Member of Technical Staff, Security
Mandolin · San Francisco, California
- Location
- San Francisco, California, United States
- Employment
- Full time
- Level
- Staff
- Posted
- 4 months ago
About this role
About Mandolin
Nearly every disease will become treatable in our lifetimes. Mandolin is laying the clinical and financial infrastructure to get groundbreaking treatments to patients faster, powered by AI agents.
Mandolin partners closely with the largest healthcare institutions in the US, covering more than $10B drug spend across the country. We're backed by Greylock, SV Angel, Maverick, SignalFire, and the founders of Vercel, Decagon, and Yahoo.
The Role
Mandolin is seeking a highly motivated and versatile Security Engineer to help secure our applications, cloud infrastructure, and compliance programs. This role is ideal for a security generalist with hands-on experience across Application Security, Platform/Cloud Security, and Governance, Risk & Compliance (GRC). The ideal candidate will partner closely with Engineering, DevOps, IT, and Compliance teams to embed security into software development, infrastructure, and operational processes while supporting the organization’s overall security and compliance posture.
The ideal candidate is a hands-on security professional who can operate across multiple security domains, balance technical and compliance priorities, and help build scalable, practical, and business-aligned security programs.
What you’ll do
Integrate security into the Software Development Lifecycle (SDLC) and CI/CD pipelines
Conduct application security reviews, threat modeling, vulnerability assessments, and support secure code review practices
Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies
Design and implement security controls across cloud and infrastructure environments including AWS, Azure, or GCP
Secure cloud-native platforms, containers, Kubernetes environments, CI/CD systems, and Infrastructure-as-Code (IaC) deployments
Monitor and improve logging, alerting, vulnerability management, endpoint protection, and incident response capabilities
Collaborate with Platform Engineering and DevOps teams to improve infrastructure hardening and operational security practices
Support security compliance initiatives including SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST-based programs
Assist with risk assessments, audit readiness, evidence collection, policy development, vendor security reviews, and remediation tracking
Help drive security awareness, promote secure engineering best practices, and contribute to long-term security strategy and maturity initiatives
Research emerging threats, vulnerabilities, and security technologies to continuously improve organizational security posture
Must-have experience
4+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related cybersecurity roles
Strong understanding of application security, infrastructure/cloud security, and security compliance concepts
Experience securing modern web applications, APIs, cloud environments, and distributed systems
Hands-on experience with cloud platforms such as AWS, Azure, or GCP
Familiarity with CI/CD pipelines, container security, Kubernetes, and Infrastructure-as-Code security practices
Experience with security tools such as SAST, DAST, SIEM, vulnerability scanners, CSPM, EDR/XDR, and IAM solutions
Scripting or automation experience using Python, Bash, PowerShell, or similar languages.
Strong communication skills with the ability to collaborate across technical and non-technical teams
Nice-to-haves
Experience in SaaS, fintech, healthcare, or other regulated environments
Familiarity with Zero Trust architectures and modern identity/security frameworks
Experience supporting compliance audits and governance initiatives
Relevant certifications such as CISSP, Security+, CCSP, AWS Security Specialty, GSEC, OSCP, or similar
Compensation Philosophy
Compensation for this position will include a base salary, equity, and a variety of comprehensive benefits. The U.S. base salary range for this role is $160,000 - $270,000. Actual base salaries will be based on candidate-specific factors, including experience, skillset, and location, and local minimum pay requirements as applicable.
Benefits & Perks
As part of our total rewards package, we offer attractive benefits and perks to our employees, including:
Free lunch in the office daily & dinner if you're in the office past 7PM
Comprehensive health, dental, & vision insurance for you and your family
Life insurance
10 company holidays
Take what you need PTO
4% 401k matching
$300/month company-sponsored commuter benefits
State of the art gym in the office
And more!
Please note the above benefits & perks are for full-time employees
As published by Mandolin. Applications are handled on their site.
Skills this posting mentions
About Mandolin
Mandolin is the leading AI automation platform for specialty drug access. The company’s AI agents act just like a best employee, completing tasks like reasoning about clinical policies, calling payers, parsing faxes and handwritten notes, and making decisions across entire workflows.
All 5 openings at MandolinOne click, then it is written
Apply to Mandolin with a resume written for this role.
Queue Member of Technical Staff, Security and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Mandolin’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Mandolin
See all- 3 months ago
- 12 months ago
- 13 months ago
- 13 months ago
Similar roles elsewhere
See more- Today
Support Engineer, AI Infrastructure & Tooling
FigmaSan Francisco, CA • New York
$169k - $245k/yrMid levelEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Mandolin publishes. Refolk is not the employer and does not handle their hiring. Applications go to Mandolin directly.