Staff Security Engineer, Detection & Response (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote within the US through hub cities, including New York, San Francisco/Bay Area, Seattle, Boston, Washington, DC, and Chicago. New York City employees must work onsite three days per week; employees in Boston, DC, Chicago, Seattle, and San Francisco must attend monthly Work Together Days.
Salary: $221,000–$299,000 per year, plus equity and benefits.
Company
is a virtual healthcare platform providing women’s and family health programs through employer, health plan, and consumer services.
What you will do
- Own the incident detection and response program and lead hands-on investigations, including log analysis, incident reconstruction, and recommendations for business and engineering leaders.
- Threat-model systems and codebases, assess attack surfaces, trust boundaries, and data flows, and identify exploitable weaknesses.
- Hunt for bugs and SDLC control gaps, implement fixes, and coordinate broader remediation with engineering and product security teams.
- Own and tune detection logic through 7AI, validate investigations and escalations, define alert criteria, and improve logging and visibility.
- Assess and manage security risks in internally adopted and externally developed LLM, AI-generated code, and agentic systems.
Requirements
- 6+ years of security experience combining hands-on software or application security with detection and SIEM engineering ownership.
- Ability to read production code across multiple languages and stacks and determine whether findings are exploitable.
- Experience building threat models and reasoning about attack surfaces, trust boundaries, and data flows.
- Track record of finding and fixing systemic weaknesses through incident response or proactive review.
- Strong communication skills and the ability to direct investigations and influence peers.
- Must be based in the US hub-city network and meet the applicable onsite or monthly in-person attendance requirements.
Nice to have
- Experience with AI-assisted security operations, LLM-based triage, or agentic escalation systems.
- Experience securing AI and LLM-powered systems against prompt injection, model misuse, or agentic tool abuse.
- Exposure to secure-by-default infrastructure, golden paths, container or image security, and patching lifecycles.
- Certifications such as GCIH, GCFA, GCDA, OSCP, or CISSP.
Culture & Benefits
- Flexible hybrid work model with remote work through US hub cities and structured in-person collaboration.
- Employer-covered health, dental, and insurance plan options.
- Access to Maven healthcare services, including mental health, reproductive health, family planning, and pediatrics.
- Wellness partnerships, in-office meals, and Work Together Days.
- 16 weeks of fully paid parental leave and a new parent stipend after one year of employment.
- Annual professional development stipend, career coaching, equity, and 401(k) matching for US-based employees.
Hiring process
- Submit an application describing relevant security experience and transferable background.
- Interview requests and offers are sent only from an official @mavenclinic.com email address.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →