Pomelo Care Logo

Senior Product Security Engineer

💰 $175k-$200k

Job Description

About us

Pomelo Care is the national leader in evidence-based healthcare for women and children. We deliver personalized, high-quality clinical interventions from reproductive care and pregnancy, infant care and pediatrics, to hormonal health through perimenopause and menopause, with long-term preventive care and condition management. Our model delivers 247 multispecialty care to address the medical, behavioral, and social factors that most significantly impact outcomes for women and children. We partner with payers, employers, and providers to expand access to quality healthcare across the system.

What you’ll do

As our first Product Security Engineer, you will sit at the intersection of Security and Software Engineering. Reporting directly to the CISO, you will be a “Security Builder”: embedded within our engineering teams with the autonomy needed to build the automation, tools, and workflows that make security a seamless part of the software development lifecycle.

You aren’t just finding bugs; you are building the systems that prevent and fix them at scale. Your work will be centered on three core strategic pillars:

  • Secure architecture and auth: you will design and implement auth enhancements such as magic link improvements and access/audit log features to monitor access and improve transparency.
  • Privacy engineering: you will lead the privacy engineering initiatives including DSAR integration, building automated data deletion capabilities directly into the Pomelo mobile app and our internal platform to ensure seamless compliance. You will also help improve privacy-preserving data de-identification and anonymization as needed.
  • Full-cycle remediation: you will own the end-to-end pentest-to-fix lifecycle. This means you don’t just triage reports; you write the code to fix penetration test findings, remediate SAST issues, and build greenkeeping systems for high-volume dependency patching with regression testing.

Beyond these pillars, you will serve as a high-leverage engineering partner to the broader InfoSec team by:

  • Building secure-by-default libraries: reducing the load on core Software Engineering by creating internal libraries and patterns that make security the default path.
  • Threat modeling: partnering with engineering leads to conduct threat modeling and ensure secure design at the earliest stages of the development process.
  • Scaling through collaboration: as a security resource embedded in our engineering teams, you will help engineering squads navigate complex security use cases, translating GRC requirements into elegant code rather than manual checklists.

Who you are

You’re an enthusiastic and collaborative engineer who enjoys solving meaningful problems through code. You view security as a product challenge, and you believe the best way to secure a system is to make the “secure way” the “easy way.” In particular, you:

  • Are a builder first: Have 5+ years of software engineering experience with a strong foundation in computer science and a track record of shipping production-grade code (Python, Go, Kotlin or similar).
  • Have a security mindset: You understand the OWASP Top 10, identity flows and prompt injections, but you’d rather build a system that eliminates a class of vulnerability than manually triage individual alerts. You believe security expertise should be embedded into the development process, not bolted on at the end.
  • Are an automation enthusiast: you enjoy tackling complex problems with practical automation and are keeping up with trends in LLM agents to multiply your engineering impact.
  • Navigate ambiguity: as a floating resource across various engineering teams, you are comfortable context-switching and can quickly build rapport with different engineering teams to understand their needs.

W e’ll be super excited if you

  • Have experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.
  • Have prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.
  • Have experience building data infrastructure that supports AI/ML workloads,internal developer platforms and privacy preserving data de-identification and anonymization techniques.
  • Have previously worked in a fast-paced, product-oriented startup environment.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged – and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We also offer:

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $175,000 to $200,000. We expect most candidates to fall in the middle of the range.

#LI-Remote

Potential Fraud Warning

Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information.

Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com.

If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at [email protected]  to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.

Share this job:
Please let Pomelo Care know you found this job on Remote First Jobs 🙏

5843 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like Pomelo Care

Explore remote-first companies similar to Pomelo Care. Discover other top-rated employers that offer flexible schedules and work-from-anywhere options.

Maven Clinic Logo

Maven Clinic

A virtual clinic providing digital care programs for women and families across fertility, maternity, parenting, and menopause.

View company profile →
One Medical Logo

One Medical

Accessible primary care services through in-office and virtual platforms across 19 major U.S. cities.

View company profile →
Fort Health Logo

Fort Health

Virtual mental health care for children and adolescents through pediatrician and school partnerships.

View company profile →
Seven Starling Logo

Seven Starling

Virtual behavioral health services for women during fertility, pregnancy, loss, postpartum, and early motherhood.

View company profile →
Brightline Logo

Brightline

Virtual therapy, psychiatry, and coaching for kids and teens, available to families nationwide.

View company profile →
Nutrition International Logo

Nutrition International

Delivering nutrition interventions in over 60 countries across Asia and Africa to improve public health.

View company profile →

Project: Career Search

Rev. 2026.3

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply