Pomelo Care is the leading virtual medical practice for women and children, providing care across various stages of life. They are seeking a Staff Security Engineer to own security problems end to end, build secure solutions, and partner with compliance to enhance safety and efficiency.
Responsibilities:
- Own security problems end to end: navigate ambiguity to decide what matters, build it, ship it independently
- Find the real risks and build the most direct controls that take them off the table
- Build secure-by-default libraries, guardrails, and tooling so dozens of engineers can move fast without footguns
- Define and implement strict least-privilege guardrails across all services to safeguard sensitive patient information and health metrics
- Harden developer machines to minimize the risk of supply chain attacks and Whatever Comes Next from AI
- Partner with compliance to turn control objectives into real controls, and help focus effort on the requirements that genuinely reduce risk and unlock new commercial opportunities (HITRUST, health plan requirements, etc.)
Requirements:
- You have a strong track record of making organizations measurably safer. That track record is risks you've closed, not tickets you've opened
- You can tell signal from noise, and you spend your time on the risks that actually move the needle
- You're a builder first: 7+ years of software engineering with production-grade code under your belt (Kotlin, Java, Python, Go, C# or similar)
- You have real security depth — threat modeling, identity and auth flows, the OWASP Top 10, cloud and supply-chain security
- When something's wrong, your instinct is to understand the actual threat and build the most direct fix — not to go shopping for a product that claims to handle it
- You're looking for room to own more over time — and you're the type to take it, not wait for it
- Have built in healthcare and understand HIPAA and HITRUST — and how to satisfy them without drowning engineering in process
- Have experience with Google Cloud Platform and a modern product stack
- Have built internal developer platforms or secure-by-default tooling that other engineers actually adopted
- Have worked in a fast-paced, product-oriented startup