Principal Security Engineer

Candidhealth
San Francisco +2 more
On-site

Who this role is best for

Aimed at senior security professionals who architect enterprise-grade systems in healthcare tech, requiring deep compliance expertise and leadership without direct reports.

Best fit for

  • Technical leaders comfortable being the sole security authority in a scaling startup.
    — “you will be the foundational technical pillar for security at Candid Health
  • Practitioners who balance security rigor with startup speed and trade-offs.
    — “you excel at navigating the technical trade-offs required in a fast-moving engineering organization

Things to consider

  • Must regularly interface with enterprise customers' CISOs as technical spokesperson.
    — “you'll regularly serve as the expert technical voice in the room with our largest enterprise customers
  • Equity-heavy compensation indicates lower base salary than pure-cash roles.
    — “we heavily value the potential upside from equity in our compensation package

How to stand out

  • Demonstrate specific HIPAA/HITRUST implementation case studies, not just compliance knowledge.
    — “Translate rigorous frameworks like HIPAA, SOC2, SOC1, PCI, and HITRUST into concrete engineering requirements
  • Show mentorship examples that scaled security culture beyond direct reports.
    — “mentor engineers, and help scale a world-class security engineering culture
  • Prepare technical risk-to-business translation examples for leadership discussions.
    — “translates complex technical risks into business priorities
Pace · Fast PacedCollaboration · MediumAutonomy · HighDecision Impact · CompanyLevel · Principal

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • secure system architecture
  • compliance with regulatory standards
  • security-first culture
Typical background
security engineeringhealthcare IT

Skills & requirements

Required

Security ArchitectureEnterprise SecurityData IntegrityCompliance Frameworks

Preferred

Healthcare Data SecurityAI Infrastructure

Stack & domain

LeadershipCommunicationHealthcare

About the role

Original posting from Candidhealth via Ashby

THE ROLE

You will be the foundational technical pillar for security at Candid Health. As our first Principal Security Engineer, you won't just be managing a compliance checklist—you will architect, build, and scale the technical systems that protect our customers and their patients.

Operating as a high-influence individual contributor, you will partner directly with Engineering and Product leadership to ensure we ship features rapidly while maintaining an ironclad promise of data integrity. This is a role for a heavy-hitting technical leader who wants to set the security blueprint for a fast-growing health-tech platform.

WHAT YOU’LL DO

  • Architect and Guide the Security Landscape: Serve as the ultimate technical authority for security at Candid. While you won’t be managing HR lines, you will set the technical bar, mentor engineers, and help scale a world-class security engineering culture.
  • Design the Enterprise-Grade Roadmap: Lead the technical transition from a foundational security posture to a best-in-class, resilient enterprise architecture capable of defending complex healthcare data workflows.
  • Drive Strategy at the Leadership Level: Act as the subject matter expert who translates complex technical risks into business priorities. You will partner with executive leadership to stack-rank risks and embed security directly into Candid’s overarching business strategy.
  • Bake Trust & Compliance into the Architecture: Translate rigorous frameworks like HIPAA, SOC2, SOC1, PCI, and HITRUST into concrete engineering requirements. You will ensure compliance is a living, automated process built into our code and infra, and you'll regularly serve as the expert technical voice in the room with our largest enterprise customers.
  • Evangelize a "Secure-by-Design" Culture: Level up our 200+ employees. Through threat modeling, secure coding practices, and cross-functional collaboration, you will embed a security-first mindset across every team from engineering to legal.
  • Own Vulnerability & Vendor Deep Dives: Oversee third-party penetration testing, dissect vendor architectures before integration, and ensure our production environments undergo continuous automated and manual scrutiny.

WHO YOU ARE

  • An Elite Technical Leader: You have 10+ years of experience in security engineering, with a proven track record of architecting secure systems across complex technical surface areas in both startup and scaled enterprise environments.
  • A Practitioner, Not Just a Theorist: You have driven security outcomes at scale. You know how to balance pragmatism with bulletproof defense-in-depth, and you excel at navigating the technical trade-offs required in a fast-moving engineering organization.
  • A Security Expert: You possess a deep, native understanding of sensitive, highly regulated datasets and the unique, high-stakes challenges of handling protected critical information
  • A Force Multiplier: You know how to code, architect, and influence. You are equally comfortable writing secure infrastructure-as-code, threat-modeling a distributed system, or standing in front of an enterprise customer's CISO to defend Candid's security posture.

Our values

We spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):

  • We put our customers first
  • We take care of each other and ourselves
  • We anchor on outcomes and work relentlessly and creatively to achieve them
  • We collectively prioritize building a diverse and inclusive workspace
  • We believe humility is our greatest strength
  • We are candid, kind, and committed
  • We strive to be the most prepared person in the room
  • We are truth seekers

Pay Transparency

The estimated starting annual salary range for this position is $240,000 - $310,000 USD. The listed range is a guideline from Pave https://www.pave.com/ data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.

Source: Candidhealth careers (Ashby)

Similar roles