San Francisco, CAremote

Salary
$175,000–$225,000
Posted
Jul 6, 2026
Location
San Francisco, CA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A security engineering role at an early-stage BCI startup, focused on owning end-to-end security across a cloud-based data platform, connected medical devices, and client applications. Day-to-day work spans threat modeling, security architecture, vulnerability tracking, and automation, as well as guiding security through the full product lifecycle in a regulated medical environment. Best suited to someone with broad experience across cloud, device, and network security who can also mentor engineers and manage external security vendors.

Senior level · Remote

Must have (8)
AWS, Azure or GCPIAMPKIBLE, Wi Fi or UsbTLSSTRIDE or Attack TreesCVSSPython, Shell Scripting or PowerShell
Nice to have (1)
ISO 14971

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 620 people nationally plausibly meet what this posting asks for (information security analysts). range 130–1,100

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
BLE3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The job title is 'Security Engineer' with no level modifier; advertised seniority is Unspecified. However, the scope — owning portfolio-wide security architecture, leading cross-functional teams, and operating in a regulated medical-device environment — firmly supports a Senior classification.

Cloud platform requirement names AWS, Azure, and GCP as interchangeable examples of the required cloud security experience; AWS is listed first and the others are captured as alternatives.

Device connectivity (BLE, Wi-Fi, USB) is listed as a single requirement covering local device connections; BLE is used as the primary name with Wi-Fi and USB as alternatives since the JD treats them as a grouped capability.

STRIDE and Attack Trees are listed together as the threat-modeling methodologies required; STRIDE is primary with Attack Trees as an alternative.

Python, Bash, and PowerShell are listed as interchangeable scripting/programming options for security automation.

Azure ecosystem experience appears under Preferred Qualifications and is captured separately as preferred, even though Azure also appears in the required cloud-platform list as an alternative.

Medical device cybersecurity frameworks (FDA Section 524B, ISO 14971, FIPS-3) and QMS experience are listed under Preferred Qualifications; ISO 14971 is used as the representative named standard.

No compensation figures, degree requirement, or employment type are stated in the posting.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗