Senior/Staff Engineer, Application & Product Security
at Grow Therapy · 501-1000 employees
- Seniority
- Staff Principal
- Work model
- Remote
- Employment
- Full Time
- Location
- Remote
- Posted
- 5d ago
at Grow Therapy · 501-1000 employees
Grow Therapy is a mental-health platform that enables a 26,000-provider network to offer insured virtual and in-person therapy and psychiatric services.
Grow was born to tackle a critical challenge: making mental health care more effective and accessible for everyone. Since launching in 2020, 15 million sessions have started on Grow, and we've barely scratched the surface. We do it through a three-sided marketplace that empowers providers, augments insurance payors, and serves patients. Every solution we build reveals ten more waiting to be delivered, and that's just what gets us going. We've backed that ambition with more than $328M in funding, including our Series D at a $3B valuation from Sequoia Capital, Transformation Capital, TCV, SignalFire, Menlo Ventures, Goldman Sachs Alternatives, and others. At Grow, the work you do can literally change someone's life. Your work here doesn't stay on a screen; it impacts whether someone can find, afford, and access quality care. That ambition sets us apart, and offers you an endless runway to impact one of the world's most urgent issues. We don’t have passenger seats here. Everyone is driving something that matters. This work deserves real commitment. So if you thrive on meeting problems head on, untangling serious complexity, and working at pace with the sharpest yet kindest people around, you've come to the right place. THE OPPORTUNITY You'll make the secure path - the easy path for our engineering org of roughly 145 engineers, baking secure defaults, CI guardrails, and threat modeling into the SDLC so security ships with the product instead of blocking it, including for our fast growing AI and agent features. WHAT YOU'LL BE DOING - Champion a secure by default culture, building defense in depth into our frameworks, architecture, and everyday processes - Develop security requirements and work directly with teams to build them into new applications and services - Manually dig into our source code to build a real, working understanding of our products, not just a surface level view from tooling output - Drive the product security roadmap in collaboration with product, engineering, and the wider security team - Partner across product, engineering, DevOps, and services to ship secure software without slowing teams down - Design solutions that resolve and mitigate vulnerabilities and risk, and research the threats and attack methods most relevant to Grow - Run security risk assessments, hands on penetration testing, and threat modeling, and turn those findings into secure coding education for engineers YOU'LL BE A GOOD FIT IF - You have 6+ years of experience in application or product security - You code well enough to automate tedious work and build frameworks or services that solve real security problems - You've been hands on with microservice architectures - You collaborate well, both within a security team and across the wider engineering org - You prioritize based on real risk, not just raw vulnerability counts - You've rolled up your sleeves and built a deep understanding of a codebase, rather than just talking about SAST, DAST, and SBOM tooling from the outside - You work well with product managers and service teams, not just engineers, and you genuinely care about the product and how it actually functions Employment Type: Full Time, Exempt Base Compensation: The base compensation range for this position is: - Hybrid Commitment: $217,000–$288,000 USD Annually - Fully Remote Commitment: $182,000- $240,000 USD Annually This role can be hybrid (onsite from our NYC, San Francisco, or Seattle hub location three days per week: Tuesday, Wednesday, Thursday) or fully remote. Both arrangements include travel 2–3 times per year (e.g., company and department offsites). The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate’s working location. Full Time Employee Benefits: - Health Benefits: Comprehensive medical, dental, vision, life, and disability coverage. - Grow for Grow: No cost access to therapy through the Grow platform (available to US employees) - Financial Wellness: Retirement savings programs and equity opportunities to help you invest in your future. - Flexible Time Off, Paid Holidays & Winter Break: Flexible time off, company paid holidays (which vary by country), and a full company wide Winter Break to rest and recharge - Parental Leave: Up to 18 weeks of paid parental leave to support you and your growing family and a new child stipend. - Mental Health Mornings/Afternoons: Dedicated weekly flexible time for self care, whether that's therapy, exercise, journaling, time with family, or simply taking a break. - Wellness & Development Stipend: Annual stipend to support your personal wellbeing and professional growth, from fitness and education to books and learning resources. - Commuter Benefits: Pre tax commuter benefits to support teammates working from one of our hub locations. - Home Office & Meals: Support for your home workspace plus meal benefits, with offerings tailored to both remote and hub based employees. - Additional Perks: A variety of wellbeing benefits, including wellness memberships, virtual care, pet insurance discounts (where available), and global travel assistance. Research shows that some groups hesitate to apply unless they meet every qualification. If you’re excited about this role but don’t check every box, we encourage you to apply. At Grow, we value diverse experiences, transferable skills, and the unique strengths each person brings. Grow Therapy is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Use of AI Tools: We use certain AI and autom