Avatar for Curative
Curative
Actively Hiring
Building a healthier tomorrow, together
  • B2B
  • Scale Stage
    Rapidly increasing operations

Staff Security Engineer

  • Remote ()
  • |8 years of exp
  • |Full Time
Posted: 2 months ago
Hires remotely in
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
TypeScript
Shell
Elk
DataDog
IAM
DLP
Go
DAST
SAST
EDR
AWS Security
Kubernetes Security
Containerized Workloads

About the job

About Curative

Curative is building the future of health insurance with a first-of-its-kind employer-based plan designed to remove financial barriers and make care truly accessible: one monthly premium with $0 copays and $0 deductibles*. Backed by our recent $150M in Series B funding and valuation at $1.275B, Curative is scaling rapidly and investing in AI-powered service, deeper member engagement, and a smart network designed for today’s workforce.

Our north star guides everything we do: healthcare only works when people can actually use it. That belief drives every decision we make: from how we design our plan, support our members, to how we collaborate as a team.

If you want to do meaningful work with a team that moves fast, experiments boldly, and cares deeply, Curative is the place to do it. We’re growing fast and looking for teammates who want to help transform health insurance for the better.

Role Overview

Unlike most insurers, we build our own software. Our member, provider and operations platforms are systems we wrote, and we hold sensitive health data in systems we designed ourselves. That means we get to secure them the way a software company would, not the way an insurer usually does.

As one of the most senior hands-on security engineers at Curative, you will focus on building and shipping production systems rather than drafting policy. In this builder-focused role, you will take end-to-end ownership of our technical security architecture: building threat detection and response capabilities, embedding security into our software development lifecycle, securing our AI ecosystem and internal tools, hardening our AWS baseline, and protecting the identity, endpoint, and operational footprint used daily by our workforce.

Rather than hiring narrow domain experts, we build around multi-faceted engineers who seamlessly bridge application security, incident response, AI safety, and infrastructure hardening. We look for deep expertise in at least one core domain alongside a broad technical range, driven by an AI-first mindset that scales personal leverage. Whether your foundation lies in full-stack software development or high-velocity security automation, you default to shipping code over manual processes. You leverage LLMs and automated AI agents within your daily execution to scale solutions across domains that historically demanded full sub-teams. Crucially, you demonstrate strong engineering judgment on knowing precisely when to write custom tools, deploy commercial solutions, build autonomous workflows, or deprioritize.

We operate with an AI-first mindset across engineering, and our security practice leads that standard rather than falling behind it. Reporting directly to the VP of InfoSec and IT, you will partner closely with talented peers across software, platform, infrastructure, data, and compliance teams. Driving impact requires cross-functional alignment to ensure robust security controls seamlessly support rapid execution.

This is a remote position

Key Responsibilities

Detection, Response & Visibility

  • Own strategy and hands-on engineering for Detection and Response platforms; identify, onboard, and normalize all log sources including cloud, containers, endpoints, and SaaS
  • Build and maintain Security Orchestration, Automation, and Response (SOAR) tooling, including AI agents for alert triage and investigation enrichment, to reduce response time and analyst toil
  • Lead incident response for complex threats including developing runbooks, driving post-incident improvements, and designing/running BCP/DR tabletop exercises.

Product Security

  • Embed security into the SDLC: threat modeling, secure design reviews, SAST/DAST tooling, AI code review, and automated security gates in CI/CD pipelines and AI processes
  • Own the vulnerability management program at host and application levels; track and drive remediation
  • Champion "security as code" practices across engineering teams

AI & Security

  • Build AI-powered security tooling: threat detection and anomaly identification at appropriate confidence thresholds, automated triage and remediation workflows, and AI-assisted post-mortem summarization
  • Define and implement the security model for LLM-based systems and internal AI tooling
  • Architect harness patterns to constrain LLM behavior and harden against prompt injection, indirect injection via RAG pipelines, and data exfiltration via model outputs
  • Evaluate and govern AI tool adoption from a security and data-risk perspective

Infrastructure & Platform Security

  • Own AWS security posture and enforce baselines across Linux/Windows, network devices, and enterprise SaaS (M365, Google Workspace, Azure)
  • Partner with IT as a peer to protect corporate assets (identity, endpoints, enterprise SaaS) with an AI-forward lens: ship controls IT can operate, and use agents to automate access reviews, offboarding checks, and vendor onboarding
  • Engineer, configure, and operate EDR, DLP, and endpoint security programs
  • Provide IAM architecture expertise across identity and access systems

Leadership & Mentorship

  • Mentor and actively develop junior and mid-level security engineers through design reviews, pairing, and direct feedback. Growing team capability is a core expectation of this role
  • Define and drive security engineering standards across the organization
  • Collaborate closely with IT operations, platform, and software to translate threat intelligence into detection and hardening priorities

Qualifications

  • Software engineering or strong scripting background (Python, Go, Typescript, or shell): you write production-quality code, keep it in version control, and would rather ship a tool than file a ticket
  • Depth in one or more specializations: AI Security, Product Security, Detection & Response.
  • 8+ years in security engineering with demonstrated growth into technical leadership
  • Breadth and hands-on SIEM experience (DataDog, ELK, or equivalent)
  • Breadth and hands-on AWS security and IAM expertise
  • Breadth and hands-on Product security fundamentals: threat modeling, SAST/DAST, secure SDLC
  • Experience building with AI/LLM APIs and practical knowledge of LLM security risks
  • Breadth and hands-on experience with EDR, DLP, and vulnerability management
  • Breadth and hands-on experience with containerized workloads and Kubernetes security
  • Proven track record of mentoring engineers and raising team capability

Nice to Have

  • Startup or scale-up experience in regulated SaaS (healthcare, fintech, or similar)
  • CISSP, GIAC, or OSCP certification
  • MITRE ATT&CK knowledge applied to detection engineering
  • "Security as code" experience (OPA, Checkov, tfsec, or similar)
  • Data science or anomaly detection skills applied to security telemetry
  • Healthcare industry background (HIPAA, HITRUST)
  • Experience with the following tools/technologies: Kubernetes/EKS, Terraform/Terragrunt, Atlantis, Cloudflare, Buildkite, Wiz, Semgrep, EscapeTech, GitHub Advanced Security, Datadog, HashiCorp Vault, N8N, Snowflake, Linear

Perks & Benefits

  • Curative Health Plan (100% employer-covered medical premiums for you and 50% coverage for dependents on the base plan.)
    • $0 copays and $0 deductibles (with completion of our Baseline Visit )
    • Preventive and primary care built in
    • Mental health support
    • One-on-one care navigation
    • Chronic condition programs (diabetes, weight, hypertension)
    • Maternity and family planning support
    • 24/7/365 Curative Telehealth
    • Pharmacy benefits
  • Comprehensive dental and vision coverage
  • Employer-provided life and disability coverage with additional supplemental options
  • Flexible spending accounts
  • Generous PTO policy plus 11 paid annual company holidays
  • 401K for full-time employees
  • Generous Up to 8–12 weeks paid parental leave, based on role eligibility.

About the company

Curative company logo

Curative

Actively Hiring
Building a healthier tomorrow, together501-1000 Employees
Company Size
501-1000
Company Type
Healthcare Technology
Company Type
Health Tech
Company Type
Diagnostic
Company Type
Molecular Diagnostic
Company Type
Population Health
Company Type
Biotech
Company Type
Health And Medicine
  • B2B
  • Scale Stage
    Rapidly increasing operations
Learn more about Curative image

Funding

AMOUNT RAISED
$152.5M
FUNDED OVER
1 round
Round
B
$152549994
Series B - Nov 2025

Founders

Isaac Turner
Co-founder, CTO • 7 years
San Francisco Bay Area
image
Vlad Slepnev
CSO • 7 years
image
Fred Turner
CEO • 7 years
Los Angeles
image
View the team image

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives
Archesys company logo
Archesys
Improving the government services that impact everyday lives
Archesys company logo
Archesys
Improving the government services that impact everyday lives
Take-Two Interactive Software company logo
Take-Two Interactive Software
Game development needs creativity, but creativity needs an environment to be nurtured in
Neuralink company logo
Neuralink
Ultra-high bandwidth brain-machine interfaces to connect humans and computers
T-Rex Solutions company logo
T-Rex Solutions
We solve our clients’ critical challenges by leveraging our innovative technical expertise
LogicMonitor company logo
LogicMonitor
We expand what’s possible for businesses by advancing the technology behind them
IgniteTech company logo
IgniteTech
AI-first enterprise software that helps organizations grow revenue and transform