Security Engineer at Echo Neurotechnologies
San Francisco, CA
$175,000–$225,000
Jul 6, 2026
San Francisco, CA
Jul 21, 2026
What this job asks for AI summary
A security engineering role at an early-stage BCI startup, focused on owning end-to-end security across a cloud-based data platform, connected medical devices, and client applications. Day-to-day work spans threat modeling, security architecture, vulnerability tracking, and automation, as well as guiding security through the full product lifecycle in a regulated medical environment. Best suited to someone with broad experience across cloud, device, and network security who can also mentor engineers and manage external security vendors.
Senior level · Remote
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 620 people nationally plausibly meet what this posting asks for (information security analysts). range 130–1,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The job title is 'Security Engineer' with no level modifier; advertised seniority is Unspecified. However, the scope — owning portfolio-wide security architecture, leading cross-functional teams, and operating in a regulated medical-device environment — firmly supports a Senior classification.
Cloud platform requirement names AWS, Azure, and GCP as interchangeable examples of the required cloud security experience; AWS is listed first and the others are captured as alternatives.
Device connectivity (BLE, Wi-Fi, USB) is listed as a single requirement covering local device connections; BLE is used as the primary name with Wi-Fi and USB as alternatives since the JD treats them as a grouped capability.
STRIDE and Attack Trees are listed together as the threat-modeling methodologies required; STRIDE is primary with Attack Trees as an alternative.
Python, Bash, and PowerShell are listed as interchangeable scripting/programming options for security automation.
Azure ecosystem experience appears under Preferred Qualifications and is captured separately as preferred, even though Azure also appears in the required cloud-platform list as an alternative.
Medical device cybersecurity frameworks (FDA Section 524B, ISO 14971, FIPS-3) and QMS experience are listed under Preferred Qualifications; ISO 14971 is used as the representative named standard.
No compensation figures, degree requirement, or employment type are stated in the posting.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.