Hinge Health Logo

Hinge Health

Lead Security Engineer

Posted 19 Days Ago
Remote or Hybrid
Hiring Remotely in New York, NY, USA
191K-287K Annually
Mid level
Remote or Hybrid
Hiring Remotely in New York, NY, USA
191K-287K Annually
Mid level
Lead and implement security guardrails for AI-enabled development and AWS cloud infrastructure. Design IAM and least-privilege controls, secure AI/ML pipelines, integrate security into CI/CD and developer tooling, run cloud/IAM audits, build AI-driven security monitoring and incident response, ensure HIPAA and other compliance, and mentor engineering teams.
The summary above was generated by AI
The Opportunity

Join the team securing the platform that helps millions of people move beyond musculoskeletal pain. As Hinge Health's engineering organization embraces AI-assisted development — including AI-powered code generation, automated PR review workflows, agent sandboxing, and MCP gateway integrations — we need a Lead Security Engineer who will build the security guardrails, tooling, and standards that ensure we ship with confidence. You'll sit at the critical intersection of cloud security, AI-enabled engineering, and identity & access management, partnering closely with Application Security, SRE, and R&D Engineering to design and enforce security-by-design principles across our AWS environment, CI/CD pipelines, and developer tooling. This is your chance to make a real impact on the lives of millions by driving advancements in healthcare security — ensuring utmost compliance and privacy while enabling engineers to move fast and safely.

Candidates must be within commuting distance to New York City

 
 
Who You Are
  • A Security-First Thinker: You instinctively design systems that are secure by default, and you know how to balance security rigor with engineering velocity.

  • An AI-Savvy Engineer: You're energized (not intimidated) by the rapid adoption of AI-assisted development and see it as an opportunity to build novel security frameworks.

  • A Trust Builder: You communicate effectively across engineering, compliance, and leadership teams — authoring clear, plain-spoken technical proposals that drive alignment.

  • A Learn-it-all: You stay ahead of emerging threats and continuously evolve your approach — from adversarial ML to supply chain attacks on AI pipelines.

  • A Leader at All Levels: You're hands-on in code and architecture, but you also mentor others and help the team self-organize around measurable outcomes.

     
Basic Qualifications
  • Bachelor's degree in a technical, engineering, or scientific field — or comparable education/experience

  • 3+ years in cybersecurity, with 3+ years focused on security operations or IAM

  • 2+ years of experience in cloud security operations, specifically AWS

  • 2+ years of coding experience (e.g., Python, Go, or TypeScript) with hands-on experience developing Terraform and infrastructure-as-code

  • Hands-on experience securing AI/ML systems, including data pipelines, model deployments, API integrations, and their security challenges

     
Preferred Qualifications
  • AWS Solutions Architect or Security Specialty certification

  • AI/ML security certifications or familiarity with adversarial machine learning threats and mitigation strategies

  • Experience building or integrating security controls into CI/CD pipelines and AI-assisted development workflows

  • Experience managing an Enterprise IdP, especially Okta, with deep understanding of OAuth 2.0 and SAML

  • SOC 2, PCI, or HIPAA audit/training certifications

  • Knowledge of low-level networking principles

What You'll Accomplish

In your first 3 months:

  • Audit current cloud security posture and IAM architecture across our AWS environment; build relationships with key stakeholders in Application Security, SRE, and R&D Engineering.

  • Assess existing AI-assisted development tooling (Claude Code, Cursor, MCP gateway) for security risks and begin developing a governance framework.

In your first 6 months:

  • Design and implement AI-driven tools and workflows to enhance security monitoring, threat detection, incident response, and IAM governance.

  • Develop and enforce policies and protocols to protect AI tools and platforms from misuse, data breaches, and external threats — including secure agent sandboxing and MCP server governance.

  • Deliver IAM solutions enabling secure, granular access controls that enforce least privilege principles, utilizing automation and AI for privilege escalation and approvals.

     

In your first year:

  • Own the security strategy for AI-enabled development and cloud infrastructure, acting as the primary subject matter expert for security engineering across the organization.

  • Ensure all compliance regulations — including HIPAA, privacy, and relevant security frameworks — are met for new services, AI tooling, and infrastructure.

  • Develop and drive cybersecurity initiatives related to incident response, threat intelligence, vulnerability management, and monitoring tools.

  • Mentor team members in adopting new security tools and processes; educate the broader organization through knowledge-sharing sessions and author clear technical proposals with measurable security OKRs.

     
About Hinge Health

At Hinge Health, we're using technology to scale and automate the delivery of healthcare – starting with musculoskeletal (MSK) conditions, which affect over 1.7 billion people worldwide. With an AI-powered human-centered care model, Hinge Health leverages cutting-edge technology to improve outcomes, experiences and costs to help people move beyond their pain. The platform addresses a broad spectrum of MSK care – from acute injury, to chronic pain, to post-surgical rehabilitation – through personalized, evidence-based care. As the preferred partner to 50+ health plans, PBMs and other ecosystem partners, Hinge Health is available to over 20 million people across more than 2,550 employers. The company is headquartered in San Francisco with additional offices in Montreal and Bangalore.

 

Learn more at hingehealth.com

What You'll Love About Us
  • Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn't available where you live.

  • Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match.

  • Modern life stipends: Manage your own learning and development.

     
Culture & Engagement

Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter. By submitting your application you are acknowledging we are using your personal data as outlined in the personnel and candidate privacy policy.

 
 


Beware of Phishing Attempts: We've noticed an increase in phishing where fraudsters impersonate employees and send fake job offers to steal sensitive information. We'll never ask for financial details during the hiring process and only use "@hingehealth.com" emails. If you receive a suspicious offer, stop communication and report it to the US FBI Internet Crime Complaint Center. To verify an email from our recruiting team, forward it to [email protected].

Similar Jobs

16 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-180K Annually
Senior level
140K-180K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead application security engineering across the SDLC using AI-assisted threat modeling, automated security testing, vulnerability prioritization, and secure-by-default controls. Partner with Engineering, Product, QA, DevOps, and AI platform teams to secure applications, APIs, cloud infrastructure, data, and AI/ML systems. Build security automation, CI/CD controls, policy-as-code guardrails, developer enablement, and proactive defenses against emerging threats such as prompt injection and data poisoning.
Top Skills: AIAi/MlAWSAzureBurp SuiteCi/CdContainer ScanningDastDjangoDockerFastapiGCPGithub Advanced SecurityIac ScanningInfrastructure-As-CodeJwtKubernetesNode.jsOauth2OidcOwasp ZapPolicy-As-CodeReactSastScaSemgrepSnykSonarqubeTrivy
Yesterday
Remote
United States
103K-158K Annually
Expert/Leader
103K-158K Annually
Expert/Leader
Artificial Intelligence • Cloud • Machine Learning • Software • Business Intelligence • Cybersecurity • Big Data Analytics
Serves as the senior technical authority for enterprise cybersecurity architecture and engineering supporting a federal VA program. Leads security architecture reviews, threat modeling, risk and gap analyses, modernization, governance, requirements traceability, and secure implementation across cloud, health IT, network, data, identity, and emerging technologies. Advises government and technical leadership, guides multidisciplinary teams, develops architectural standards and recommendations, supports A&A and ATO activities, presents executive briefings, reviews deliverables, and mentors cybersecurity personnel.
Top Skills: 5GAPIsArtificial IntelligenceAuthority To Operate (Ato)Cis ControlsCloud ComputingCryptographyDlpEnterprise Architecture ToolsFedrampFismaHipaaInternet Of ThingsMobile TechnologiesNetwork TopologyNist Cybersecurity FrameworkNist Sp 800-53Post-Quantum CryptographyQuantum ComputingSabsaSecurity Reference ArchitecturesVr/XrZero Trust
11 Days Ago
Remote
United States
180K-210K Annually
Senior level
180K-210K Annually
Senior level
Fintech • HR Tech • Payments • Cryptocurrency
Own security and infrastructure for a fintech payments platform, with security comprising roughly two-thirds of the role. Responsibilities include cloud and application security, IAM, secrets management, threat modeling, detection engineering, incident response, vulnerability management, compliance, privacy, CI/CD, infrastructure as code, observability, reliability, backups, disaster recovery, and on-call operations. The role reports to the CTO and will establish the security function as the company’s founding security hire.
Top Skills: BigQueryCcpaCi/CdCloud RunCloudflareCloudflare PagesDnsEthereumGdprGoogle Cloud PlatformIamInfrastructure As CodeIso 27001MySQLNode.jsPci DssSecret ManagerSecurity Command CenterSoc 2TypescriptVpcWaf

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account