Founding Security Engineer

Tandem
New York
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Ownership","Autonomy","Low-ego"]

Own how sensitive healthcare data is protected at scale. Build cloud and infrastructure security foundations across AWS and GCP, embed security into product design and code reviews, and lead detection, logging, and incident response with complete audit trails. Secure identity and corporate surfaces (SSO, endpoints, SaaS hardening) and implement security controls for agentic AI systems. Also operationalize security automation to support SOC 2, HIPAA, and HITRUST.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tandem
Tandem
1 month ago

Founding Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Own how sensitive healthcare data is protected at scale. Build cloud and infrastructure security foundations across AWS and GCP, embed security into product design and code reviews, and lead detection, logging, and incident response with complete audit trails. Secure identity and corporate surfaces (SSO, endpoints, SaaS hardening) and implement security controls for agentic AI systems. Also operationalize security automation to support SOC 2, HIPAA, and HITRUST.
Location: New York
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own cloud and infrastructure security across AWS and GCP by building guardrails, identity/network architecture, secrets management, and secure-by-default primitives.
  • •Build security into the product by leading secure design and code reviews, hardening authentication/authorization, and shipping secure tooling and libraries.
  • •Own detection, logging, and incident response, including audit trails proving how protected health information is accessed.
  • •Secure the corporate and identity surface including SSO, device/endpoint security, SaaS hardening, and access across the employee lifecycle.
  • •Secure agentic AI systems handling sensitive data by designing isolation and data-flow controls and implementing security automation for SOC 2, HIPAA, and HITRUST.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceVisionDentalPaid LeaveParental Leave401k

Key Requirements

  • •7+ years in security engineering with a strong software engineering foundation, including designing and implementing rather than only reviewing.
  • •Deep, hands-on cloud security experience across AWS and/or GCP, with real infrastructure-as-code experience.
  • •Experience across security domains including infrastructure, application, identity, and detection/response—able to operate as the first and only security engineer.
  • •Experience protecting sensitive data at scale, with familiarity working with PHI and HIPAA.
  • •Comfort designing security for LLMs and AI agents.
Experience:7+ years
Skills:OwnershipAutonomyLow-ego
Tech Stack:AWSGCPInfrastructure-as-codeSecrets managementAuthenticationAuthorizationSSOSaaS hardeningSOC 2HIPAAHITRUSTLoggingIncident responseAudit trailsLLMsAI agents

Company Brief

Tandem
Builds a virtual office platform that helps remote teams connect, collaborate, and communicate in real time with presence, audio rooms, and workspace tools designed to recreate an in-person office experience online.
Industry: Enterprise Software
Website