What is a Security Engineer at Flatiron Health?
A Security Engineer at Flatiron Health plays a critical role in safeguarding the technology and data that drive cancer research and patient care. Because Flatiron Health works directly with highly sensitive Protected Health Information (PHI) and clinical oncology data, security is not just a technical requirement—it is a foundational pillar of patient trust and regulatory compliance. As a Security Engineer, you are tasked with protecting complex cloud-native platforms, secure APIs, and data pipelines that connect life science companies, researchers, and oncology clinics.
In this role, you will collaborate closely with software engineering, product, and data platform teams to embed security into every phase of the software development lifecycle. The threat landscape you will navigate is highly complex, ranging from safeguarding against sophisticated external threats targeting healthcare infrastructure to securing internal workflows and ensuring rigorous compliance with frameworks like HIPAA and HITRUST. Your engineering contributions will directly enable Flatiron Health to scale its data products safely, ensuring that oncology insights can be generated without compromising patient privacy.
The work is highly cross-functional, requiring a blend of deep technical expertise and strong communication skills. You will build and maintain security tools, conduct threat modeling, perform vulnerability assessments, and write automated security policies in code. This position offers a unique opportunity to apply cutting-edge security practices to a mission-driven domain, where your day-to-day security decisions have a direct, positive impact on the fight against cancer.

