Staff Software Engineer - App & Cloud Security
at WithCoverage · 51-100 employees
- Seniority
- Staff Principal
- Location
- New York, NY
- Posted
- 5d ago
at WithCoverage · 51-100 employees
WithCoverage provides an AI-enabled risk-management platform that identifies insurance coverage gaps and manages policy procurement for high-growth businesses.
<p><strong>Location:</strong> New York, NY<br><strong>Job Type: </strong>Full-Time</p> <p><strong>About </strong><a href="https://withcoverage.com/"><strong>WithCoverage</strong></a><strong>:</strong></p> <p><strong>WithCoverage replaces the traditional insurance brokerage with AI-supercharged risk management designed for the modern economy. </strong></p> <p>We partner with hundreds of high-growth, category-defining companies, including GoPuff, Eight Sleep, Bombas, Chomps, and Blank Street Coffee. Our clients span iconic consumer brands, hospitality leaders, GCs, advanced manufacturers, and next-generation defense contractors. They operate in complex risk environments and need a partner that can move at their speed.</p> <p>Instead of a fragmented, manual brokerage stack, we have built a new category: elite risk advisors operating on top of proprietary technology. Our in-house Agency Management System gives our team and AI agents full visibility into policies, exposures, claims, billing, and commissions. This platform enables deep automation, better decisions, and a fundamentally higher standard of service.</p> <p>WithCoverage was founded by JD Ross (co-founder of Opendoor) and Max Brenner (Bain, Compound). <strong>We have raised over $43M from leading investors including Sequoia, 8VC, Khosla Ventures and Crystal Venture Partners. </strong></p> <p>Our ambition is not to build a better brokerage. It is to redefine how risk is managed across the economy.</p> <p><strong>Why join us:</strong></p> <ul> <li><strong>Grow faster</strong> – We’re scaling quickly, giving you significant opportunities to learn, lead, and shape your career and the company's future.</li> <li><strong>Work that matters</strong> – We protect the world’s most innovative brands: consumer icons, hospitality leaders, next-gen defense contractors, and US manufacturers.</li> <li><strong>Redefine an industry</strong> – Insurance is one of the largest, slowest-moving markets. We rewrite the playbook with proprietary technology, automation, and AI.</li> <li><strong>Financial rewards</strong> – We hire the best and invest in you. That means competitive comp, meaningful equity, and excellent benefits. We believe strongly in internal promotion and lay out a plan for everyone's career growth.</li> </ul> <p><strong>About The Role:</strong></p> <p><strong>Staff Software Engineer - App & Cloud Security</strong></p> <p>We are open to a wide range of levels for this role.</p> <p>As a Staff Software Engineer - App & Cloud Security, your primary responsibility will be to secure every layer of WithCoverage: our products, production code, AWS infrastructure, AI systems, corporate technology, networks, and physical environment. You’ll help build our security architecture from the ground up while operating at startup speed.</p> <p>This is a hands-on engineering role. You won’t simply identify vulnerabilities or produce policies. You’ll write the code, Terraform, guardrails, detections, and internal tools that fix problems at their source. You’ll establish foundations such as RBAC, ABAC, tenant isolation, least-privilege access, secure networking, defense-in-depth, auditability, and incident response.</p> <p>You’ll also lead the technical work required to prepare WithCoverage for SOC 2, HIPAA, and related customer requirements. You’ll turn controls into continuously monitored systems, automate evidence collection, and make our security posture observable. Security here should increase our velocity, not create bureaucracy.</p> <h2>What You’ll Do</h2> <ul> <li>Establish and evolve cloud security capabilities across AWS, covering account organization, identity and access frameworks, network separation, and protected communication between services.</li> <li>Develop and maintain Terraform-driven security architecture – build reusable modules, paved roads, and automated guardrails that let engineers ship securely without waiting on a security approval process.</li> <li>Create and manage scalable cloud identity solutions encompassing workload identities, service accounts, role-based access, role assumption, and access across environments.</li> <li>Automate security processes throughout CI/CD pipelines and cloud platforms to minimize manual effort and lower operational exposure.</li> <li>Oversee the protection of production Kubernetes and container environments, including cluster hardening, RBAC, workload identity, container image assurance, and runtime safeguards.</li> <li>Automate security and compliance. Translate SOC 2, HIPAA, and customer requirements into technical controls. Automate evidence collection, access reviews, vulnerability detection, configuration monitoring, remediation, incident response, and recovery.</li> <li>Secure the company end to end. Protect our AI agents, sensitive client data, production systems, endpoints, corporate identities, office network, physical access, and vendors. Address AI-specific risks such as prompt injection, excessive tool permissions, data leakage, and unsafe autonomous actions.</li> <li>Make security move at startup speed. Make pragmatic build-versus-buy decisions, using software and AI to avoid expensive enterprise products when a focused internal capability is safer and more economical.</li> </ul> <h2>Who You Are</h2> <ul> <li>7+ years of experience building or securing software and infrastructure in production environments. You are comfortable moving from identifying a risk to writing, deploying, and operating the solution yourself. You are mostly in code.</li> <li>You have hands-on experience securing AWS environments and understand IAM, networking, Linux, containers, infrastructure as code, CI/CD, secrets management, encryption, logging, and vulnerability management.</li> <li>You have built or substantially improved authentication, authorization, RBAC, ABAC, multi-tenant isolation, or other security-critical product infrastructure. Experience preparing for SOC 2 or HIPAA is strongly