Principal Security Engineer
Candidhealth · San Francisco (CA), Denver (CO), New York (NY)
About this role
## Principal Security Engineer ### The Role You will be the foundational technical pillar for security at Candid Health. As our first **Principal Security Engineer**, you won’t just manage a compliance checklist—you will architect, build, and scale the technical systems that protect our customers and their patients. You’ll operate as a high-influence individual contributor, partnering directly with Engineering and Product leadership to ship features rapidly while maintaining an ironclad promise of data integrity. ### What You’ll Do - **Architect and Guide the Security Landscape:** Serve as the ultimate technical authority for security at Candid. Set the technical bar, mentor engineers, and help scale a world-class security engineering culture. - **Design the Enterprise-Grade Roadmap:** Lead the transition from a foundational security posture to a best-in-class, resilient enterprise architecture for complex healthcare data workflows. - **Drive Strategy at the Leadership Level:** Translate complex technical risks into business priorities. Partner with executive leadership to stack-rank risks and embed security into Candid’s overarching business strategy. - **Bake Trust & Compliance into the Architecture:** Translate frameworks like **HIPAA, SOC 2, SOC 1, PCI, and HITRUST** into concrete engineering requirements. Ensure compliance is living and automated in code and infrastructure. - **Evangelize a “Secure-by-Design” Culture:** Level up a 200+ person organization through threat modeling, secure coding practices, and cross-functional collaboration. - **Own Vulnerability & Vendor Deep Dives:** Oversee third-party penetration testing, dissect vendor architectures before integration, and ensure continuous automated and manual scrutiny of production environments. ### Who You Are - **An Elite Technical Leader:** 10+ years of security engineering experience, with a track record of architecting secure systems across complex technical surfaces in both startup and scaled enterprise environments. - **A Practitioner, Not Just a Theorist:** You’ve driven security outcomes at scale and can balance pragmatism with defense-in-depth—while navigating trade-offs in a fast-moving org. - **A Security Expert:** Deep, native understanding of sensitive, highly regulated datasets and the challenges of handling protected critical information. - **A Force Multiplier:** You can code, architect, and influence. Comfortable with secure infrastructure-as-code, threat modeling distributed systems, and presenting security posture to enterprise customers’ CISOs. ### Our Values - We put our customers first - We take care of each other and ourselves - We anchor on outcomes and work relentlessly and creatively to achieve them - We collectively prioritize building a diverse and inclusive workspace - We believe humility is our greatest strength - We are candid, kind, and committed - We strive to be the most prepared person in the room - We are truth seekers ### Pay Transparency Estimated starting annual salary range: **$240,000 – $310,000 USD**. The listed range is a guideline from Pave (https://www.pave.com/). Actual base salary may vary based on job-related skills, experience/qualifications, interview performance, and market data. Total compensation may include equity, sales incentives (for sales roles), and employee benefits.
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.