```html
Modern Health is a mental health benefits platform for employers, offering employees access to one-on-one, group, and self-serve digital resources across emotional, professional, social, financial, and physical well-being—all in a single platform. As a Product Security Engineer, you'll embed security into product development, protecting sensitive mental health data while enabling rapid innovation at a fully remote, high-growth company backed by leading investors including Kleiner Perkins, Founders Fund, and Y Combinator.
About the Role
Join Modern Health's security team to drive product security and application security initiatives across our mental health platform. You'll collaborate with product, engineering, and leadership teams to identify and mitigate security risks, design secure architectures, and establish security practices that scale with the business. This role bridges security expertise and product development, ensuring compliance and data protection requirements are met while maintaining velocity.
Responsibilities
- Conduct threat modeling and security architecture reviews for new features and systems handling sensitive health data
- Perform application security assessments, code reviews, and vulnerability analysis to identify and remediate risks
- Partner with engineering teams to implement secure coding practices and integrate security testing into CI/CD pipelines
- Develop and maintain security requirements and controls aligned with regulatory frameworks (HIPAA, SOC 2, etc.)
- Lead security incident response and post-incident reviews for product-related security events
- Create security documentation, runbooks, and guidance for product teams
- Evaluate third-party tools, libraries, and dependencies for security vulnerabilities and licensing concerns
Requirements
- 5+ years of experience in application security, product security, or related security engineering roles
- Strong understanding of secure software development lifecycle (SDLC) practices
- Hands-on experience with threat modeling, vulnerability assessment, and secure architecture design
- Proficiency in code review and ability to identify common vulnerability patterns (OWASP Top 10)
- Experience with security testing tools and frameworks
- Familiarity with cloud platforms (AWS, GCP, or Azure) and containerization security
- Knowledge of relevant compliance standards (HIPAA, SOC 2, GDPR) is a plus
- Strong communication skills and ability to translate security concepts for non-security stakeholders
- Authorized to work in the United States
Benefits
- Fully remote position—work from anywhere in the US
- Competitive salary and equity package
- Comprehensive health, dental, and vision coverage
- Mental health and wellness benefits
- Professional development and learning opportunities
- Collaborative, empathy-driven culture with high accountability
```