support ongoing improvement. Ensure Compliance & Operational Excellence - Follow all recruiting and employment policies, including EEO and diversity hiring practices. - Maintain complete and accurate documentation within the ATS. - Protect candidate information and maintain confidentiality. Qualifications Required - 1–3+ years of recruiting, HR, or related experience (agency or corporate). - Experience managing full‑cycle recruiting or supporting portions of the hiring process. - Familiarity with ATS platforms and common sourcing tools (e.g., LinkedIn, Indeed). - Strong communication, organization, and relationship‑building skills. - Ability to interpret basic recruiting data to support decision‑making. - Knowledge of fair hiring practices and employment regulations. Preferred - Experience supporting high‑volume, hourly, or manufacturing/operations environments. - Experience working across multiple locations or functions. - Bachelor’s degree in HR, Business, or a related field (or equivalent practical experience). - Multilingual skills are a plus (French preferred but not required). Core Competencies - Understanding of basic business operations - Relationship building and stakeholder communication - Inclusive and consistent interviewing - Foundational sourcing strategies - Organization and prioritization - Clear communication and facilitation - Data‑informed problem solving - Commitment to strong candidate and hiring manager experience What Success Looks Like in the First Year - Roles filled within expected timelines. - Strong candidate quality and positive hiring manager feedback. - Positive candidate experience ratings and consistent communication. - Accurate and up‑to‑date ATS documentation. - Growing trust from hiring managers as a reliable recruiting partner. Tools & Technologies - Applicant Tracking System (ATS) - Candidate sourcing platforms (e.g., job boards, LinkedIn) - Talent pipeline tools - Collaboration, communication, and reporting tools This is a remote role in the U.S. HIRING SALARY RANGE: $76,000 - $105,000 (Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, location and alignment with market data.) The posted salary range reflects the target compensation for this role. However, we recognize that exceptional candidates may bring unique skills and experiences that exceed the typical profile. If you believe your background warrants consideration beyond the stated range, we encourage you to apply. To support an efficient and fair hiring process, we may use technology assisted tools, including artificial intelligence (AI), to help identify and evaluate candidates. All hiring decisions are ultimately made by human reviewers. This position includes a competitive benefits package. For details, please visit the About Us tab on the Johnson Controls Careers site at https://jobs.johnsoncontrols.com/about-us Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visit EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.

United States
$76K - $105K / year
Job Closed
OtherRemoteTeam 1,001-5,000Since 1973H1B No Sponsor

You desire impactful work. You’re RGA ready RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all. The Senior Security Risk Analyst will be responsible for identifying, assessing, reporting, and monitoring security risks across RGA’s enterprise security and business functions. This role involves collaborating with various departments to ensure compliance with security policies and standards, while additionally recommending security measures to protect RGA’s assets from potential threats. Principal Duties - Conduct comprehensive security risk assessments of enterprise systems and processes, as well as provide recommendations for risk mitigation. - Review, analyze, and provide recommendations for policy, standard, and baseline configuration exceptions. - Perform vendor risk assessments to include inherent & residual risk identification, analysis, and mitigation, and additionally track risk remediation to completion. - Provide recommendations for vendor contractual requirements stemming from vendor risk assessment outcomes. - Serve as a project security advisor including risk analysis gate checks in the secure SDLC process. - Conduct thorough threat modeling exercises to identify potential security vulnerabilities and risks. - Stay current on security trends, threats, and best practices to continuously improve the organization's security posture. - Perform other duties as assigned. Education - Required: Bachelor’s degree or equivalent experience - Preferred: Master’s degree and/or LOMA certification Required Experience, Abilities, and Skills - 5-8 years of IT security, privacy, audit, controls and regulatory compliance, or related experience. - Experience conducting risk assessments aligned with industry standard frameworks & standards. - Advanced understanding of IT domains: infrastructure, networking, storage, databases, operating systems, cloud, applications, etc. - Strong understanding of security technologies and domains, including: SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, etc. - Knowledge of risk and control frameworks/standards (e.g., NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, ISO/IEC 27005, etc.). - Oral and written communication skills, demonstrating the ability to convey complex technical and security concepts and terminology to non-technical stakeholders. - Ability to manage multiple projects/tasks simultaneously, including the ability to delegate key areas of responsibility. - Ability to successfully liaise with individuals across a wide variety of operational, functional, and technical disciplines. - Excellent analytical, problem-solving, and critical-thinking skills. Preferred Experience, Abilities, and Skills - 2+ years leadership role experience - Insurance/Reinsurance industry knowledge/experience - Information security, compliance, risk, or audit professional certifications, such as: CISSP, CISA, CISM, CGEIT, CRISC, CPA, OSCP, CCSP, CCSK - Project management skills/experience Preferred Technical Experience - Cloud risk assessment experience (e.g., AWS, Azure, Google Cloud, etc.) - Cyber Risk Quantification (CRQ) experience (e.g., FAIR) - Automation experience: Python, REST API, PowerShell, etc. - Previous experience as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, Cloud Engineer #LI-CW1 #LI-Remote What you can expect from RGA: - Gain valuable knowledge from and experience with diverse, caring colleagues around the world. - Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought. - Join the bright and creative minds of RGA, and experience vast, endless career potential. We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you. Compensation Range: $89,310.00 - $134,870.00 Annual Base pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits. RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.

United States
$89.3K - $134K / year
Job Closed