Application Security Architect
Woebot HealthAbout the role
Full Time, Remote
Woebot Health has physical offices in San Francisco, Boston and Dublin, Ireland. If you’re not currently based in one of our beautiful flagship cities, please inquire whether your position can be fully remote
Our vision is to make mental health radically accessible.
We are a team of innovators, experts and business builders who have come together to develop advanced technologies that can transform healthcare.
We’re focused on addressing the vast, unmet need for improved engagement and outcomes in mental health with Woebot, a digital coach that helps people engage more deeply and continuously in their mental health. Woebot's breakthrough is its ability to form a human-level bond with people using the latest in NLP, ML and other advanced technologies. Leveraging this therapeutic bond, and the expertise of our Stanford-trained clinicians and scientists, Woebot is constantly learning from the experience of more than one million people and hundreds of millions of messages exchanged to deliver high quality CBT-based tools that are psychologically related and responsive to a person’s dynamic state of health.
Our work to advance human-centered technology has attracted a lot of attention. Today we’ve amassed more mentions in the scientific literature than any other digital therapeutic company, and are regularly featured as the architects of a radically new approach to mental health. But we’ve only just begun. With the backing of some of the world’s most forward thinking investors and advisors, we’re poised to redefine how people access mental health care.
Are you ready to create a new future for mental health, for everyone? Let's do it together!
How You’ll Thrive
Within 1 month you will:
- Learn the Woebot Health’s policies and procedures, as well as the architecture and cloud infrastructure for our product(s)
- Conduct an initial security review of the products and document any security improvement opportunities. Then create an actionable plan to address the opportunities you discover.
- Meet with and build relationships with key personnel, such as engineers, product, quality, privacy, data scientists, and clinical teams to understand product, business, and security needs.
- Start taking security design and planning responsibilities to ensure the business is supported in planning for security efforts, including security sprint planning management.
- On an ongoing basis, be responsible for performing cybersecurity risk assessments (CSRAs) and security reviews during Change Requests for our product(s), engaging with colleagues across the company.
Within 3 months you will:
- On an ongoing basis, collaborate with key teams to design secure solutions and security features.
- Align product security with medical device, health, and regional regulatory requirements and best practice, as applicable.
- Incorporate security requirements into the Quality Management System requirements, including but not limited to:
- 1) Developing Security Requirements 2) Improving and managing Product Vulnerability Management and Disclosure plan.
- Create short and long term roadmaps to address identified security opportunities. Then develop product security standards and procedures with the appropriate teams, translating security requirements into operational success.
- Create and manage a product security risk exceptions process.
Within 6 months you will:
- Continue progress and management on the above mentioned milestones.
- Fully embed yourself in the Total Product and Software Development Lifecycles at each stage from product/feature concept through release to retirement.
- Act on and implement the roadmaps to improve and document product security.
- Implement Secure by Design and Default.
- Work with commercial, engineering, privacy, and security to support security questionnaires from multiple large customers or health organizations.
- Assist leadership in audits pertaining to security and working with product teams to ensure compliance to industry security frameworks and regulatory requirements.
- On an ongoing basis, perform security assessments for all products including but not limited to threat modeling, risk assessments, and penetration testing
Within Year 1 you will:
- Be an advocate for protecting user, customer, and Woebot Health business data.
- Stay up to date on threat landscapes, industry best practice, and regulatory requirements, implementing them into Woebot products that must adhere to the highest security standards.
Key Responsibi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s