{"schemaVersion":"jobsearcher.job.v1","id":"61c5e40940ea9686a0625016","url":"https://jobsearcher.com/jobs/61c5e40940ea9686a0625016","canonicalUrl":"https://jobsearcher.com/jobs/61c5e40940ea9686a0625016","title":"Senior Software Engineer - Encryption & PHI","description":"About StackAI\n\nStackAI is the enterprise AI transformation platform for organizations with regulated and complex operations. It gives teams one place to build, deploy, govern, and scale AI agents that can analyze data, connect to business systems, and carry out business-critical workflows.\n\nThose agents need to work wherever an enterprise’s data and systems live. StackAI supports more than 100 enterprise integrations and can be deployed in our multi-tenant cloud, in a customer’s VPC, or on-premises—allowing organizations to bring AI into sensitive operational work while retaining control over where their agents and data run.\n\nStackAI is an Asana company and continues to operate as its own product and brand.\n\nAbout the role\n\nWe are looking for a senior Python engineer who has built security-critical product systems.\n\nYou will join the Core Engineering team and build the systems that determine how StackAI encrypts customer data, manages keys and signatures, handles PHI and PII, protects customer credentials, and enforces tenant and authentication boundaries.\n\nWe’re looking for an engineer who brings strong security judgment to the software they build: someone who can move between architecture and implementation, reason carefully about trust boundaries, and turn security requirements into reliable product capabilities.\n\nThis is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python and take projects from initial investigation and design through implementation, migration, rollout, and operation.\n\nThe systems you build will shape which sensitive and regulated workloads enterprises can run on StackAI and how confidently they can put them into production.\n\nWhat you’ll do\n\nBuild encryption and key-management systems. Design and evolve how customer data is encrypted, how keys are scoped and rotated, and how these systems work across hosted, VPC, and on-premises deployments.\n\nProtect sensitive data. Build the controls that detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage.\n\nSecure customer credentials. Protect the credentials and tokens customers provide to StackAI, from storage and access control through their use at runtime.\n\nStrengthen product trust boundaries. Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication.\n\nCreate shared security foundations. Build Python services, libraries, and APIs that make security-critical behavior consistent and straightforward for other engineers to use.\n\nEvolve live systems safely. Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback.\n\nWhat we’re looking for\n\n4+ years of experience building and operating production backend systems.\n\nStrong professional experience with Python in a substantial production codebase.\n\nHands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees.\n\nDepth in at least one of the following:\n\nEncryption and key management\n\nSigning, authentication, sessions, or token infrastructure\n\nMulti-tenant isolation\n\nSensitive-data processing\n\nSecure storage and runtime use of customer credentials\n\nPractical knowledge of applied cryptography\n\nExperience changing critical systems without disrupting existing customers or making previously stored data inaccessible.\n\nStrong judgment around trust boundaries, failure modes, and the consequences of compromise.\n\nThe ability to take an ambiguous technical problem from investigation through production rollout.\n\nYou do not need to have worked in every area listed above. We are looking for a strong software engineer with meaningful depth in security-critical systems and the ability to take ownership of adjacent problems.\n\nPrior healthcare experience is helpful but not required. We care more about your ability to understand sensitive-data requirements and turn them into reliable product behavior.\n\nBonus points\n\nExperience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation\n\nPHI or PII detection, redaction, pseudonymization, or tokenization\n\nPKI, certificate systems, or cryptographic signing\n\nMulti-tenant SaaS products handling sensitive customer data\n\nExperience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain\n\nSelf-hosted, VPC, on-premises, or air-gapped deployments\n\nAI-agent, LLM, or connector-based application architecture\n\nStartup or growth-stage product experience\n\nHow we work\n\nThe Core Engineering team owns the systems at the center of StackAI. Engineers take problems end to end: defining the approach, writing the code, planning the migration, and remaining accountable for how the system behaves in production.\n\nThe work moves quickly, and decisions are made close to the implementation. We value engineers who can make sound trade-offs under ambiguity, ship durable systems, and continue improving them as the product and its requirements evolve.\n\nAs part of Asana, you will be able to draw on established security and infrastructure teams when a problem crosses application and platform boundaries. This role remains embedded in Core Engineering, with direct ownership of the product systems you build.\n\nCompensation Range: $248K - $282K","company":"Stackai","rawCompany":"stackai","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-03T10:23:03.382Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Software Engineer - Encryption & PHI","description":"About StackAI\n\nStackAI is the enterprise AI transformation platform for organizations with regulated and complex operations. It gives teams one place to build, deploy, govern, and scale AI agents that can analyze data, connect to business systems, and carry out business-critical workflows.\n\nThose agents need to work wherever an enterprise’s data and systems live. StackAI supports more than 100 enterprise integrations and can be deployed in our multi-tenant cloud, in a customer’s VPC, or on-premises—allowing organizations to bring AI into sensitive operational work while retaining control over where their agents and data run.\n\nStackAI is an Asana company and continues to operate as its own product and brand.\n\nAbout the role\n\nWe are looking for a senior Python engineer who has built security-critical product systems.\n\nYou will join the Core Engineering team and build the systems that determine how StackAI encrypts customer data, manages keys and signatures, handles PHI and PII, protects customer credentials, and enforces tenant and authentication boundaries.\n\nWe’re looking for an engineer who brings strong security judgment to the software they build: someone who can move between architecture and implementation, reason carefully about trust boundaries, and turn security requirements into reliable product capabilities.\n\nThis is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python and take projects from initial investigation and design through implementation, migration, rollout, and operation.\n\nThe systems you build will shape which sensitive and regulated workloads enterprises can run on StackAI and how confidently they can put them into production.\n\nWhat you’ll do\n\nBuild encryption and key-management systems. Design and evolve how customer data is encrypted, how keys are scoped and rotated, and how these systems work across hosted, VPC, and on-premises deployments.\n\nProtect sensitive data. Build the controls that detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage.\n\nSecure customer credentials. Protect the credentials and tokens customers provide to StackAI, from storage and access control through their use at runtime.\n\nStrengthen product trust boundaries. Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication.\n\nCreate shared security foundations. Build Python services, libraries, and APIs that make security-critical behavior consistent and straightforward for other engineers to use.\n\nEvolve live systems safely. Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback.\n\nWhat we’re looking for\n\n4+ years of experience building and operating production backend systems.\n\nStrong professional experience with Python in a substantial production codebase.\n\nHands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees.\n\nDepth in at least one of the following:\n\nEncryption and key management\n\nSigning, authentication, sessions, or token infrastructure\n\nMulti-tenant isolation\n\nSensitive-data processing\n\nSecure storage and runtime use of customer credentials\n\nPractical knowledge of applied cryptography\n\nExperience changing critical systems without disrupting existing customers or making previously stored data inaccessible.\n\nStrong judgment around trust boundaries, failure modes, and the consequences of compromise.\n\nThe ability to take an ambiguous technical problem from investigation through production rollout.\n\nYou do not need to have worked in every area listed above. We are looking for a strong software engineer with meaningful depth in security-critical systems and the ability to take ownership of adjacent problems.\n\nPrior healthcare experience is helpful but not required. We care more about your ability to understand sensitive-data requirements and turn them into reliable product behavior.\n\nBonus points\n\nExperience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation\n\nPHI or PII detection, redaction, pseudonymization, or tokenization\n\nPKI, certificate systems, or cryptographic signing\n\nMulti-tenant SaaS products handling sensitive customer data\n\nExperience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain\n\nSelf-hosted, VPC, on-premises, or air-gapped deployments\n\nAI-agent, LLM, or connector-based application architecture\n\nStartup or growth-stage product experience\n\nHow we work\n\nThe Core Engineering team owns the systems at the center of StackAI. Engineers take problems end to end: defining the approach, writing the code, planning the migration, and remaining accountable for how the system behaves in production.\n\nThe work moves quickly, and decisions are made close to the implementation. We value engineers who can make sound trade-offs under ambiguity, ship durable systems, and continue improving them as the product and its requirements evolve.\n\nAs part of Asana, you will be able to draw on established security and infrastructure teams when a problem crosses application and platform boundaries. This role remains embedded in Core Engineering, with direct ownership of the product systems you build.\n\nCompensation Range: $248K - $282K","datePosted":"2026-09-03T10:23:03.382Z","dateModified":"2026-09-03T10:23:03.382Z","hiringOrganization":{"@type":"Organization","name":"Stackai","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"61c5e40940ea9686a0625016"},"url":"https://jobsearcher.com/jobs/61c5e40940ea9686a0625016"}}