
Senior Security Engineer (Product Security)
Oscar Health
Job description
-
We’re hiring a Senior Product Security Engineer 1 to join our Security Team
-
As a Senior Product Security Engineer, you will be a key technical resource for the team, leading the security of the software development life cycle (SDLC) from design to completion. You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that our “paved roads” for development remain fast and secure
-
You will work to Secure Architecture. You will help architect, build, test, and deploy Oscar’s application security systems and processes
-
You will work on AI Integration & Security. You will design security measures for AI-driven workflows, specifically integrating security reviews into AI agent processes that bypass traditional ticketing
-
You will report into the Manager of Product Security
-
Vulnerability Management: Drive the vulnerability management lifecycle, from automated identification (SAST/DAST) to complex manual analysis and remediation tracking
-
Technical Mentorship: Act as a technical resource and mentor to junior engineers, providing guidance to remove obstacles and develop smooth, highly functional workflows
-
Code Review & Development: Conduct source code reviews of internal and third-party software while writing production-quality code and libraries for engineering teams to utilize
-
Risk Assessment: Build risk assessment frameworks and deliver action plans to manage assessed risks, simplifying intricate security concerns into actionable steps
-
Partner with Engineering: Provide guidance to Engineering teams for remediating or migrating vulnerabilities. Give in-depth software security presentations to the engineering team
-
Compliance with all laws and regulations
-
Other Duties as Assigned- 4+ years of combined career experience in software development and information security
-
Proven experience across all areas of the Secure Software Development Life Cycle
-
Hands-on experience using AI models and integrating them with internal systems via protocols like the Model Context Protocol (MCP)
-
Strong background in building moderate to complex standalone systems or major new features
-
Bachelors degree or four years of equivalent experience
-
Prior work experience in or understanding of security challenges specific to the healthcare or health insurance industries