Kairos
Back to jobs

Senior Software Engineer, Product Security

On-site
Pomelo CareUS3 months agoWebsite
Fresh
Senior
Engineering, Product and Data

Compensation

Salary undisclosed
Apply
Share

Description

What you'll do

As our first Product Security Engineer, you will sit at the intersection of Security and Software Engineering. Reporting through our Security Engineering function, you will be a "Security Builder": embedded within our engineering teams with the autonomy needed to build the automation, tools, and workflows that make security a seamless part of the software development lifecycle. This is a unique opportunity for a talented software engineer with a passion for cybersecurity to pivot into a full-time security role and help us protect mission-critical systems, applications, and valuable patient data at Pomelo.

You aren't just finding bugs; you are building the systems that prevent and fix them at scale. Your work will be centered on three core strategic pillars:

  • Secure architecture and auth: you will design and implement auth enhancements such as magic link improvements and access/audit log features to monitor access and improve transparency.
  • Privacy engineering: you will lead the privacy engineering initiatives including DSAR integration, building automated data deletion capabilities directly into the Pomelo mobile app and our internal platform to ensure seamless compliance. You will also help improve privacy-preserving data de-identification and anonymization as needed.
  • Full-cycle remediation: you will own the end-to-end pentest-to-fix lifecycle. This means you don't just triage reports; you write the code to fix penetration test findings, remediate SAST issues, and build greenkeeping systems for high-volume dependency patching with regression testing.

Beyond these pillars, you will serve as a high-leverage engineering partner to the broader InfoSec team by:

  • Building secure-by-default libraries: reducing the load on core Software Engineering by creating internal libraries and patterns that make security the default path.
  • Threat modeling: partnering with engineering leads to conduct threat modeling and ensure secure design at the earliest stages of the development process.
  • Scaling through collaboration: as a security resource embedded in our engineering teams, you will help engineering squads navigate complex security use cases, translating GRC requirements into elegant code rather than manual checklists.

Who you are

You’re an enthusiastic and collaborative engineer who enjoys solving meaningful problems through code. You view security as a product challenge, and you believe the best way to secure a system is to make the "secure way" the "easy way." In particular, you:

  • Your foundation is in Engineering: You have 5+ years of software engineering experience and are ready to pivot to a full-time security role, bringing a strong foundation in computer science and a track record of shipping production-grade code (Python, Go, Kotlin or similar).
  • Have a security mindset: You understand the OWASP Top 10, identity flows and prompt injections, but you’d rather build a system that eliminates a class of vulnerability than manually triage individual alerts. You believe security expertise should be embedded into the development process, not bolted on at the end.
  • Are an automation enthusiast: you enjoy tackling complex problems with practical automation and are keeping up with trends in LLM agents to multiply your engineering impact.
  • Navigate ambiguity: as a floating resource across various engineering teams, you are comfortable context-switching and can quickly build rapport with different engineering teams to understand their needs.

We’ll be super excited if you

  • Have experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.
  • Have prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.
  • Have experience building data infrastructure that supports AI/ML workloads,internal developer platforms and privacy preserving data de-identification and anonymization techniques.
  • Have previously worked in a fast-paced, product-oriented startup environment.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged, and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We value working across disciplines, moving fast, data-driven decision making, learning, and always putting the patient first.

 

Benefits and Perks:

  • Comprehensive Health, Dental, and Vision coverage for employees and their families
  • High deductible Health Plans with Health Savings Account (HSA) options
  • Flexible Spending Account (FSA)
  • Equity grant participation
  • 401(k) program 
  • Competitive vacation policy 
  • 16 weeks paid parental leave 
  • Fully remote work flexibility (within the US)

Compensation:

The expected base salary range offered for this role is $190,000-$220,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications.

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Stack

PythonLLMsGCPMachine Learning
Posted
Mar 16, 2026
Last seen
Jun 26, 2026
First seen
Jun 26, 2026
Status
active
Senior Software Engineer, Product Security at Pomelo Care | Kairos