Founded in 2021 and headquartered in Menlo Park, California, Sprinter Health is a rapidly expanding healthcare company that provides in-home services such as lab draws, vitals chec
Staff, Security Engineer (App & Product Sec)
Location
California
Posted
20 days ago
Salary
$235K - $285K / year
Seniority
Senior
Job Description
Staff, Security Engineer (App & Product Sec)
Sprinter Health
About Sprinter HealthAt Sprinter Health, our mission is reimagining how people access care by bringing it directly to their homes. Nearly 30% of patients in the U.S. skip preventive or chronic care simply because they can’t get to a doctor’s office. For many, the ER becomes their first touchpoint with the healthcare system, driving over $300B in avoidable costs every year. By using the same technologies that power leading marketplace and last-mile platforms, we deliver care where people are, especially those who need it most. So far, we’ve supported more than 2 million patients across 22 states, completed 130,000+ in-home visits, and maintained a 92 NPS. Our team of clinicians, technologists, and operators has raised over $125M from investors like a16z, General Catalyst, GV, and Accel and enjoys multi-year runway. About the RoleWe’re looking for a Staff Security Engineer to be Sprinter’s first dedicated security hire and help build the foundation for how security scales across the company. This is a high-ownership role for someone who can operate strategically and hands-on. You’ll define our security roadmap, strengthen our cloud and application security posture, support HIPAA, SOC 2, and HITRUST readiness, and partner closely with engineering, product, IT, legal, operations, and leadership to make security a core part of how we build and operate. As our first security function hire, you will not just execute against an existing program. You’ll help decide what the program should be. That includes designing controls, implementing tools, driving vulnerability management, supporting partner security reviews, improving IAM, embedding security into the SDLC, and helping Sprinter make smart risk decisions as we scale. This role is ideal for someone who wants to build a security function from the ground up in a high-growth, mission-driven healthcare company. Office LocationWe are a hybrid company based in the Bay Area with offices in both San Francisco and Menlo Park. For this role, we are also open to considering remote candidates. We will give priority to candidates who are based in or open to working from the San Francisco Bay Area. What you will do - Build and lead Sprinter’s security program as the company’s first dedicated security hire - Define and execute a practical security roadmap across cloud infrastructure, application security, compliance, identity, vendor risk, and incident readiness - Design, implement, and maintain security controls that support HIPAA, SOC 2, and HITRUST requirements - Partner with legal, product, IT, engineering, and operations teams to ensure ongoing audit readiness and compliance maturity - Improve security across AWS and GCP environments, including IAM, networking, encryption, secrets management, and cloud-native application security - Evaluate and implement security tooling for vulnerability management, cloud security posture management, security monitoring, DAST, and related needs - Lead vulnerability management efforts across applications, infrastructure, cloud environments, and third-party systems - Coordinate penetration testing efforts, work with external security partners, and drive remediation with engineering teams - Embed security into the software development lifecycle through secure design reviews, CI/CD checks, developer guidance, and pragmatic security standards - Own or support partner, customer, and vendor security reviews, including questionnaires, risk assessments, and remediation planning - Strengthen identity and access management across internal systems, applications, and cloud environments - Develop clear security policies, procedures, documentation, and reporting for internal teams and senior leadership - Advise on AI security best practices as Sprinter adopts and builds AI-enabled systems, including data handling, model risk, application security, and privacy controls - Build strong working relationships across teams so security is viewed as a partner to the business, not a blocker What you have done - Spent 8+ years in security engineering, cloud security, application security, infrastructure security, DevSecOps, or related roles - Built or meaningfully scaled a security function, security program, or major security domain in a high-growth environment - Operated as a senior technical owner for security across engineering, infrastructure, product, IT, and compliance stakeholders - Worked hands-on with cloud security in AWS, GCP, or similar cloud environments - Implemented security controls that support compliance frameworks such as HIPAA, SOC 2, HITRUST, ISO 27001, or similar - Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments - Partnered with engineering teams to embed security into architecture, development, CI/CD, and production operations - Worked with identity and access management systems such as Okta, Auth0, SSO, MFA, RBAC, or related tooling - Evaluated, selected, or implemented security tools such as SIEM, DAST, vulnerability scanners, CSPM, endpoint security, or monitoring platforms - Used scripting or infrastructure-as-code tools such as Python, Bash, Terraform, or similar to automate security workflows - Communicated security risks, tradeoffs, and priorities clearly to technical and non-technical stakeholders - Made practical risk decisions in environments where speed, ambiguity, compliance, and security all matter What gives you an edge - You’ve been the first security hire or an early security leader at a startup - You’ve built security programs in healthcare, fintech, insurance, logistics, marketplace, or other regulated or operationally complex environments - You have deep experience with HIPAA, SOC 2, HITRUST, or healthcare security and privacy requirements - You’ve supported customer, partner, or enterprise security reviews in a B2B or healthcare environment - You’ve helped prepare for or lead security audits and compliance assessments - You have experience with AI security, including secure AI application development, model risk, data privacy, adversarial risk, or AI governance - You’ve worked closely with product and engineering teams to make security usable, scalable, and developer-friendly - You have experience with container security, Kubernetes, network security, endpoint security, or encryption standards - You hold certifications such as CISSP, CISM, AWS Certified Security Specialty, CEH, or similar The Interview ProcessWe aim to complete the interview process within 2–3 weeks. It will usually consist of: - Recruiter Screen: Background fit, motivation, and compensation alignment - Hiring Manager Interview: Security leadership, technical depth, and first-of-function experience - Technical Interview: Cloud security, application security, compliance, vulnerability management, and security architecture - Cross-Functional Interview: Collaboration style and ability to partner with engineering, product, IT, legal, and operations - References: Validation of performance, judgment, and working style What we offer - Meaningful pre-IPO equity - Medical, dental, and vision plans 100% paid for you and your dependents - Flexible PTO + 10 paid holidays per year - 401(k) with match - 16-week parental leave policy for birthing parent, 8 weeks for all other parents - HSA + FSA contributions - Life insurance, plus short and long-term disability coverage - Free daily lunch in-office - Annual learning stipend - Relocation assistance Our Technology Stack - AWS - GCP - Terraform and infrastructure-as-code tooling - TypeScript - Python - Bash - CI/CD systems - Okta - Auth0 - SIEM, DAST, vulnerability management, and cloud security tooling - Identity, access, and secrets management systems - Cloud networking and infrastructure tooling - Container and deployment systems - Serverless AWS, including AppSync, DynamoDB, Lambda, Amplify, CloudFormation, and Node - GraphQL - React Native and React Native for Web Equal Opportunity StatementSprinter Health is an equal opportunity employer. We value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected classes. Beware of recruitment fraud and scams that involve fictitious job descriptions followed by false job offers. If you are applying for a job, you can confirm the legitimacy of a job posting by viewing current open roles on our official Sprinter Health Careers website. All legitimate job postings will require an application to be made directly on our official Sprinter Health Careers website. Job-related communications will only be sent from email addresses ending in @sprinterhealth.com. Please ensure that you’re only replying to emails that end with @sprinterhealth.com.
Benefits
- 401(K) matching, Childcare benefits, Company equity, Company-sponsored outings, Continuing education stipend, Customized development tracks, Dental insurance, Disability insurance, Documented equal pay policy, Volunteer in local community, Family medical leave, Flexible Spending Account (FSA), Flexible work schedule, Free daily meals, Generous parental leave, Company-sponsored happy hours, Health insurance, Highly diverse management team, Open door policy, Life insurance, Mean gender pay gap below 10%, Onsite gym, Open office floor plan, Paid holidays, Pair programming, Paid sick days, Onsite office parking, Performance bonus, Pet friendly, Promote from within, Lunch and learns, Relocation assistance, Free snacks and drinks, OKR operational model, Unlimited vacation policy, Vision insurance, Some meals provided, Mental health benefits, Diversity employee resource groups, Hiring practices that promote diversity, Fertility benefits, Employee-led culture committees, Hybrid work model, In-person all-hands meetings, Pay transparency, Mother's room, Flexible time off, Bereavement leave benefits, Company-wide vacation
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Security Engineer - GRC
GoDaddyGoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members across North America,
Role Description Join our team as an Information Security Leader at GoDaddy. We help solve large-scale and cross-company issues while ensuring that partnership with the development and operational communities remains front of mind. GoDaddy is looking for a Principal Risk Engineer with: - Security risk management experience - Technical depth - Strong leadership abilities - Experience building and performing information security audits and gap assessments You must be comfortable: - Communicating with internal teams and external auditors - Designing and leading security campaigns - Prioritizing the resolution of audit findings while applying a risk-based approach As a team, we will help: - Identify any gaps in security control implementation - Design solutions to manage security risks at scale - Provide the information needed to make risk-based decisions and planning What you'll get to do: - Build and manage a Security Controls framework that encompasses the regulatory and industry compliance frameworks we follow - Perform targeted gap assessments to identify any deviations from the control framework - Propose and manage enterprise-wide security campaigns for managing deviations to reduce risk - Partner with other InfoSec teams and Engineering teams to define and prioritize security initiatives and investments guided by risk assessment principles - Align risk management initiatives with applicable compliance regulations Qualifications - 10+ years of professional experience in Information Security or related fields such as Information Technology, IT Audit, etc. - 6+ years of dynamic experience managing programs related to information security and information security audits - Experience building unified security controls frameworks - Experience managing audits applying compliance frameworks such as PCI DSS, NIST CSF, NIST 800-53, ISO, SOC-2 etc. - Executive reporting on the status of security programs and campaigns - Experience in Security Engineering concepts such as Threat modeling and architecture reviews - Experience with auditing cloud infrastructure such as AWS Requirements - A bachelor’s degree in computer science or related field - Certifications like PCI ISA, CISA, CRISC, ISO Lead Assessor, CISSP, etc. - Experience working at a Big 4 Audit firm(s) Benefits - Paid time off - Retirement savings (e.g., 401k, pension schemes) - Bonus/incentive eligibility - Equity grants - Participation in our employee stock purchase plan - Competitive health benefits - Family-friendly benefits including parental leave Company Description GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences, and perspectives. GoDaddy is proud to be an equal opportunity employer. GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
• Engage in a 45-minute AI-moderated video interview. • Discuss your professional experiences with security and monitoring systems. • Provide constructive feedback on current technology solutions. • Share insights on future needs and challenges in operational security.
Senior Application Security Engineer
Felix Technologies, Inc.At Félix, we're building the financial ecosystem for Latin immigrants in the U.S., starting with a revolution in remittances. Our core product is an AI-powered chatbot built on WhatsApp, allowing our users to send money home as easily as sending a text message. We leverage cutting-edge technology like AI, blockchain, and stablecoins to make cross-border payments faster, more affordable, and more accessible than ever before. We are a hyper-growth Series B company, backed by over $100 million in funding from top-tier global investors, including QED, Castle Island, Switch Ventures, HTwenty, Monashees, and General Catalyst Customer Value Fund. This isn't just about the numbers; it's a testament to the trust our investors have in our vision and our team. Additionally, Félix was selected as an “Endeavour Entrepreneur” and was a recipient of the CrossTech Fintech Startups Award. We are a group of extremely talented and dedicated high-performers, united by our shared obsession with a single goal: empowering our customers. Joining Félix means you will be part of a team building a legacy, a company that will outlive us all. This is a rare opportunity to apply your skills to a deeply meaningful mission—serving a community that has been underserved for too long. We are a team that is fiercely loyal to each other, where radical transparency and constructive feedback are how we grow and push for excellence. We are bold, we care less about what others are doing, and more about creating sustainable value and a product that truly makes our users' lives better. We are building the future, today.
Role Description Félix is looking for a Senior Application Security Engineer to help scale the security of our software development lifecycle in a fast-growing, cloud-native fintech platform. This is a hands-on role focused on embedding security across CI/CD pipelines and developer workflows. You will work closely with SecOps and engineering teams to ensure that security controls are integrated early in the development process, enabling teams to ship secure code quickly and confidently. Your mission is to ensure that application security is consistently integrated into Félix’s SDLC, strengthening our overall security posture while supporting rapid product development. Responsibilities - Build and Automate Secure CI/CD Pipelines: Design, implement, and maintain security controls within our GitHub Actions CI/CD pipelines. - Drive Vulnerability Management: Take ownership of our vulnerability management program using platforms like DefectDojo. - Champion Secure Development: Act as a security subject matter expert for our product engineering teams. - Coordinate Security Assessments: Manage and support internal and external penetration testing engagements. - Develop Security Standards: Help define and document foundational security requirements for source code management. - Support Compliance Initiatives: Partner with our GRC function to implement necessary application security controls. Qualifications - Proven experience as an Application Security Engineer, Product Security Engineer, or in a similar role. - Hands-on experience building, securing, and operating CI/CD pipelines, preferably with GitHub Actions. - Strong proficiency with security scanning tools (e.g., SAST, DAST, SCA, secret scanning). - Proficiency in a scripting or programming language, with a strong preference for Python. - Deep understanding of web application vulnerabilities, secure architecture principles, and the OWASP Top 10. - Experience working with cloud-native technologies and environments (GCP, Kubernetes/GKE, Docker). - Experience in a regulated industry (Fintech, Healthcare, etc.) and familiarity with compliance frameworks like SOC 2 and PCI DSS. - Experience with Infrastructure-as-Code tools like Terraform and related security scanners (e.g., Checkov). - Familiarity with vulnerability management platforms like DefectDojo. Requirements - These are the applicable requisites, although equivalent competencies in any of the above will also be considered. Benefits - Competitive salary - Initial stock options grant - Annual performance bonus - Health, dental, and vision plans - Remote work environment, although we have offices in Miami and México City. - Continuous learning opportunities - Unlimited PTO - Paid parental leave - Empowering opportunities for growth in a dynamic entrepreneurial environment Equal Opportunity Employer At Félix, we are committed to providing equal employment opportunities to all qualified employees and applicants without regard to race, religion, nationality, sex, sexual orientation, gender identity, age, or disability.
Enterprise Security Trust Program Manager
SnowflakeSnowflake delivers the AI Data Cloud to help organizations share data, build apps and power their business with AI.
• Develop understanding of regulated industry compliance requirements as they apply to Snowflake. • Establish programs to manage Snowflake’s compliance posture with those regulations, including ensuring readiness, how we communicate that posture externally, and leading customer or regulator audits of the same. • Become an expert on Snowflake’s control environment, security features and best practices for customer deployment. • Respond to customer inquiries about Snowflake’s security and compliance obligations and lean into how we can enable customers and field personnel to increasingly self-serve. • Become a trusted advisor, facilitator and respond to customer and regulatory inquiries about Snowflake’s security and compliance obligations and documentation. • Participate in sales calls to discuss Snowflake's security and compliance capabilities.


