nMust Have: Experience in Consumer facing Product companies
n
nWhat this role is about
nWe’re looking for a hands-on Product Security Engineer who enjoys breaking things (ethically), understanding how systems actually work, and fixing security issues before they become incidents.
n
nYou’ll work closely with engineering teams to secure our web, mobile, and API platforms and help embed security naturally into how products are built.
n
nThis is not a policy-only or tool-only role. You’ll be close to the code, architecture, and developers.
n
nWhat you’ll do (day to day)
n
n
- Review applications and APIs for real-world security issues, not just OWASP checklists
n
- Threat model new features and architecture changes before they go live
n
- Test web and mobile applications through hands-on black-box testing
n
- Help developers fix vulnerabilities and explain why they matter
n
- Set up and maintain security checks in CI/CD pipelines (SAST, SCA, IaC scanning)
n
- Coordinate penetration tests, review findings,
and make sure issues actually get fixed
n
- Manage our Truemed’s VDP Program
n
- Review AWS security basics - AWS WAF, S3 exposure, secrets, and logging
n
n
nWhat we’re looking for
n
n
- 4-7+ years of hands-on experience in application or product security, in a consumer facing product company
n
- Strong understanding of web, mobile (android / iOS) and API security fundamentals
n
- Practical experience with DevSecOps tools and CI/CD pipelines
n
- Ability to work closely with engineering teams and explain security clearly
n
- Comfortable operating in a fast-moving product setting
n
n
nNice to Have
n
n
- Experience with AWS-native services
n
- Prior work in consumer-scale or data-sensitive platforms
n
n
nWhy you’ll enjoy working here
n
n
- You’ll have ownership and visibility, secure healthcare data.
n
- Security feedback is taken seriously and acted on
n
- You’ll help shape how product security works as the company grows
n