Member of Technical Staff, Security
Quick Summary
About Mandolin Nearly every disease will become treatable in our lifetimes. Mandolin is laying the clinical and financial infrastructure to get groundbreaking treatments to patients faster, powered by AI agents.
Mandolin is seeking a highly motivated and versatile Security Engineer to help secure our applications, cloud infrastructure, and compliance programs.
Nearly every disease will become treatable in our lifetimes. Mandolin is laying the clinical and financial infrastructure to get groundbreaking treatments to patients faster, powered by AI agents.
Mandolin partners closely with the largest healthcare institutions in the US, covering more than $10B drug spend across the country. We're backed by Greylock, SV Angel, Maverick, SignalFire, and the founders of Vercel, Decagon, and Yahoo.
Mandolin is seeking a highly motivated and versatile Security Engineer to help secure our applications, cloud infrastructure, and compliance programs. This role is ideal for a security generalist with hands-on experience across Application Security, Platform/Cloud Security, and Governance, Risk & Compliance (GRC). The ideal candidate will partner closely with Engineering, DevOps, IT, and Compliance teams to embed security into software development, infrastructure, and operational processes while supporting the organization’s overall security and compliance posture.
The ideal candidate is a hands-on security professional who can operate across multiple security domains, balance technical and compliance priorities, and help build scalable, practical, and business-aligned security programs.
Responsibilities
~1 min read- →
Integrate security into the Software Development Lifecycle (SDLC) and CI/CD pipelines
- →
Conduct application security reviews, threat modeling, vulnerability assessments, and support secure code review practices
- →
Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies
- →
Design and implement security controls across cloud and infrastructure environments including AWS, Azure, or GCP
- →
Secure cloud-native platforms, containers, Kubernetes environments, CI/CD systems, and Infrastructure-as-Code (IaC) deployments
- →
Monitor and improve logging, alerting, vulnerability management, endpoint protection, and incident response capabilities
- →
Collaborate with Platform Engineering and DevOps teams to improve infrastructure hardening and operational security practices
- →
Support security compliance initiatives including SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST-based programs
- →
Assist with risk assessments, audit readiness, evidence collection, policy development, vendor security reviews, and remediation tracking
- →
Help drive security awareness, promote secure engineering best practices, and contribute to long-term security strategy and maturity initiatives
- →
Research emerging threats, vulnerabilities, and security technologies to continuously improve organizational security posture
4+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related cybersecurity roles
Strong understanding of application security, infrastructure/cloud security, and security compliance concepts
Experience securing modern web applications, APIs, cloud environments, and distributed systems
Hands-on experience with cloud platforms such as AWS, Azure, or GCP
Familiarity with CI/CD pipelines, container security, Kubernetes, and Infrastructure-as-Code security practices
Experience with security tools such as SAST, DAST, SIEM, vulnerability scanners, CSPM, EDR/XDR, and IAM solutions
Scripting or automation experience using Python, Bash, PowerShell, or similar languages.
Strong communication skills with the ability to collaborate across technical and non-technical teams
Experience in SaaS, fintech, healthcare, or other regulated environments
Familiarity with Zero Trust architectures and modern identity/security frameworks
Experience supporting compliance audits and governance initiatives
Relevant certifications such as CISSP, Security+, CCSP, AWS Security Specialty, GSEC, OSCP, or similar
What We Offer
~1 min readCompensation for this position will include a base salary, equity, and a variety of comprehensive benefits. The U.S. base salary range for this role is $160,000 - $270,000. Actual base salaries will be based on candidate-specific factors, including experience, skillset, and location, and local minimum pay requirements as applicable.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- May 13, 2026
- First seen
- May 17, 2026
- Last seen
- May 17, 2026
Posting Health
- Days active
- 0
- Repost count
- 1
- Trust Level
- 57%
- Scored at
- May 17, 2026
Signal breakdown
Please let mandolin know you found this job on Jobera.
3 other jobs at mandolin
View all →Explore open roles at mandolin.
Similar Member Of Technical Staff jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.