NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Security Engineer in United States of America
4 months ago
Apply with autofill
Apply with autofill
Candidhealth·4 months ago
4 months ago

Product Security Engineer

San Francisco (CA), United States of AmericaFull-timeSenior · 5+ yearsSecurity Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at candidhealth

How you compare FREE

?
Your scoreYour score: not yet known
→
49
Top 10%Top 10%: 49 out of 100

Top 10% of NextRaise users matched against Security Engineer roles in United States.

PDF or DOCX · no account needed

Apply faster with autofill FREEcandidhealth uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

About this role

About Candid Health

In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care.

 

That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.

 

Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish—submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.

 

Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups—processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.

 
 

Role Overview

We are looking for a Product Security Engineer to join our team and act as a champion for security within our product engineering organization. You will be responsible for ensuring our products are designed, developed, and maintained with security as a core pillar. You will work in partnership with development squads to perform threat modeling, guide secure architecture decisions, and automate security gates in our CI/CD pipelines.

Key Responsibilities

  • Security by Design: Lead threat modeling sessions during the architectural design phase of new features to identify potential risk vectors early.

  • Secure Development Lifecycle (SDLC): Drive the adoption of "Shift Left" security practices, integrating security tooling (SAST, DAST, SCA) directly into developer workflows.

  • Vulnerability Management: Triage, prioritize, and partner with engineering teams to remediate vulnerabilities found in code, third-party libraries, and cloud infrastructure.

  • Security Tooling & Automation: Build, maintain, and tune security automation tools to reduce friction for developers while maintaining high-security standards.

  • Secure Coding Standards: Develop and deliver training, coding patterns, and security guardrails to help engineering teams build resilient, secure-by-default products.

  • Incident Response Support: Assist in identifying the root cause of security incidents related to product features and contribute to post-incident remediation and architectural improvements.

  • Supply Chain Security: Build out processes and automation to ensure the security of open-source dependencies.

Required Qualifications

  • Experience: 5+ years of experience in software engineering or security engineering, specifically focusing on product security or application security.

  • Technical Skills:

    • Proficiency in one or more programming languages (e.g., Python, Go, Java, or JavaScript).

    • Deep understanding of modern web/cloud architecture (e.g., APIs, Microservices, Kubernetes, AWS/GCP/Azure).

    • Familiarity with the OWASP Top 10 and common exploitation techniques.

  • Collaboration: Proven ability to influence and collaborate with engineering teams without hindering development velocity.

  • Problem Solving: Strong analytical skills to evaluate complex systems and design innovative, practical security solutions.

Preferred Skills (Nice to Have)

  • Experience with Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation).

  • Experience in designing cryptographic implementations or secure authentication/authorization flows (e.g., OAuth, OIDC, JWT).

  • Knowledge of compliance frameworks relevant to our industry (e.g., SOC2, ISO27001, HIPAA).

Pay Transparency

The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.

Company

Candidhealth
San Francisco (CA), United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Candidhealth's careers site·first seen 16 Jun 2026·last verified 8 Sept 2026·How we source jobs

Similar jobs

  • Data Security Engineer at CommvaultUnited States–match not yet calculated
  • 2026 Intern Conversion: 2027 Return Intern Cybersecurity at Walmart(USA) ISD Office, United States of America–match not yet calculated
  • Application Security Engineer at strivehealthDenver, United States of America–match not yet calculated
  • UAS Cybersecurity Engineer at Science Applications InternationalHuntsville, United States of America–match not yet calculated
  • Cybersecurity Tools Engineer at 9thwayinsigniaUnited States - Remote–match not yet calculated

Browse more jobs

  • Security Engineer jobs in United States
  • Security Analyst jobs in United States
  • Cloud Security Engineer jobs in United States
  • Penetration Tester jobs in United States
  • Security Engineer jobs in India
  • Security Engineer jobs in United Kingdom