← Back to results

Staff Security Engineer, Detection & Response

Own the Incident Detection and Response program, leading investigations and enhancing security measures in a hybrid work environment.

Location
New York, NY, United States
Compensation
$221k–$299k/yr
Level
staff
Type
full time · Hybrid

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Maven Clinic → Save job Scanned from mavenclinic.com

What you'll build

  • Lead investigations hands-on
  • Hunt for bugs in codebase
  • Propose and implement fixes
  • Own and tune detection logic
  • Help manage AI security risks

Must have

  • 6+ years of security experience
  • Comfortable reading production code
  • Experience building threat models
  • Track record of finding and fixing weaknesses
  • Strong communication skills

Nice to have

  • Hands-on experience with AI-assisted security operations tooling
  • Interest in securing AI and LLM-powered systems
  • Prior exposure to golden-path initiatives
  • Experience with container security
  • Relevant certification such as GCIH or CISSP

Practical constraints

  • Onsite three days a week for NYC office
  • Monthly Work Together Days for remote employees in specific cities

AI in the day-to-day

Help us understand and manage the security risks that come with our growing use of LLMs and AI tooling.

Requirements

Experience
6+ years

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Education Budget Equity/Stock Options Remote Work Health Insurance Parental Leave

Joblaze summary

In this role, the Staff Security Engineer for Detection & Response at Maven Clinic is responsible for leading the Incident Detection and Response program, focusing on threat modeling and investigating security incidents. The position requires a strong background in security, particularly in software and application security, along with experience in detection engineering and SIEM tools. This role is suited for a senior professional with a proven track record in identifying and mitigating systemic vulnerabilities, particularly in environments utilizing AI technologies.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 27, 2026. Last confirmed on Maven Clinic's careers page September 27, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 77% of 65 comparable staff security roles in United States we track (median $200,000 across 29 companies).
  • AI/ML appears in 8.5% of 82 comparable staff security roles in United States; SIEM appears in 4.9% of 82 comparable staff security roles in United States.

Quick facts

Is the Staff Security Engineer, Detection & Response role remote?
It's hybrid — Maven Clinic expects some on-site time in New York, NY, United States.
What's the salary range?
Maven Clinic lists $221,000–$299,000 for this role.
How much experience is required?
At least 6 years of relevant experience for this Staff Security Engineer, Detection & Response role.
Where is the role based?
Maven Clinic is hiring for this position in New York, NY, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI tooling, AI/ML, AppSec, LLM, SIEM.
What seniority level is this role?
Maven Clinic targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Security Engineer, Detection & Response role at Maven Clinic.

From the original posting

Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife — improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com

About the Role

You'll own our Incident Detection and Response program, including threat modeling our systems and codebase and directing the investigation when something does happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide technical direction and judgment calls. You'll spend most of your time finding bugs in our code and gaps in our SDLC before they become incidents, then building and implementing or project managing the fixes yourself. AI is a growing part of that surface, and as our reliance on LLMs, AI-generated code, and agents expands, you'll be responsible for understanding and managing the risk that comes with it.

What You'll Own

Investigation & Technical Direction

  • Lead investigations hands-on. When an incident or suspicious finding comes up, you pull the logs, build the narrative of what happened, and advise business and engineering leaders on next steps.
  • Read production code when needed to understand what's actually happening.

Proactive Hunting & SDLC Hardening

  • When you're not investigating, hunt for bugs in our codebase and weaknesses in our SDLC where problems can slip past existing controls.
  • Propose and implement fixes yourself, or manage the resolution with the right teams, whether that's a specific code fix, a broader process or control change.
  • Partner with our Product Security Engineer on golden paths when a weakness points to a systemic gap.

Detection Engineering

  • Own and tune the detection logic running through 7AI, validating its investigations and escalations and setting the criteria for what triggers an alert.
  • Close gaps in logging and visibility so the tooling has the right data to work with.

Managing AI Risk

  • Help us understand and manage the security risks that come with our growing use of LLMs and AI tooling, both in what we build and what we adopt internally.

What We're Looking For

Required:

  • 6+ years of security experience combining hands-on software or AppSec depth with detection and SIEM engineering ownership.
  • Comfortable reading production code across multiple languages and stacks well enough to judge whether a finding is actually exploitable.
  • Experience building threat models of codebases, reasoning about attack surface, trust boundaries, and data flow well enough to anticipate where problems will emerge.
  • A track record of finding and fixing systemic weaknesses, whether they surfaced through an incident or through your own proactive review.
  • Strong communication skills, with enough credibility to direct an investigation and influence peers informally.

Strongly preferred:

  • Hands-on experience with AI-assisted security operations tooling, such as AI SOC platforms, LLM-based triage, or agentic escalation systems.
  • Interest or experience in securing AI and LLM-powered systems, including risks like prompt injection, model misuse, or agentic tool abuse.
  • Prior exposure to golden-path or secure-by-default infrastructure initiatives, even in a supporting role.
  • Experience with container or image security and the patching lifecycle.
  • A relevant certification such as GCIH, GCFA, GCDA, OSCP, or CISSP.

The base salary range for this role is $221,000 - $299,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.

Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.

At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.

Standard company text repeated across Maven Clinic's postings is omitted here.

Similar positions

Maven Clinic
Staff Software Engineer - Product Security
Maven Clinic · New York, NY; Remote, US (Hub cities)
Maven Clinic
Staff Software Engineer, Identity Platform
Maven Clinic · New York, NY; Remote, US (Hub cities)
Maven Clinic
Staff Software Engineer, Backend Engineering
Maven Clinic · New York, NY; Remote, US (Hub cities)
Maven Clinic
Staff Software Engineer, Infrastructure
Maven Clinic · New York, New York, United States; San Francisco, CA; Remote, US; Seattle, Washington, United States
Maven Clinic
Senior Software Engineer, Backend Engineering
Maven Clinic · New York, NY; Remote, US (Hub cities)