Skip to content

Stedi

Security Engineering Manager

Location
Remote in the USA, US
Arrangement
Remote
Employment type
Full-time
Level
Manager
Posted
16 September 2026 (14 days ago)

Checked 14 days agoApplications go to the employer, never to RoleSprint

About this role

WE'RE BUILDING A NEW HEALTHCARE CLEARINGHOUSE

Stedi is the only headless clearinghouse and RCM engine. Headless means every part of our product is accessible via API. Developers and AI agents build their own interface on top of it. By offering modern, AI-ready APIs alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked by Ramp https://ramp.com/data/top-saas-vendors-on-ramp-march-2026 as one of the fastest-growing SaaS vendors.

Stedi has lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company's infrastructure; a passion for automation and eliminating toil; and $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more.

To see what we ship, watch the 2026 Stedi Keynote https://www.youtube.com/watch?v=MxyCUNAr9Y8. To learn more about how we work, watch our founder Zack's interview with First Round Capital https://www.youtube.com/watch?v=IO6sR-i5rSs.

WHAT WE’RE LOOKING FOR

Stedi is looking for a Security Engineering Manager to lead our scaling security function. This team is at the core of our infrastructure, managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications for healthcare technology companies that process transactions for millions of patients each month.

This is a true player-coach role where you’ll be managing a team of talented security engineers while still being in the weeds. You’ll own our security strategy and do the work: writing CDK, building playbooks, and pushing security projects through yourself. An ideal candidate is excited to have the leverage of setting the team’s direction while still staying deep in the technical details.

You'll be accountable for security across AWS infrastructure, our software development lifecycle, endpoint security, and our compliance posture – and for making it seamless for every engineer at Stedi to build in a way that meets regulatory requirements without slowing down innovation.

HOW WE BUILD

- We use AWS exclusively for our customer-facing backend infrastructure. We use tools like GitHub, Stripe, Vanta, and PagerDuty, but all of our application work happens on AWS.

- We use serverless technologies almost exclusively to build our products: Lambda, API Gateway, SQS, SNS, DynamoDB, Aurora Serverless, and more. We don’t run a single server.

- We use CDK (TypeScript) to define infrastructure as code.

WHAT YOU'LL DO

- Lead and grow a high-performing security team by setting an ambitious pace with rigorous quality expectations, and by hiring as the function scales.

- Oversee our compliance engineering posture, ensuring our processes and evidence meet SOC, HIPAA, and HITRUST requirements.

- Manage daily engineering efforts, monitoring timelines and resources to ensure projects are executed efficiently and to a high standard.

- Increase accountability across the team by setting clear performance expectations and regularly reviewing progress to ensure high standards are consistently met.

- Continuously assess vulnerabilities, perform regular risk assessments, and prioritize remediation based on actual risk to the business and our customers.

- Mentor engineers and make security a shared responsibility and focus across Stedi.

WHO YOU ARE

- 6+ years of experience in security or security adjacent roles, with at least 3+ years in a management role.

- Experience with compliance frameworks such as SOC, HIPAA, and/or HITRUST and control design.

- Hands-on experience in application security and endpoint security.

- Exceptional written communication skills, with the ability to synthesize and clearly convey complex technical and risk information to both engineers and executives.

- Proven experience managing and fostering collaboration in a remote-first environment, ensuring team alignment and cohesion.

- A commitment to cultivating a high-performing team.

- High bandwidth with the ability to pay thoughtful attention to many areas simultaneously.

- Ability to context switch throughout the course of the day or week as priorities shift.

- Philosophical alignment with the Stedi Standards https://www.stedi.com/careers.

We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note:

- All official communication about roles at Stedi will only come from an @stedi.com http://stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com http://frompersona.com.

- If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at careers@stedi.com.

We appreciate your attention to this and your interest in joining Stedi.

At Stedi, we're looking for people who are deeply curious and aligned to our ways of working. You're encouraged to apply even if your experience doesn't perfectly match the job description.

Eligible remote locations

  • US
  • CA

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Ashby under the board identifier Stedi, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 16 September 2026, last checked 14 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free