<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>8cb6707b-8c3</externalid>
      <Title>Senior Product Security Engineer</Title>
      <Description><![CDATA[<p>JOB DESCRIPTION:</p>
<p><strong>About us</strong></p>
<p>At Pomelo Care, we are redefining the healthcare journey for women and children. As the leading virtual medical practice in our field, we provide a continuous circle of support,from the first steps of family building and the complexities of pregnancy to the nuances of postpartum, pediatric, and midlife care.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>As our first Product Security Engineer, you will sit at the intersection of Security and Software Engineering. Reporting directly to the CISO, you will be a &quot;Security Builder&quot;: embedded within our engineering teams with the autonomy needed to build the automation, tools, and workflows that make security a seamless part of the software development lifecycle.</p>
<p>You aren&#39;t just finding bugs; you are building the systems that prevent and fix them at scale. Your work will be centered on three core strategic pillars:</p>
<ul>
<li>Secure architecture and auth: you will design and implement auth enhancements such as magic link improvements and access/audit log features to monitor access and improve transparency.</li>
</ul>
<ul>
<li>Privacy engineering: you will lead the privacy engineering initiatives including DSAR integration, building automated data deletion capabilities directly into the Pomelo mobile app and our internal platform to ensure seamless compliance. You will also help improve privacy-preserving data de-identification and anonymization as needed.</li>
</ul>
<ul>
<li>Full-cycle remediation: you will own the end-to-end pentest-to-fix lifecycle. This means you don&#39;t just triage reports; you write the code to fix penetration test findings, remediate SAST issues, and build greenkeeping systems for high-volume dependency patching with regression testing.</li>
</ul>
<p>Beyond these pillars, you will serve as a high-leverage engineering partner to the broader InfoSec team by:</p>
<ul>
<li>Building secure-by-default libraries: reducing the load on core Software Engineering by creating internal libraries and patterns that make security the default path.</li>
</ul>
<ul>
<li>Threat modeling: partnering with engineering leads to conduct threat modeling and ensure secure design at the earliest stages of the development process.</li>
</ul>
<ul>
<li>Scaling through collaboration: as a security resource embedded in our engineering teams, you will help engineering squads navigate complex security use cases, translating GRC requirements into elegant code rather than manual checklists.</li>
</ul>
<p><strong>Who you are</strong></p>
<p>You’re an enthusiastic and collaborative engineer who enjoys solving meaningful problems through code. You view security as a product challenge, and you believe the best way to secure a system is to make the &quot;secure way&quot; the &quot;easy way.&quot; In particular, you:</p>
<ul>
<li>Are a builder first: Have 5+ years of software engineering experience with a strong foundation in computer science and a track record of shipping production-grade code (Python, Go, Kotlin or similar).</li>
</ul>
<ul>
<li>Have a security mindset: You understand the OWASP Top 10, identity flows and prompt injections, but you’d rather build a system that eliminates a class of vulnerability than manually triage individual alerts. You believe security expertise should be embedded into the development process, not bolted on at the end.</li>
</ul>
<ul>
<li>Are an automation enthusiast: you enjoy tackling complex problems with practical automation and are keeping up with trends in LLM agents to multiply your engineering impact.</li>
</ul>
<ul>
<li>Navigate ambiguity: as a floating resource across various engineering teams, you are comfortable context-switching and can quickly build rapport with different engineering teams to understand their needs.</li>
</ul>
<p><strong>We’ll be super excited if you</strong></p>
<ul>
<li>Have experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.</li>
</ul>
<ul>
<li>Have prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.</li>
</ul>
<ul>
<li>Have experience building data infrastructure that supports AI/ML workloads,internal developer platforms and privacy preserving data de-identification and anonymization techniques.</li>
</ul>
<ul>
<li>Have previously worked in a fast-paced, product-oriented startup environment.</li>
</ul>
<p><strong>Why you should join our team</strong></p>
<p>By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.</p>
<p>We strive to create an environment where employees from all backgrounds are respected. We also offer:</p>
<ul>
<li>Competitive healthcare benefits</li>
</ul>
<ul>
<li>Generous equity compensation</li>
</ul>
<ul>
<li>Unlimited vacation</li>
</ul>
<ul>
<li>Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&amp;A questions, and opportunities for 1-1 mentorship)</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, Go, Kotlin, Google Cloud Platform, Github Advanced Security, Stytch, Sentry, Fullstory, Statsig</Skills>
      <Category>Engineering</Category>
      <Industry>Healthcare</Industry>
      <Employername>Pomelo Care</Employername>
      <Employerlogo>https://logos.yubhub.co/pomelocare.com.png</Employerlogo>
      <Employerdescription>Pomelo Care is a virtual medical practice providing continuous support for women and children&apos;s health, leveraging a technology-driven platform.</Employerdescription>
      <Employerwebsite>https://www.pomelocare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/pomelocare/jobs/5829729004</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>a16e3869-796</externalid>
      <Title>Technical Product Manager</Title>
      <Description><![CDATA[<p>We are looking for a Technical Product Manager to lead product-level outcomes and implement the Revenue Technology Engineering roadmap. This team supports our internal Field Employees through internal tooling, GenAI powered workflows, and support experiences.</p>
<p>As a Technical Product Manager, you will partner with Support, Revenue Operations, program management, and IT to execute the vision, prioritize, and deliver lovable product features that balance innovation with operational excellence.</p>
<p>Key responsibilities include:</p>
<p>User Discovery: Interview internal users to uncover friction points and root causes, translating these insights into detailed functional requirements and clear feature initiatives tied to business outcomes. Cross-Functional Collaboration: Partner with Field, Engineering, and Revenue Operations to scope, plan, and launch &#39;lovable&#39; products. Outcome Driven: Define and build success metrics directly into the product design phase, using data to inform current execution and future strategy. Innovation: Identify and apply improvements to internal workflows and new feature sets, incorporating GenAI where appropriate. Efficiency &amp; Adoption: Drive internal efficiency, high feature adoption, and operational cost reduction.</p>
<p>Requirements include:</p>
<p>Technical Fluency: A strong technical background with the ability to discuss trade-offs with engineers. Functional Precision: Proven track record of refining high-level business requirements to granular, actionable technical specifications. Analytical Outlook: Professional experience using data to drive continuous improvement and track product-level success. Leadership &amp; Ownership: Ability to operate with high autonomy and ownership in a fast-paced environment, leading cross-team projects to completion. Humble Attitude: A commitment to the success of the team and the company above all else.</p>
<p>Bonus points include familiarity with SQL and platforms like Pendo, Amplitude, Fullstory, or Looker, experience with Elastic Cloud, Elastic Stack, or similar cloud-based search and analytics platforms, and experience or willingness to work in a distributed, remote-first organization.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$106,900-$156,900 CAD</Salaryrange>
      <Skills>SQL, Pendo, Amplitude, Fullstory, Looker, Elastic Cloud, Elastic Stack, GenAI, Cloud-based search and analytics platforms</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Elastic, the Search AI Company</Employername>
      <Employerlogo>https://logos.yubhub.co/elastic.co.png</Employerlogo>
      <Employerdescription>Elastic enables everyone to find the answers they need in real time, using all their data, at scale, with the Elastic Search AI Platform used by more than 50% of the Fortune 500.</Employerdescription>
      <Employerwebsite>https://www.elastic.co/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/elastic/jobs/7603577</Applyto>
      <Location>Canada</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
  </jobs>
</source>