<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>8cb6707b-8c3</externalid>
      <Title>Senior Product Security Engineer</Title>
      <Description><![CDATA[<p>JOB DESCRIPTION:</p>
<p><strong>About us</strong></p>
<p>At Pomelo Care, we are redefining the healthcare journey for women and children. As the leading virtual medical practice in our field, we provide a continuous circle of support,from the first steps of family building and the complexities of pregnancy to the nuances of postpartum, pediatric, and midlife care.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>As our first Product Security Engineer, you will sit at the intersection of Security and Software Engineering. Reporting directly to the CISO, you will be a &quot;Security Builder&quot;: embedded within our engineering teams with the autonomy needed to build the automation, tools, and workflows that make security a seamless part of the software development lifecycle.</p>
<p>You aren&#39;t just finding bugs; you are building the systems that prevent and fix them at scale. Your work will be centered on three core strategic pillars:</p>
<ul>
<li>Secure architecture and auth: you will design and implement auth enhancements such as magic link improvements and access/audit log features to monitor access and improve transparency.</li>
</ul>
<ul>
<li>Privacy engineering: you will lead the privacy engineering initiatives including DSAR integration, building automated data deletion capabilities directly into the Pomelo mobile app and our internal platform to ensure seamless compliance. You will also help improve privacy-preserving data de-identification and anonymization as needed.</li>
</ul>
<ul>
<li>Full-cycle remediation: you will own the end-to-end pentest-to-fix lifecycle. This means you don&#39;t just triage reports; you write the code to fix penetration test findings, remediate SAST issues, and build greenkeeping systems for high-volume dependency patching with regression testing.</li>
</ul>
<p>Beyond these pillars, you will serve as a high-leverage engineering partner to the broader InfoSec team by:</p>
<ul>
<li>Building secure-by-default libraries: reducing the load on core Software Engineering by creating internal libraries and patterns that make security the default path.</li>
</ul>
<ul>
<li>Threat modeling: partnering with engineering leads to conduct threat modeling and ensure secure design at the earliest stages of the development process.</li>
</ul>
<ul>
<li>Scaling through collaboration: as a security resource embedded in our engineering teams, you will help engineering squads navigate complex security use cases, translating GRC requirements into elegant code rather than manual checklists.</li>
</ul>
<p><strong>Who you are</strong></p>
<p>You’re an enthusiastic and collaborative engineer who enjoys solving meaningful problems through code. You view security as a product challenge, and you believe the best way to secure a system is to make the &quot;secure way&quot; the &quot;easy way.&quot; In particular, you:</p>
<ul>
<li>Are a builder first: Have 5+ years of software engineering experience with a strong foundation in computer science and a track record of shipping production-grade code (Python, Go, Kotlin or similar).</li>
</ul>
<ul>
<li>Have a security mindset: You understand the OWASP Top 10, identity flows and prompt injections, but you’d rather build a system that eliminates a class of vulnerability than manually triage individual alerts. You believe security expertise should be embedded into the development process, not bolted on at the end.</li>
</ul>
<ul>
<li>Are an automation enthusiast: you enjoy tackling complex problems with practical automation and are keeping up with trends in LLM agents to multiply your engineering impact.</li>
</ul>
<ul>
<li>Navigate ambiguity: as a floating resource across various engineering teams, you are comfortable context-switching and can quickly build rapport with different engineering teams to understand their needs.</li>
</ul>
<p><strong>We’ll be super excited if you</strong></p>
<ul>
<li>Have experience with Google Cloud Platform (GCP), Github Advanced Security (GHAS), Stytch, Sentry, Fullstory, Statsig or similar technology stack.</li>
</ul>
<ul>
<li>Have prior experience in healthcare data, including understanding of HIPAA, SOC 2 Type 2 and HITRUST compliance requirements.</li>
</ul>
<ul>
<li>Have experience building data infrastructure that supports AI/ML workloads,internal developer platforms and privacy preserving data de-identification and anonymization techniques.</li>
</ul>
<ul>
<li>Have previously worked in a fast-paced, product-oriented startup environment.</li>
</ul>
<p><strong>Why you should join our team</strong></p>
<p>By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.</p>
<p>We strive to create an environment where employees from all backgrounds are respected. We also offer:</p>
<ul>
<li>Competitive healthcare benefits</li>
</ul>
<ul>
<li>Generous equity compensation</li>
</ul>
<ul>
<li>Unlimited vacation</li>
</ul>
<ul>
<li>Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&amp;A questions, and opportunities for 1-1 mentorship)</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, Go, Kotlin, Google Cloud Platform, Github Advanced Security, Stytch, Sentry, Fullstory, Statsig</Skills>
      <Category>Engineering</Category>
      <Industry>Healthcare</Industry>
      <Employername>Pomelo Care</Employername>
      <Employerlogo>https://logos.yubhub.co/pomelocare.com.png</Employerlogo>
      <Employerdescription>Pomelo Care is a virtual medical practice providing continuous support for women and children&apos;s health, leveraging a technology-driven platform.</Employerdescription>
      <Employerwebsite>https://www.pomelocare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/pomelocare/jobs/5829729004</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>ac007c05-251</externalid>
      <Title>Staff Product Engineer, Product Platform</Title>
      <Description><![CDATA[<p><strong>About The Role</strong></p>
<p>As a Staff Product Engineer on Replit’s Product Platform team, you’ll build the shared product systems and primitives that power Replit’s core experiences — enabling product teams to ship faster and helping users (and agents) build better software.</p>
<p><strong>What you’ll do</strong></p>
<ul>
<li>Lead major cross-team platform initiatives, taking foundational systems from 0 → 1 and scaling them to support millions of users</li>
</ul>
<ul>
<li>Build shared, extensible Agent primitives that Replit Agent can reuse safely and consistently (Meta Programming)</li>
</ul>
<ul>
<li>Identify the highest-leverage technical bottlenecks (performance, reliability, correctness, abuse, observability), then design and ship solutions for our scale</li>
</ul>
<ul>
<li>Raise the bar for engineering excellence through architecture reviews, code quality, reliability standards, and mentorship</li>
</ul>
<ul>
<li>Partner across teams to improve platform adoption, ergonomics, and velocity — turning platform work into measurable outcomes</li>
</ul>
<p><strong>Core areas you’ll work on</strong></p>
<ul>
<li>Agents and Replit users depend on us to build applications (e.g. Connectors framework, Content/configuration primitives (CMS + product surfaces), Data/analytics/events + experimentation primitives)</li>
</ul>
<ul>
<li>Replit Agent as a principal in third party systems. Agent can be fully used within ChatGPT and publishes straight to the iOS app store. We’ll be doing loads of that.</li>
</ul>
<ul>
<li>Platform product teams rely on us to ship consistently (e.g. Identity &amp; Access platform (SSO/SCIM), Localization/i18n platform, Notifications &amp; communications platform)</li>
</ul>
<ul>
<li>Core web platform infrastructure (e.g. performance &amp; page load optimization, observability and debugging workflows, caching strategy and reliability)</li>
</ul>
<p><strong>Required skills and experience</strong></p>
<ul>
<li>7+ years of professional software engineering experience</li>
</ul>
<ul>
<li>Understanding of the full agentic software development stack, helping coding agents build, test and review correct code.</li>
</ul>
<ul>
<li>Strong track record leading complex projects with cross-functional stakeholders</li>
</ul>
<ul>
<li>Experience building and operating platform systems that other teams depend on</li>
</ul>
<ul>
<li>Experience operating and scaling systems in production (reliability, performance, incidents, on-call readiness)</li>
</ul>
<ul>
<li>Strong product judgment: you can balance UX, speed, correctness, and long-term maintainability</li>
</ul>
<ul>
<li>Comfort working in modern web stacks such as TypeScript, React, Node.js, Postgres</li>
</ul>
<p><strong>Bonus points</strong></p>
<ul>
<li>Experience working in environments with a high engineering bar (or a fast-growing startup where you shipped fast _without_ burning out quality)</li>
</ul>
<ul>
<li>Experience with platform and distributed systems patterns (queues, workflows, caching, rate limiting, async processing)</li>
</ul>
<ul>
<li>Familiarity with systems like Redis, Postgres, Workflow engines (e.g. Temporal), Auth and enterprise identity (SSO, SCIM), Abuse protection and edge systems (Cloudflare), Cloud platforms (GCP), Observability (Datadog, Sentry), Localization, Experimentation and event pipelines (Statsig, Segment, analytics/event tracking)</li>
</ul>
<p><strong>Example Projects You’ll Work On</strong></p>
<ul>
<li>Connectors platform for agents — ship a secure connector framework (OAuth/permissions/data access) so agents can integrate with Slack/Notion/GitHub/etc.</li>
</ul>
<ul>
<li>Agent-facing external surfaces — own high-quality embedded experiences (desktop/extension/embeds) that let agents act in-context across tools</li>
</ul>
<ul>
<li>Safety + abuse controls for agent actions — design permissioning, rate limits, and policy enforcement so agents can operate safely at scale</li>
</ul>
<ul>
<li>Real-time notifications platform — design in-app/email surfaces + build reliable delivery/fanout, preferences, and observability</li>
</ul>
<ul>
<li>Core web platform performance + caching — improve latency and reliability via caching strategy (Redis), profiling, and safe fallbacks</li>
</ul>
<ul>
<li>Events + experimentation primitives — standardize tracking/metrics + feature flags/rollouts so teams can ship safely and measure impact</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$225K – $320K</Salaryrange>
      <Skills>TypeScript, React, Node.js, Postgres, Redis, Postgres, Workflow engines, Auth and enterprise identity, Abuse protection and edge systems, Cloud platforms, Observability, Temporal, Cloudflare, GCP, Datadog, Sentry, Statsig, Segment, analytics/event tracking</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Replit</Employername>
      <Employerlogo>https://logos.yubhub.co/replit.com.png</Employerlogo>
      <Employerdescription>Replit is a software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/replit/af1dd557-3ed6-4be6-9756-c465ead52329</Applyto>
      <Location>Foster City, CA</Location>
      <Country></Country>
      <Postedate>2026-03-07</Postedate>
    </job>
  </jobs>
</source>