Founding Security Engineer
Forus · New York, NY
—
Jul 13, 2026
New York, NY
Jul 21, 2026
What this job asks for AI summary
The first security engineering hire at a healthcare technology company, this role carries broad ownership across cloud infrastructure (AWS and GCP), application security, identity, detection and incident response, and AI data-flow controls — all in a regulated environment handling protected health information. The work spans hands-on building of security primitives and tooling to implementing the technical controls underpinning SOC 2, HIPAA, and HITRUST compliance. It suits an experienced security engineer with a strong software foundation who can operate independently across multiple domains.
Senior level · 7+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 140 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 60–210
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
What the occupation pays Median $143,559 (middle half $110,181–$179,574).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (6)
The title 'Founding Security Engineer' carries no explicit seniority level word, so the title states no level; however, the 7+ years requirement and first/sole security engineer scope firmly support Senior.
SOC classification is Medium confidence: the role is heavily security-engineering (15-1212) but the JD emphasizes a strong software engineering foundation, shipping libraries and tooling, and code reviews — meaningful overlap with 15-1252 Software Developers.
AWS and GCP are listed together as the cloud platforms owned ('AWS and/or GCP'); they are treated as interchangeable alternatives for the same cloud security requirement rather than two separate stacked requirements.
HIPAA familiarity and PHI experience are explicitly called 'a strong plus' in the preferred qualifications block, so they are marked preferred.
LLM/AI agent security is framed as a desired qualification ('Comfort designing security for LLMs and AI agents') in the ideal-qualifications section, so it is marked preferred.
No compensation figures are stated; the posting references competitive salary and equity but gives no numbers.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.