Staff Software Engineer (Product Security)
Maven Clinic · United States
About The Role
Join Maven, a digital health company focused on women's and family health. As a Staff Software Engineer in Product Security, you will design and implement scalable infrastructure for compliance, build and maintain identity and access management systems, and lead threat modeling and security architecture reviews. You will also create self-service security tools, automate security processes, and contribute to incident response and continual improvement of security posture. This role offers a range of benefits, including 401K matching, paid parental leave, professional development stipend, and access to wellness partnerships.
- Design and implement scalable infrastructure supporting HIPAA, SOC 2, and ISO 27001 compliance, and establish Zero Trust principles.
- Create self-service security tools that integrate with developer workflows, automate onboarding/offboarding, access reviews, and approvals.
- Lead threat modeling and security architecture reviews for new products and services, and partner with product and data teams to embed secure-by-default design patterns.
- You care deeply about our mission—building safer, smarter healthcare for women and families
- You take a pragmatic, automation-first approach to solving security problems
- You balance rigor with velocity, enabling teams to move quickly without compromising trust
- You communicate clearly with both technical and non-technical stakeholders
- You’re curious, adaptable, and eager to lead initiatives from concept to production
- Experience with Kubernetes, containers, and infrastructure-as-code (Terraform)
- Familiarity with security testing frameworks and secure SDLC principles
- Deep understanding of cloud security (GCP preferred; AWS/Azure welcome)
- Excellent communication and documentation skills
- Strong coding proficiency in Python, TypeScript, Go and/or Rust
- 8+ years of software engineering experience, including 3+ in security infrastructure or application security
- Proven ability to design and implement large-scale, distributed, cloud-native systems
- Experience with security compliance automation (SOC 2, ISO 27001, PCI-DSS, NIST)
- Expertise in Zero Trust architectures, authentication/authorization frameworks, and data-loss prevention
- Familiarity with AI/ML security and AI-assisted analysis tools
- Background in data security telemetry and threat detection
- Certifications (CISSP, GCP Professional Cloud Security Engineer, OSCP) a plus
- Exposure to supply-chain security and CI/CD pipeline hardening
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring