Senior Security Engineer, Data Infrastructure
About the role
We're looking for a Senior Security Engineer to own the data security infrastructure at Grow Therapy, the systems that determine how sensitive data is classified, protected, and safely governed across the company. Our customers trust us with some of the most sensitive data there is, and it's our responsibility to honor that trust by treating it with the highest standards of security. You'll be the hands-on technical owner of the infrastructure that makes that possible and the person who makes protecting that data the easy, default path for the rest of the company.
Reporting into the Head of Security and partnering closely with Data, Engineering, and our Detection & Response team, this is a role that requires both building and strategizing: you'll ship the pipelines and services yourself and define what great data security looks like a year out, then make it real. Security sits within Grow's Internal Foundations pillar — the team building company-wide infrastructure to support safe AI adoption, so you'll be architecting the data-protection foundation that every other team, and every AI tool, builds on top of.
What You'll Be Doing
- Define what data security looks like a year from now — then build it. Own a clear, opinionated vision for Grow's data security infrastructure: where the biggest risks are, what "secure by default" means for sensitive data, and the roadmap to get there.
- Make data classification executable. Build the automated classification and tagging pipelines that scan our production data models, infer sensitivity, and propagate those tags through data lineage — aligning with our Data Classification Policy so that every downstream system can act on classification automatically rather than guess.
- Control how data is used internally. Build field-level dynamic masking, tokenization, and redaction — driven by classification tags — so that sensitive data is exposed only when there's a genuine need, and access is scoped, justified, and logged. Make masked-by-default the path of least resistance for the tools teams build on top of our data.
- Secure the data path into AI tooling. We're an AI forward organization. You'll own the security of the data connectors and pipelines feeding AI tools - including authentication, authorization, observability. Your role will be to ensure Grow can take advantage of new AI technologies safely and appropriately.
- Build fast, safe, and scalable encryption pipelines. Design and ship the encryption infrastructure that protects our most sensitive data end to end — application-layer and field-level encryption, envelope encryption, key management — engineered to be fast and scalable enough that teams reach for it by default rather than around it.
You'll Be a Good Fit If You're
- A hands-on data infrastructure engineer. You're comfortable writing production code, designing data pipelines and services, and doing system design reviews — and you've built security or data infrastructure that real teams depend on.
- Worked deep in the data-security stack. You've built meaningfully across some combination of data classification, masking/tokenization, encryption and key management, and secure data access, and you can connect into a coherent system.
- Able to set direction and then execute on it. You're energized by a blank canvas: you can define what success looks like a year out, prioritize ruthlessly toward it, and inspire partner teams to support you in this goal.
- Someone who thinks in terms of risk reduction, not checkboxes. You instinctively reach for the highest-leverage control on the largest surface, and you'd rather make the secure path the default.
- A clear, compelling communicator. You can explain data-security tradeoffs and risk to non-technical audiences — including executives and clinical stakeholders — with precision, empathy, and confidence.
Pay
Hybrid Commitment: $182,000–$250,000 USD Annually
Fully Remote Commitment: $152,000–$208,000 USD Annually
This role can be hybrid (onsite from our NYC, San Francisco, or Seattle hub location three days per week: Tuesday, Wednesday, Thursday) or fully remote. Both arrangements include travel 2–3 times per year (e.g., company and department offsites). The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate's working location.
Benefits
- Health Benefits: Comprehensive medical, dental, vision, life, and disability coverage.
- Grow for Grow: No cost access to therapy through the Grow platform (available to US employees)
- Financial Wellness: Retirement savings programs and equity opportunities to help you invest in your future.
- Flexible Time Off, Paid Holidays & Winter Break: Flexible time off, company paid holidays (which vary by country), and a full company wide Winter Break to rest and recharge
- Parental Leave: Up to 18 weeks of paid parental leave to support you and your growing family and a new child stipend.
- Mental Health Mornings/Afternoons: Dedicated weekly flexible time for self care, whether that's therapy, exercise, journaling, time with family, or simply taking a break.
- Wellness & Development Stipend: Annual stipend to support your personal wellbeing and professional growth, from fitness and education to books and learning resources.
- Commuter Benefits: Pre tax commuter benefits to support teammates working from one of our hub locations.
- Home Office & Meals: Support for your home workspace plus meal benefits, with offerings tailored to both remote and hub based employees.
- Additional Perks: A variety of wellbeing benefits, including wellness memberships, virtual care, pet insurance discounts (where available), and global travel assistance.