Maven Clinic

Staff Security Engineer, Detection & Response

Maven Clinic • $221K — $299K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of security experience with a focus on software or AppSec and SIEM engineering.
  • Ability to read and assess production code across various languages.
  • Experience in building threat models related to attack surfaces and data flows.
  • Proven track record of identifying and resolving systemic vulnerabilities.
  • Strong communication skills to guide investigations and influence peers.

Responsibilities

  • Lead hands-on investigations of incidents and findings, building narratives and advising stakeholders.
  • Analyze production code to understand vulnerabilities and system behavior.
  • Proactively hunt for bugs and weaknesses within the codebase and SDLC.
  • Propose and implement fixes or manage resolutions with appropriate teams.
  • Own and refine detection logic, validating investigations and alert criteria.
  • Identify gaps in logging to enhance visibility for detection tools.
  • Assess and manage risks associated with AI and LLM technologies.

Benefits

  • Comprehensive health, dental, and insurance options covered by the employer.
  • Access to mental health and reproductive health specialists via Maven.
  • Support for wellness through various partnerships.
  • Generous 16 weeks of 100% paid parental leave and stipend.
  • Annual professional development stipend and personal career coaching.
  • 401K matching with immediate vesting for US-based employees.
Full Job Description
About the Role

You'll own our Incident Detection and Response program, including threat modeling our systems and codebase and directing the investigation when something does happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide technical direction and judgment calls. You'll spend most of your time finding bugs in our code and gaps in our SDLC before they become incidents, then building and implementing or project managing the fixes yourself. AI is a growing part of that surface, and as our reliance on LLMs, AI-generated code, and agents expands, you'll be responsible for understanding and managing the risk that comes with it.
What You'll Own
Investigation & Technical Direction
  • Lead investigations hands-on. When an incident or suspicious finding comes up, you pull the logs, build the narrative of what happened, and advise business and engineering leaders on next steps.
  • Read production code when needed to understand what's actually happening.
Proactive Hunting & SDLC Hardening
  • When you're not investigating, hunt for bugs in our codebase and weaknesses in our SDLC where problems can slip past existing controls.
  • Propose and implement fixes yourself, or manage the resolution with the right teams, whether that's a specific code fix, a broader process or control change.
  • Partner with our Product Security Engineer on golden paths when a weakness points to a systemic gap.
Detection Engineering
  • Own and tune the detection logic running through 7AI, validating its investigations and escalations and setting the criteria for what triggers an alert.
  • Close gaps in logging and visibility so the tooling has the right data to work with.
Managing AI Risk
  • Help us understand and manage the security risks that come with our growing use of LLMs and AI tooling, both in what we build and what we adopt internally.
What We're Looking For

Required:
  • 6+ years of security experience combining hands-on software or AppSec depth with detection and SIEM engineering ownership.
  • Comfortable reading production code across multiple languages and stacks well enough to judge whether a finding is actually exploitable.
  • Experience building threat models of codebases, reasoning about attack surface, trust boundaries, and data flow well enough to anticipate where problems will emerge.
  • A track record of finding and fixing systemic weaknesses, whether they surfaced through an incident or through your own proactive review.
  • Strong communication skills, with enough credibility to direct an investigation and influence peers informally.

Strongly preferred:
  • Hands-on experience with AI-assisted security operations tooling, such as AI SOC platforms, LLM-based triage, or agentic escalation systems.
  • Interest or experience in securing AI and LLM-powered systems, including risks like prompt injection, model misuse, or agentic tool abuse.
  • Prior exposure to golden-path or secure-by-default infrastructure initiatives, even in a supporting role.
  • Experience with container or image security and the patching lifecycle.
  • A relevant certification such as GCIH, GCFA, GCDA, OSCP, or CISSP.

The base salary range for this role is $221,000 - $299,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.

Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.

At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.

Benefits That Work For You

Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally. We remain focused on providing a competitive benefits package for our employees. On top of standards such as employer-covered health, dental, and insurance plan options, we offer an inclusive approach to benefits:
  • Maven for Mavens: access to the full platform and specialists, including care for mental health, reproductive health, family planning and pediatrics.
  • Whole-self care through wellness partnerships
  • Hybrid work, in office meals, and work together days
  • 16 weeks 100% paid parental leave and new parent stipend (for Mavens who've been with us for 1 year+)
  • Annual professional development stipend and access to a personal career coach through Maven for Mavens
  • 401K matching for US-based employees, with immediate vesting

These benefits are applicable to Maven Clinic Co., US-based, full-time employees only. 1099/Contract Providers are ineligible for these benefits.

About Maven Clinic

Maven Clinic is a digital health company that provides a platform for women's and family health. The company offers a range of services including virtual appointments with healthcare providers, on-demand access to a network of women's and family health practitioners, and personalized care plans. Maven Clinic aims to improve access to healthcare for women and families, and to provide a more convenient and affordable alternative to traditional healthcare services. The company was founded in 2014 and is headquartered in New York City.
Learn more about Maven Clinic
Size
100 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Maven Clinic

More Information Technology Jobs

Find similar Staff Security Engineer, Detection & Response jobs: