Product Security Engineer
About Us
Mosaic Clinical Technologies™ is pioneering a new imaging paradigm—shifting radiology from reactive diagnostics to proactive, decision-driven care. Through our AI-native platform, MosaicOS™, we unite fragmented technologies into a single, intelligent ecosystem designed to help clinical teams work faster, think smarter and deliver better care. Built cloud-native and designed for continuous iteration, MosaicOS™ is engineered to solve the industry’s most pressing challenges. Our platform expands clinical capacity, improves diagnostic quality by combining human expertise with AI, and turns operational complexity into strategic advantage through seamless integration or replacement of legacy imaging systems.
Every AI tool within MosaicOS™ is validated across tens of millions of exams to ensure safe, reliable and meaningful clinical impact. With a ransomware-resistant design and built-in redundancy, our platform is designed to ensure continuity of care and protect both patients and operations. Mosaic Clinical Technologies™ is building technology that evolves with clinicians to advance clinical excellence and improve patient outcomes.
About the Role
Lead application security testing initiatives, including SAST, DAST, SCA, IaC, container security, and penetration testing across cloud-native environments.
- Integrate and optimize security tooling, monitoring, policy enforcement, and ASPM capabilities throughout CI/CD pipelines and development workflows.
- Conduct security reviews, threat modeling, architecture assessments, and risk analyses for applications, APIs, cloud platforms, and deployment environments.
- Partner with engineering, platform, and DevOps teams to embed security controls and secure-by-default practices throughout the Secure SDLC.
- Identify security vulnerabilities and risks across code, infrastructure, cloud environments, and third-party dependencies, providing remediation guidance and support.
- Define and implement security policies, standards, controls, governance frameworks, and measurable security metrics to strengthen product security programs.
- Serve as a product security subject matter expert, collaborating cross-functionally with engineering, product, compliance, legal, sales, and customer-facing teams to support security reviews, customer inquiries, and due diligence activities.
Requirements
- 5+ years of experience in Application Security, Product Security, DevSecOps, Cloud Security, or related cybersecurity roles.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field, or equivalent practical experience preferred.
- One of the following certifications, or equivalent: CISSP, CCSP, CASE is highly preferred.
- Familiarity with industry frameworks and standards such as: OWASP, SAMM, NIST SSDF, ISO 27001, SOC 2, CIS Benchmarks.
- Strong understanding of Secure SDLC principles and secure software engineering practices, microservices, APIs, containers, Kubernetes, and CI/CD pipelines.
- Experience securing cloud-native environments such as AWS, Azure, or GCP.
- Hands-on experience with modern application security tooling including: SAST, DAST, Software Composition Analysis (SCA), Container security scanning, Infrastructure-as-Code (IaC) scanning, CI/CD security integrations.
Benefits
- Competitive benefits package – eligibility starts the month after hire, with tiered options to choose from.
- Compensation reviews and career growth opportunities.
- Flexible remote schedules.
- Generous PTO plans and paid holidays.
- Proudly certified as a Great Place to Work for five consecutive years.
Pay
The salary range for this position is $97,700 - $146,500. Final determinations may vary based on several factors including but not limited to education, work experience, certifications, and geographic location. This role is also eligible for an annual discretionary bonus. In addition to this range, Radiology Partners offers competitive total rewards packages, which include health & wellness coverage options, 401k benefits, and a broad range of other benefits such as family planning and telehealth (all benefits are subject to eligibility requirements).