GRAIL Logo

GRAIL

Staff Product Security Engineer

Posted 2 Hours Ago
Be an Early Applicant
Hybrid
Menlo Park, CA
Senior level
Hybrid
Menlo Park, CA
Senior level
Lead product security architecture and security-by-design across the product lifecycle. Embed security into SSDLC and DevSecOps, perform threat modeling and risk assessments, define controls for AI/ML products, manage post-market surveillance, oversee penetration and advanced testing, support incident response, partner with cross-functional stakeholders for regulatory compliance, track security metrics, and mentor other engineers.
The summary above was generated by AI
  • GRAIL is seeking a mission-driven and high-impact Staff Product Security Engineer to serve as a technical cornerstone for product security initiatives across the company. Reporting to the Director of Product Security, this role plays a critical part in enabling secure, resilient products that support GRAIL’s life‑saving mission.

    As a Staff-level individual contributor, you will lead the technical execution of the Product Security roadmap, partner closely with Engineering and Product teams, and mentor other security engineers. You will influence architecture and development decisions across the product lifecycle, helping teams navigate an evolving threat landscape while maintaining delivery velocity in a regulated environment.

    This role is based in Menlo Park, California, and will move to Sunnyvale, California in Fall 2026. GRAIL offers a flexible work arrangement, with the ability to work from GRAIL's office or from home. Our current flexible work arrangement policy requires that a minimum of 60%, or 24 hours, of your total work week be on-site. Your specific schedule, determined in collaboration with your manager, will align with team and business needs and could exceed the 60% requirement for the site.

 

Responsibilities

    Lead product security architecture and security-by-design practices across the full product lifecycle, from concept through post‑market support.

    Embed security into the Secure Software Development Lifecycle (SSDLC) and DevSecOps pipelines, establishing guardrails that balance risk reduction with engineering velocity.

    Perform and guide threat modeling, security risk assessments, and architecture reviews across products and enterprise‑connected systems.

    Define and enforce security controls for AI- and ML-enabled products, including data protection, model integrity, access controls, and secure pipelines.

    Manage, and operate Product Security post-market surveillance activities across GRAIL products and services, from intake through remediation and closure.

    Influence secure solution architectures for GRAIL ecosystems, considering system integration, access control (IAM), key management (KMS), secure data flows, resilience, patch management, and recovery.

    Scope, oversee, and review penetration testing and advanced security testing activities across software, systems, and infrastructure.

    Serve as a product security subject matter expert during incident response, root cause analysis, and post‑incident improvements.

    Partner with Product, Engineering, Quality, Legal, and other stakeholders to ensure alignment with regulatory and industry cybersecurity requirements.

    Define, track, and report product security metrics and KPIs to provide visibility into security posture and risk trends.

    Mentor and coach engineers, contributing to the growth of product security capabilities and future technical leaders at GRAIL.
     

Required Qualifications

    8+ years of experience in product security, cybersecurity, application security, or related technical security roles.

    Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.

    Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.

    Experience supporting security incident response and conducting root cause analysis in production environments.

    Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
     
    GRAIL Values & Leadership Expectations
    This Staff-level role is expected to model GRAIL’s core values and LEAD leadership attributes by leading through influence, collaborating across boundaries, driving results with integrity, and continuously improving how product security enables patient impact.
    These responsibilities summarize the role’s primary responsibilities and are not an exhaustive list. They may change at the company’s discretion.
     

Preferred Qualifications

    Experience working in regulated environments, including medical devices, healthcare, life sciences, or similarly regulated industries.

    Knowledge of relevant standards and frameworks such as IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre‑ and post‑market cybersecurity guidance.

    Experience securing AI/ML systems, including mitigating risks such as data poisoning, model manipulation, and unauthorized access.

    Demonstrated experience delivering cybersecurity programs, including tabletop exercises and cross‑functional incident simulations.

    Professional security certifications such as OSCP, GPEN, GCIH, GWAPT, or equivalent.

    Strong ability to translate technical security risks into business and patient-impact considerations for senior stakeholders.

    Experience working with globally distributed teams or international stakeholders.
    •  

Physical Demands and Working Environment

    Ability to work in an office and remote environment under a flexible hybrid arrangement.

    Occasional travel may be required based on business needs.
    •  

Similar Jobs at GRAIL

17 Hours Ago
Hybrid
95K-117K Annually
Mid level
95K-117K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Perform month-, quarter-, and year-end close tasks including journal entries, reconciliations, accruals, and variance analysis. Own cash, prepaid, and general accrual accounting for assigned accounts, support SOX and audit requests, improve processes via automation/AI, and partner with cross-functional teams on projects and reporting.
Top Skills: Ai ToolsCoupaExcelGoogle DocsGoogle SheetsNetSuiteScripting
17 Hours Ago
Hybrid
109K-144K Annually
Senior level
109K-144K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Lead month-end, quarter-end, and year-end close activities including journal entries, reconciliations, variance analysis, and accruals (including clinical trial accruals). Support SOX compliance and audits, drive automation and AI-enabled process improvements, maintain controls, and partner cross-functionally to ensure accurate US GAAP financial reporting.
Top Skills: Ai ToolsCoupaExcelGoogle DocsGoogle SheetsNetSuiteScripting
Yesterday
Remote or Hybrid
USA
235K-312K Annually
Mid level
235K-312K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Field-based HEOR liaison responsible for communicating and refining health economic, outcomes, and real-world evidence to payers. Support AMCP dossiers, value frameworks, and payer-focused education; partner with Market Access, Medical Affairs, and Commercial teams; identify data gaps, inform research priorities, and represent evidence at regional and national meetings. Requires travel for external engagements and internal collaboration.
Top Skills: Ngs

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account