Senior Application Security Engineer

3 weeks ago


San Francisco, United States Headway Full time
Headway

Find therapists near you who accept insurance. We'll help you find the right fit—and save you money. Get started today with online or in-person sessions.

Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance.

1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept insurance, making therapy too expensive for most people. Headway is building a new mental healthcare system that everyone can access by making it easy for therapists to accept insurance and scale their practice.

Headway was founded in 2019. Since then, we’ve grown into a diverse, national network of over 34,000 mental healthcare providers across all 50 states who run their practice on our software. We’re a Series D company with over $325m in funding from a16z (Andreessen Horowitz), Accel, GV (formerly Google Ventures), Spark Capital, Thrive Capital, Forerunner Ventures and Health Care Service Corporation.

We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.

About the role

The Trust team at Headway is focused on security and privacy for all of Headway’s customers - therapists, patients, and payers (ex: insurance companies and health systems). As an early member on the team, you’ll have the unique opportunity to be the builder and driver of our dedicated, in-house product and application security engineering efforts. In this role, you will partner closely with our product and engineering teams to ensure that our application is designed and developed securely so that we can maintain and grow customers’ trust in Headway.

What you’ll do at Headway:
  • Partner with Product and Engineering: Headway has many new product launches on the horizon that will transform the industry and have a rich data component. You will be a partner at both the design and development stage to ensure that we implement new features securely, including (but not limited to):
  • Participating in the implementation efforts
  • Doing security reviews
  • Helping with product design decisions
  • Auditing and surfacing vulnerabilities in our current products
  • Develop and Improve our Automated Tooling: Further enhance our automated tooling to scale our application security capabilities and find potential code problems both before and after we deploy.
  • Make the safe way, the easy way: Work on defining and building application guardrails so that developers can build securely by default. You also will work to instill a culture of secure development across engineering.
  • Assist in ongoing security operations: You will be part of the security and privacy team and have responsibilities to assist in incident response, vulnerability management, penetration testing, security reviews, and other operational tasks to ensure that our security program is operating at a world-class level.
Tools we use:
  • Languages: Python 3, TypeScript
  • Libraries: FastAPI, SQLAlchemy, React
  • Infrastructure: AWS (Fargate, ECS, S3, and more), Spark and Kafka
You’ll be great for this role if you have:
  • 0 → 1 security experience: You have 5+ years experience in security and/or software engineering roles with a demonstrated history of working on security-related projects or with responsibilities as a security generalist.
  • Strong cross-functional experience: You love partnering with other teams to help both teams achieve their goals.
  • Strong technical depth and breadth: You have technical experience with building secure platforms and products at a deep level. You are excited to perform security design and code reviews. You want to understand security systems and improve their efficiency and scalability.
  • Thrive in ambiguity: You love tackling ambiguous problems in a fast-paced environment with an optimistic and energizing attitude.
  • Innovation at Scale: You seek opportunities to lead the industry in implementing the latest security and privacy technologies.
  • Results driven: You care deeply about creating impact and driving results for Headway’s business.
  • Mission driven: You are motivated by Headway’s mission, increasing access to high quality mental health care.

After you apply to Headway, here are some details of what to expect during the interview process.

  • Initial screen: You’ll connect with someone in recruiting so you can learn more about the team, Headway’s mission and exciting growth, and we can get a better idea of your background.
  • First round: You'll meet with a member of our Security Engineering team for introductions and an architecture interview. Conducted similarly to a System Design interview, we’ll learn more about your knowledge of the role of security in engineering systems and web architecture.
  • Final rounds: You’ll meet several more team members for technical and non-technical interviews, including our CISO who this role reports to, and leave with a fuller picture of what it’s like to work at Headway.
  • References and the Offer: Our favorite part of the process We'll send over all of the details, including specifics on employee equity, and congratulatory messages from excited future team members
Compensation and Benefits:
  • The starting salary for an Application Security Engineer is $188,000 and increases to $230,000 based on industry tenure and experience.

Benefits offered include:

  • Equity Compensation
  • Medical, Dental, and Vision coverage
  • HSA / FSA
  • 401K
  • Work-from-Home Stipend
  • Therapy Reimbursement
  • 16-week parental leave for eligible employees
  • Carrot Fertility annual reimbursement and membership
  • 13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
  • Flexible PTO
  • Employee Assistance Program (EAP)
  • Training and professional development

We believe a team's strength is in its people, and we cannot achieve this mission without a team that reflects the diversity of this problem – across race, ethnicity, gender, sexuality, age, national origin, religion, family status, disability, military status, and experience.

Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please contact talent@findheadway.com.

Headway employees work remotely across the US, with the option to work from offices in New York City and San Francisco. Headway participates in E-Verify.

#J-18808-Ljbffr

  • San Francisco, California, United States Contrast Security Full time

    About the RoleWe are seeking a highly technical Senior Product Manager to join our foundational services group at Contrast Security. As a key member of our team, you will define and deliver the next generation of our application security platform, supporting a broad variety of application security use cases from development to production.This is a highly...


  • San Francisco, United States IDENTIFY SECURITY Full time

    We are seeking a highly skilled Staff Application Security Engineer with a strong background in cloud software service management and application security to join our dynamic team. In this role, you will play a crucial part in ensuring the reliability, scalability, and security of our software systems and digital experiences. You will work closely with the...


  • San Francisco, United States Crusoe Full time

    Crusoe is building the World's Favorite AI-first Cloud infrastructure company. We're pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications. Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the future of the...


  • San Francisco, United States Crusoe Full time

    Crusoe is building the World's Favorite AI-first Cloud infrastructure company. We're pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications. Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the future of the...


  • San Francisco, United States Tbwa ChiatDay Inc Full time

    Headway’s mission is a big one – to build a new mental health care system everyone can access. We’ve built technology that helps people find great therapists with the first software-enabled national network of providers accepting insurance.1 in 4 people in the US have a treatable mental health condition, but the majority of providers don’t accept...


  • San Francisco, United States ZipRecruiter Full time

    Job DescriptionCrusoe is building the World’s Favorite AI-first Cloud infrastructure company. We’re pioneering vertically integrated, purpose-built AI infrastructure solutions trusted by Fortune 500 companies to power their most advanced AI applications.Crusoe is redefining AI cloud infrastructure, with a mission to align the future of computing with the...


  • San Francisco, United States Amazon Development Center U.S., Inc. Full time

    Do you thrive on the challenge of threat modeling and fortifying the defenses of AI/Generative AI and cloud systems? Are you excited by the prospect of identifying customer security expectations for AI systems and influencing builders to embrace secure-by-default practices, making the secure path the seamless choice for our customers? As a Senior Security...


  • San Francisco, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout The RoleEnterprises of all sizes trust Abnormal Security's cloud products to stop cybercrime. Being effective at stopping cybercrime, due to its adversarial nature, requires a high level of agility to respond to threats. Our Research and Development organization is forming a group to develop advanced AI-powered...


  • San Francisco, California, United States Amazon Development Center U.S., Inc. Full time

    Job DescriptionAre you passionate about securing cutting-edge AI and Generative AI systems? Do you thrive on the challenge of threat modeling and fortifying defenses in cloud environments?We're seeking a Senior Application Security Engineer to join our AWS Generative AI security team. As a key member of our team, you'll be responsible for security reviews...


  • San Francisco, United States Nextdoor Full time

    Job DescriptionJob Description#TeamNextdoorNextdoor is where you connect to the neighborhoods that matter to you so you can belong. Our purpose is to cultivate a kinder world where everyone has a neighborhood they can rely on.Neighbors around the world turn to Nextdoor daily to receive trusted information, give and get help, get things done, and build...


  • San Francisco, United States Nextdoor Full time

    #TeamNextdoor Nextdoor is where you connect to the neighborhoods that matter to you so you can belong. Our purpose is to cultivate a kinder world where everyone has a neighborhood they can rely on. Neighbors around the world turn to Nextdoor daily to receive trusted information, give and get help, get things done, and build real-world connections with those...


  • San Francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA HYBRID 2-3 days per week OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience...


  • San Francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA - Fully OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience in the...


  • San Francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA - Fully OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience in the...


  • san francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA HYBRID 2-3 days per week OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience...


  • San Francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA HYBRID 2-3 days per week OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience...


  • san francisco, United States MDS (Micro-Data Systems) Full time

    Senior Security EngineerLocation: San Francisco, CA - Fully OnsiteTop skills/tools, etc. that are MUST haves:Core security with experience deploying / upgrading and migrating Palo Alto firewallsConsultative and team playerHigh level of experience with Panorama and log collectorsPalo Alto Next Generation FirewallsDetailed technical experience in the...


  • San Francisco, United States Incode Technologies Full time

    The OpportunityWe are looking for a trustworthy and proactive Senior Security Engineer to be the technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations...


  • San Francisco, United States Material Security Full time

    As a Senior Software Engineer for Platform at Material Security, you’ll build and own ambitious projects spanning our highest-scale systems. You’ll be responsible for balancing the reliability, performance, and resource-consumption of Material’s core platform services and subsystems.ResponsibilitiesBuild a sophisticated and flexible attachment...


  • San Francisco, United States OpenAI Full time

    Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team...