Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Lead Security Engineer image - Rise Careers
Job details

Lead Security Engineer

Solace is a healthcare advocacy marketplace that connects patients and families to experts who help them understand and take charge of their personal health.

🔥 About Solace

By harnessing the power of human connection through technology, Solace is transforming healthcare in the U.S.

Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate the system without help. By helping people work with professional health advocates, Solace serves as an integral, personal support layer for health issues in a way that the health system can’t. Using proprietary technology to match patients with experienced advocates, Solace cuts through the red tape of healthcare and helps individuals and families make informed decisions that result in better outcomes.

Solace is a Series B startup founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures and Signalfire. We have a lean, fully-remote U.S. team distributed coast-to-coast.

Check out our recent funding announcement in the WSJ here.

🧑‍💻 About the Role

We’re looking for a Lead Security Engineer to be our first security engineering hire and build out our security department from scratch. You will lead the charge in securing our patient-facing and internal web applications. You’ll be responsible for protecting sensitive health data, staying ahead of evolving threats, and shaping the security posture of a platform that directly impacts patients' lives.

This role is a critical hire as we continue to scale, balancing agility and speed with robust, scalable security practices. You will own end to end security processes and implementation.

What You’ll Do

  • Own web application security across all our products and services (React, Node.js, PostgreSQL, Heroku).

  • Promote a security-first culture within the organization by enforcing secure coding practices.

  • Analyze new and existing features for potential security risks.

  • Conduct regular threat modeling, vulnerability assessments, and penetration testing (both automated and manual).

  • Work cross-functionally with engineering, DevOps, and compliance teams to ensure HIPAA, SOC 2, and general data privacy adherence.

  • Monitor, detect, and respond to potential threats in real-time.

  • Lead investigations of security incidents and breaches and perform root cause analysis and support post-incident remediation and reporting.

  • Stay current on web vulnerabilities (e.g., OWASP Top 10) and mitigate them proactively.

  • Help foster a security-first culture through training, documentation, and mentorship providing guidance and training to engineering and product teams on secure development practices.

What You Bring to the Table

  • Experience working in a start-up environment.

  • 8+ years of experience in web application security or related engineering roles.

  • Proficiency with secure web development and auditing practices (e.g., input validation, authentication/authorization mechanisms, encryption in transit and at rest).

  • Experience with threat modeling, vulnerability scanning tools, and manual security testing.

  • Familiarity with regulatory/compliance frameworks

  • Experience in healthcare or other regulated industries and knowledge of implementing HIPAA compliant software.

Up for the Challenge?

We look forward to meeting you.

Fraudulent Recruitment Advisory: Solace Health will NEVER request bank details or offer employment without an interview. All legitimate communications come from official @solace.health emails only. Report suspicious activity to hiring@solace.health.

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Lead Security Engineer, Solace

If you're a seasoned professional in web application security and looking for a role that makes a real difference, then Solace has an exciting opportunity for you! As a Lead Security Engineer, you'll take the reins as our very first security engineering hire, paving the way for creating a robust security foundation at Solace. You’ll be at the forefront of protecting sensitive patient health data while working in a fully remote, agile environment. Your main responsibilities will include securing our patient-facing and internal web applications built on modern technologies like React, Node.js, and PostgreSQL. Imagine being able to shape the security posture of a platform that empowers patients to make informed health decisions. You'll engage cross-functionally with our engineering, DevOps, and compliance teams to ensure we meet critical data privacy and security standards like HIPAA and SOC 2. With your expertise in threat modeling, vulnerability assessments, and creating a security-first culture, you will train and mentor teams on secure development practices. At Solace, we are committed to transforming healthcare in the U.S., and your contribution as Lead Security Engineer could be pivotal in this journey. We can’t wait to see what you bring to the table!

Frequently Asked Questions (FAQs) for Lead Security Engineer Role at Solace
What are the responsibilities of a Lead Security Engineer at Solace?

As the Lead Security Engineer at Solace, your key responsibilities include ensuring web application security across our products and services, promoting secure coding practices, analyzing potential security risks in new and existing features, conducting vulnerability assessments, and collaborating with engineering and compliance teams to maintain HIPAA and SOC 2 compliance.

Join Rise to see the full answer
What qualifications do you need to be a Lead Security Engineer at Solace?

To be considered for the Lead Security Engineer position at Solace, candidates should have at least 8 years of experience in web application security or related roles, proficiency in secure web development practices, experience with threat modeling and vulnerability scanning tools, and familiarity with healthcare regulatory frameworks like HIPAA.

Join Rise to see the full answer
How does Solace ensure data privacy for patients?

Solace prioritizes data privacy by implementing rigorous security measures such as conducting regular threat modeling, vulnerability assessments, and ensuring compliance with relevant regulations. As a Lead Security Engineer, you will play a vital role in monitoring threats and responding in real-time to safeguard sensitive health information.

Join Rise to see the full answer
What kind of work environment can a Lead Security Engineer expect at Solace?

At Solace, the work environment is fully remote and dynamic, emphasizing agility and speed. The company values collaboration across various teams, and as the first security engineering hire, you'll have the unique opportunity to shape the security culture from the ground up.

Join Rise to see the full answer
What is the significance of a Lead Security Engineer in a startup like Solace?

The role of Lead Security Engineer at Solace is crucial as it helps establish the security posture of a startup that is transforming healthcare. Your expertise will not only protect patient data but also enhance trust in the platform as we scale and innovate in this complex industry.

Join Rise to see the full answer
Common Interview Questions for Lead Security Engineer
How do you approach building a security framework from scratch?

When building a security framework from scratch, start by conducting a risk assessment to identify critical assets and vulnerabilities. Next, establish security policies that align with regulatory requirements, implement security tools and technologies, and foster a security-first culture through training and awareness programs.

Join Rise to see the full answer
Can you explain your experience with threat modeling?

In my experience with threat modeling, I typically start by identifying assets and potential threats. I then analyze the attack vectors and vulnerabilities before prioritizing them based on impact and likelihood. This enables the identification of appropriate mitigation strategies and the formulation of a proactive security plan.

Join Rise to see the full answer
What do you consider the OWASP Top 10, and how do you mitigate these vulnerabilities?

The OWASP Top 10 is a list of the most critical security risks to web applications. To mitigate these vulnerabilities, I focus on implementing secure coding practices, regular vulnerability scans, and compliance checks. Additionally, conducting code reviews and threat modeling can help ensure that our applications are resilient against these common risks.

Join Rise to see the full answer
How do you ensure compliance with HIPAA in security practices?

To ensure compliance with HIPAA, I advocate for strong access controls, encryption of sensitive data, and regular security audits. Furthermore, educating the team about HIPAA requirements and conducting risk assessments helps to maintain compliance across all security practices and protocols implemented at Solace.

Join Rise to see the full answer
Can you describe a time you handled a security incident?

In a previous role, I encountered a security incident where suspicious activity was detected. I led the investigation, identifying the root cause and assessing the impact. Post-incident, I coordinated remediation efforts, enhanced monitoring systems, and provided a comprehensive report to stakeholders, ensuring continued vigilance against similar incidents.

Join Rise to see the full answer
What tools do you use for vulnerability assessments?

I utilize a combination of tools for vulnerability assessments, including automated scanners like Nessus and manual testing techniques. It's important to supplement automated findings with manual checks to ensure comprehensive coverage and address any potential false positives that might arise.

Join Rise to see the full answer
How do you promote a security-first culture within a team?

To promote a security-first culture, I emphasize regular training sessions, create accessible documentation on best practices, and encourage open communication about security. Recognizing team members who follow secure practices also helps to foster an environment where security is prioritized by everyone.

Join Rise to see the full answer
What is your strategy for securing web applications during the development lifecycle?

My strategy for securing web applications during the development lifecycle begins with incorporating security measures in the design phase. I advocate for secure coding standards, regular code reviews, and integrating security testing tools within CI/CD pipelines to identify vulnerabilities early and mitigate them before deployment.

Join Rise to see the full answer
How do you stay up-to-date with the latest security threats?

To stay current with the latest security threats, I regularly follow industry news, participate in webinars, and engage with community forums. I also subscribe to cybersecurity newsletters and research publications, ensuring I am well-informed about evolving threat landscapes and mitigation strategies.

Join Rise to see the full answer
What do you think are the biggest challenges in security for healthcare organizations?

The biggest challenges in security for healthcare organizations include managing sensitive patient data, ensuring compliance with strict regulations like HIPAA, and dealing with the increasing sophistication of cyberattacks. Balancing accessibility and security while fostering trust among patients is a critical aspect that organizations need to address continuously.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Solace Remote No location specified
Posted 4 days ago

Join Solace as a Technical Recruiter to drive the recruitment of engineering talent for a mission-driven healthcare advocacy startup.

Photo of the Rise User
Solace Remote No location specified
Posted 12 days ago

As a Senior Recruiter at Solace, you will play a critical role in building a team of healthcare advocates dedicated to transforming the healthcare landscape.

CACI Hybrid US VA Chantilly
Posted 10 days ago

Join CACI as a Linux Administrator to support the Department of the Air Force with your Linux OS expertise and commitment to compliance.

Photo of the Rise User
Posted yesterday

Join Aetos Systems as a Senior Cybersecurity Analyst and play a pivotal role in safeguarding our digital infrastructure.

Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
American Express Hybrid New York, New York, United States
Posted 7 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as a Technology Vendor Manager and play a key role in managing software vendor relationships and driving performance excellence.

osu Hybrid Medical Center Campus
Posted 5 days ago

As a Clinical Applications Analyst at The Ohio State University, you'll play a crucial role in improving patient care through advanced clinical information systems.

Photo of the Rise User
Posted 7 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Drive vendor management and enhance technology infrastructure as a Technology Vendor Analyst at American Express.

Photo of the Rise User
CVS Health Remote MD - Work from home
Posted 5 days ago

As a Senior LDAP Engineer at CVS Health, you'll play a crucial role in optimizing LDAP systems while transforming healthcare experiences.

Photo of the Rise User
Uni Systems Remote No location specified
Posted 12 days ago

Join Uni Systems as a DevOps Engineer and contribute to exciting projects while fostering innovation and collaboration.

Solace makes hardware and software message routers that efficiently move real-time information between distributed applications, devices and users over all kinds of local and global networks. Solace technology unifies many kinds of data movement s...

13 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!