资深安全工程师
Staff Security Engineer
职位描述
Hi, I'm Megan https://www.linkedin.com/in/meganstewart99/, and I lead the Product Security team at Jane. Product Security work day to day with the developers building the software that 70,000+ clinics use to book, chart, and bill. My view of security is that it's a partnership with developers. The people who do well here can take complex insights and make them digestible for a busy team, and focus on fixing the cause, rather than repeatedly fixing the effects of an issue.
We need a staff-level engineer who can identify the themes that tie together the insights we uncover and work with product teams to better how we build secure software at the architecture level. There's a full roadmap behind that too: changes to how our development lifecycle and GitHub workflows run, private package repositories, maturing our SCA tooling, and a security champions program. You'd lead some of those projects outright.
We also lean into AI on this team, in the back office and in the product. We're already automating reporting and reminders, and the next step is using AI for vulnerability analysis and getting closer to the code with draft fixes. If you've been somewhere that kept AI locked away and you want to build with it, or you're already securing AI features and want to do it at scale, this is a great place for that.
我们希望你带来的影响
- 通过识别漏洞中的共同主题,将重复的AppSec发现转化为架构修复,并与产品团队合作设计这些修复方案,而不是逐个实例进行修补。
- 全程主导产品安全项目,从私有包仓库开始,提升我们的SCA工具,以及改进我们的开发周期和GitHub工作流程。
- 将AI融入团队的工作方式,推动我们从自动化提醒和报告转向AI辅助的漏洞分析和更接近代码的修复草案。(尚未确认,待招聘经理跟进)
- 在Jane内部推广安全开发,通过与开发者建立信任关系,用通俗易懂的语言解释风险,并帮助长期团队无摩擦地采用新实践。
- 主导安全计划,在跨职能小组中代表产品安全团队,并作为团队中最资深的实战工程师指导同事。
我们需要的经验
- 具备高级应用安全经验,包括全程负责安全计划,并直接与开发团队协作。
查看英文原文
ABOUT THE ROLE
Hi, I'm Megan https://www.linkedin.com/in/meganstewart99/, and I lead the Product Security team at Jane. Product Security work day to day with the developers building the software that 70,000+ clinics use to book, chart, and bill. My view of security is that it's a partnership with developers. The people who do well here can take complex insights and make them digestible for a busy team, and focus on fixing the cause, rather than repeatedly fixing the effects of an issue.
We need a staff-level engineer who can identify the themes that tie together the insights we uncover and work with product teams to better how we build secure software at the architecture level. There's a full roadmap behind that too: changes to how our development lifecycle and GitHub workflows run, private package repositories, maturing our SCA tooling, and a security champions program. You'd lead some of those projects outright.
We also lean into AI on this team, in the back office and in the product. We're already automating reporting and reminders, and the next step is using AI for vulnerability analysis and getting closer to the code with draft fixes. If you've been somewhere that kept AI locked away and you want to build with it, or you're already securing AI features and want to do it at scale, this is a great place for that.
WHAT IMPACT WE'RE LOOKING FOR YOU TO MAKE
- Turn recurring AppSec findings into architectural fixes by spotting the common themes across vulnerabilities and partnering with product teams to design them out, rather than patching one instance at a time.
- Lead product security projects end to end, starting with private package repositories, maturing our SCA tooling, and the changes to how our development lifecycle and GitHub workflows run.
- Build AI into how the team works, moving us from automated reminders and reporting to AI-assisted vulnerability analysis and draft fixes that land closer to the code. (unconfirmed pending recruiter follow-up)
- Champion secure development across Jane by building trusted relationships with developers, explaining risk in plain language, and helping long-tenured teams adopt new practices without friction.
- Own security initiatives and represent Product Security in cross-functional groups, and mentor teammates as the team's most senior hands-on engineer.
WHAT EXPERIENCE WE NEED
- Staff-level application security experience, including owning security initiatives end to end and working directly with development teams.
- A real development background. Ruby on Rails is ideal; Python, Java, or C# with a willingness to get into a Rails codebase works too. You can read a draft PR and tell whether the fix is right.
- Experience finding systemic vulnerability patterns and driving architectural fixes with engineering teams, not only reporting individual findings.
- Strong relationship skills with developers and stakeholders. You make security digestible, you're comfortable pushing back kindly, and people trust you.
- Hands-on experimentation with AI in your security work, ideally building automation rather than one-off use. Experience securing AI features in a product is a strong asset.
If you don't meet every single qualification but are excited about this role, we'd still love to hear from you.
MORE ABOUT JANE
Jane is a founder-led, high-growth SaaS company with a remote-first team working across Canada, the US, and the UK, united by our mission to help the helpers.
We build the products and tools that thousands of clinics rely on every day to run their businesses, care for their patients, and grow their communities. That level of impact means every person at Jane plays an important role in how we show up for our customers. We're all responsible for being deeply connected to their needs, obsessed with improving their experience, and proud of the difference our work makes in their day-to-day lives.
Jane is growing fast, and that growth brings exciting challenges that call for adaptability, resilience, learning agility, and humility. We're proud of what we've built and quick to admit what we don't know yet. We listen, learn, and adjust as we go. More than 70,000 businesses run on Jane which has 250,000+ practitioners interacting with our product on a daily basis and growth is continuing to accelerate.
We're also embracing the possibilities of AI, using it to work smarter, improve our systems, and create even better experiences for our customers and our team. No matter your role or team, we expect every Janer to be curious, experimenting, and finding new ways to build with AI. We'll make sure you have the tools, support, and space to explore, learn, and share what you discover along the way.
Our goal isn't just delivery - it's delight. We move quickly, communicate openly, and solve real problems together. If you're energized by ambiguity, motivated by impact, and eager to learn with others, you'll thrive at Jane.
COMPENSATION & BENEFITS
At Jane, we’re committed to paying fairly, clearly, and above all, paying for growth. This role has an annual salary range of $158,400 to $247,500. While that is a large range, it is intentional. It reflects the full growth journey someone might take in the role, from developing skills early on to becoming highly proficient and ultimately achieving excellence.
Most new hires join at the accomplished stage, which for this role represents an annual salary of $188,100. A starting salary below this typically indicates a candidate with strong potential who is still developing key skills. Salaries above this usually apply to existing team members who have made a significant impact and bring deep Jane-specific knowledge.
We believe in paying for growth. You’ll have regular career development conversations with your manager and your compensation will grow as you gain experience and contribute meaningfully to our mission.
Paying clearly is one of our compensation fundamentals. Watch this https://vimeo.com/880258361 short video to learn how our salary bands are set. You’re also encouraged to ask questions about compensation at any point during the interview process.
We also offer a comprehensive benefits package, you can learn more about it here https://jane.app/documents/hiring/jane_benefits_overview.pdf!
Jane takes job scams and candidate fraud seriously. Jane will only contact you from an @jane.app http://jane.app email address. We'll never contact you from a personal email, ask for payment, or request purchases during the hiring process. If something doesn't seem right, please reach out to us at hiring@jane.app before sharing any personal information.