Staff Software Engineer - Consumer Applications (Ancestry)

23andMe Research Institute

$130K — $180K *
Consumer Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • BS in Computer Science/Engineering or equivalent, with over 10 years of industry experience.
  • Proven track record in leading large-scale consumer-facing technical projects from start to finish.
  • Extensive experience in building and optimizing APIs for web and mobile applications.
  • Expert knowledge of Python and full-stack ecosystems, including both frontend and backend frameworks.
  • Hands-on experience with AWS and modern CI/CD deployment processes.
  • Familiarity with SIEM, EDR, and various security and threat detection tools.
  • Strong understanding of security concepts and practices, including incident response and vulnerability management.

Responsibilities

  • Lead the design of scalable web applications and APIs for genetic data analysis.
  • Collaborate with cross-functional teams to define a long-term technical roadmap.
  • Account for business impacts when measuring project success and exploring new technologies.
  • Drive initiatives with a focus on quick iterations and actionable outcomes.
  • Ensure architectural decisions support optimal web and mobile experiences.
  • Shape testing strategies and optimize observability practices within the organization.
  • Stay updated on AI tools and methods to enhance engineering productivity.

Benefits

  • Opportunity to influence a wide range of security initiatives across multiple domains.
  • Work in a collaborative environment where cross-team interactions are encouraged.
  • Professional growth through mentorship and active sharing of knowledge.
  • Exposure to cutting-edge technology in cloud security and incident response tools.
  • Potential for bonus opportunities through on-call rotations and special projects.
Full Job Description
What You'll Do
  • Architect for Scale (Complexity is a Tax): Lead the design of advanced, distributed web applications and APIs that can handle massive genetic datasets while delivering sub-second, interactive consumer experiences. Treat complexity as a permanent tax on future impact-advocate for simple solutions and prioritize Total Cost of Ownership (TCO). Serve as a multi-team architectural expert, ensuring consistency across bounded contexts.
  • Drive Cross-Domain Strategy (One Team, No Silos): Partner closely with Engineering Management, Product Management, Scientific leaders, and backend/ML engineering groups to define the long-term technical roadmap. Step outside traditional engineering lanes to solve the right problems wherever they are found.
  • Deliver Business Impact (Outcome-Oriented): Demonstrate deep accountability over project outcomes. Measure success by business impact, not lines of code. Identify new technologies or methodologies that can step-change our product capabilities, always maintaining a disciplined focus on the "why" before executing on the "how."
  • Iterate to Innovate (Iteration over Perfection): Drive initiatives with a bias for action and delivery speed. Value momentum and treat every release as a hypothesis. Make high-quality technical decisions quickly, even with incomplete information, understanding that delaying for certainty is a cost.
  • Champion Omnichannel Experiences: Ensure architectural decisions and API designs seamlessly support both web and mobile clients. Account for the unique constraints of mobile releases (e.g., ensuring strict backward compatibility) and champion server-driven content and logic to keep client apps nimble.
  • Mentorship & Growth Mindset (Trust Through Transparency): Elevate the engineering culture by setting high standards for code quality and system design. Foster a culture of trust by sharing context openly and challenging directly. Actively mentor developers using coaching techniques, and lead by example in openly sharing and learning from mistakes.
  • Operational Excellence: Shape the organization's testing and observability strategies, fostering a culture that leverages operational data to anticipate issues.
  • Adapt & Evolve Workflows (AI Fluency): As the industry rapidly evolves, stay ahead of the curve by exploring, evaluating, and seamlessly integrating emerging AI/LLM-based tools and workflows into individual and team processes to enhance engineering productivity and quality.


What You'll Bring
  • Experience: BS in Computer Science/Engineering (or equivalent) with 10+ years of industry experience, including a proven track record of leading large-scale, consumer-facing technical projects from conception to widespread adoption.
  • Omnichannel API Expertise: Extensive experience building, scaling, and optimizing backend systems and APIs that power both web and mobile applications. Deep understanding of mobile release realities (backward compatibility, avoiding hardcoded client logic) and mobile-first UI/UX principles.
  • Technical Mastery: Expert-level knowledge of Python (Django or similar web frameworks like Flask) and modern full-stack ecosystems, including JavaScript/TypeScript (React). Deep understanding of web security, cryptography concepts, and performance optimization.
  • Architectural Pragmatism: Deep experience designing cross-team systems with a focus on maintainability, advanced scaling techniques, and clearly communicating technical trade-offs to non-technical stakeholders.
  • Infrastructure: Hands-on experience with AWS (serverless, managed services) and modern CI/CD deployment pipelines.
  • Bonus Qualifications: Familiarity with native mobile development (iOS/Android), compute pipelines, distributed data stores, and data-engineering tools (e.g., Celery, Spark, Metaflow) is a strong plus.


Tools We Use
  • AWS
  • Python (Django, FastAPI)
  • JavaScript/TypeScript (React)
  • Docker and high-throughput messaging systems


23andMe is looking for an experienced Detection Engineer to join our Security Operations Team. You will bring critical thinking skills, hands-on experience with Enterprise Security design and the ability to work with and influence cross-functional teams (Engineering, IT, NetOps and Architecture).

You'll be leveraging your experience and expertise with enterprise security tools and industry best practices to secure our customer data and corporate assets.

What You'll Do

  • Work within the Security Operations Team to identify threats within the environment through traditional threat hunting techniques
  • Work collaboratively to speed up response time and to determine the state of the potential threat / alert
  • Assist the security organization to identify automation opportunities and work to implement those integrations and automation improvements within the security tooling
  • Participate in an on-call rotation with additional bonus opportunities
  • Leverage multiple security techniques and tools daily, including but not limited to use of tools for: intrusion detection, endpoint detection and response, and SIEM
  • Actively threat hunt within security tools and determine steps to triage and filter the true events from background noise
  • Create and use threat hunting playbooks
  • Create and use security operations runbooks to respond to alerts
  • Design and implement new security playbooks and automation
  • Define, design, and build threat detection methodologies; help to improve the security posture of the company
  • Lead by example and share your creativity, wit and experience across the team, working on a variety of tasks ranging from threat detection within multiple enterprise security tools, assessing threats and providing targeted responses and monitoring the corporate environment for potential risks;
  • Integrate, configure, and maintain SIEM tools;
  • Train and mentor security engineers and analysts to utilize SIEM technology;
  • Manage and improve our incident response workflow, implement mitigation plans in cooperation with Engineering, SecOps, AppSec, and IT teams;
  • Help teams to leverage the existing and emerging logging and monitoring solutions, extract security events from the logs with filter/correlation tools, evaluate misconfiguration and intrusion detection signals, automate as much as possible;
  • Improve our vulnerability management program: setup and integrate security scans, triage and mitigate vulnerabilities, communicate required actions to relevant teams;
  • Implement, monitor and support Product, corporate IT and infrastructure security solutions, including:
  • Configure, manage and optimize logging, monitoring, correlation and alerting tools, and the orchestration through a security information and event management (SIEM) solution
  • Data Loss Prevention (DLP) solution focusing on PII and Intellectual Property related data.
  • Detect and respond: Deploy Threat Intelligence products and develop threat reports
  • Assist with the design, development, delivery, documentation, training, and reporting on security control mechanisms (e.g. WAF, endpoint-protection/AV/EDR, etc.);
  • Evaluate security technologies; work closely with vendors to ensure timely delivery of products, services, and feature requests;
  • Risk and evidence-based approach: Identify, assess, and prioritize security risks to Product, Infrastructure, Enterprise data and systems, including external threats, internal threats, and exposure to third-party vulnerabilities;
  • Other duties as assigned.


What You'll Bring

  • Passion for security!
  • Familiarity with how attacks are conducted against network infrastructure, web applications and employees;
  • Hands-on experience with SIEM, EDR, osquery/FleetDM, and other security tools, with the ability to triage alerts effectively to identify potential threats;
  • Some knowledge and capability with one or more scripting and programming languages (e.g., bash, Go, Python, etc.);
  • Experience implementing threat detection through security-as-code (e.g., Terraform);
  • Experience in evaluating the qualitative and quantitative effectiveness of security alerts;
  • Familiarity with building product base alerting;
  • Working knowledge of operating systems (e.g., MacOS, Windows, Linux);
  • Hands-on experience with information security tools in Google Workspace, Cloudflare, Okta, and AWS;
  • Strong understanding of security concepts such as incident response, cloud security monitoring, network security monitoring, host based analysis, MITRE ATT&CK, Cyber Kill Chain, CIA triad, and Zero Trust;
  • Sound familiarity with AWS security concepts;
  • Ability to communicate well and work with others;
  • Ability to think critically about challenging problems to determine the most effective method to solve and address;
  • A minimum of 3 years of experience with managing large scale enterprise security infrastructure including security solution design and hands-on engineering;
  • B.S./M.S. in computer science, engineering, information systems, IT, Information Security, or a related technical field.

Similar Jobs

More Consumer Technology Jobs

Find similar Staff Software Engineer - Consumer Applications (Ancestry) jobs: