--- title: 'Member of Technical Staff, Security at Mandolin' canonical: 'https://feeny.ai/job/member-of-technical-staff-security-mandolin-san-francisco-gsmaey1acp3g' type: 'job' last_seen: '2026-09-09' --- # Member of Technical Staff, Security at Mandolin - **Company:** Mandolin - **Location:** San Francisco, CA - **Compensation:** $160k–$270k - **Employment:** full-time - **Posted:** 2026-05-13 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/mandolin/c892f077-812b-464f-8e70-efa94aaf50e3 ## Job description ## ABOUT MANDOLIN Nearly every disease will become treatable in our lifetimes. Mandolin is laying the clinical and financial infrastructure to get groundbreaking treatments to patients faster, powered by AI agents. Mandolin partners closely with the largest healthcare institutions in the US, covering more than $10B drug spend across the country. We're backed by Greylock, SV Angel, Maverick, SignalFire, and the founders of Vercel, Decagon, and Yahoo. ## THE ROLE Mandolin is seeking a highly motivated and versatile Security Engineer to help secure our applications, cloud infrastructure, and compliance programs. This role is ideal for a security generalist with hands-on experience across Application Security, Platform/Cloud Security, and Governance, Risk & Compliance (GRC). The ideal candidate will partner closely with Engineering, DevOps, IT, and Compliance teams to embed security into software development, infrastructure, and operational processes while supporting the organization’s overall security and compliance posture. The ideal candidate is a hands-on security professional who can operate across multiple security domains, balance technical and compliance priorities, and help build scalable, practical, and business-aligned security programs. ## WHAT YOU’LL DO - Integrate security into the Software Development Lifecycle (SDLC) and CI/CD pipelines - Conduct application security reviews, threat modeling, vulnerability assessments, and support secure code review practices - Identify and remediate vulnerabilities related to the OWASP Top 10, APIs, authentication/authorization, secrets management, and software dependencies - Design and implement security controls across cloud and infrastructure environments including AWS, Azure, or GCP - Secure cloud-native platforms, containers, Kubernetes environments, CI/CD systems, and Infrastructure-as-Code (IaC) deployments - Monitor and improve logging, alerting, vulnerability management, endpoint protection, and incident response capabilities - Collaborate with Platform Engineering and DevOps teams to improve infrastructure hardening and operational security practices - Support security compliance initiatives including SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, and NIST-based programs - Assist with risk assessments, audit readiness, evidence collection, policy development, vendor security reviews, and remediation tracking - Help drive security awareness, promote secure engineering best practices, and contribute to long-term security strategy and maturity initiatives - Research emerging threats, vulnerabilities, and security technologies to continuously improve organizational security posture ## MUST-HAVE EXPERIENCE - 4+ years of experience in Security Engineering, Application Security, Cloud Security, DevSecOps, or related cybersecurity roles - Strong understanding of application security, infrastructure/cloud security, and security compliance concepts - Experience securing modern web applications, APIs, cloud environments, and distributed systems - Hands-on experience with cloud platforms such as AWS, Azure, or GCP - Familiarity with CI/CD pipelines, container security, Kubernetes, and Infrastructure-as-Code security practices - Experience with security tools such as SAST, DAST, SIEM, vulnerability scanners, CSPM, EDR/XDR, and IAM solutions - Scripting or automation experience using Python, Bash, PowerShell, or similar languages. - Strong communication skills with the ability to collaborate across technical and non-technical teams ## NICE-TO-HAVES - Experience in SaaS, fintech, healthcare, or other regulated environments - Familiarity with Zero Trust architectures and modern identity/security frameworks - Experience supporting compliance audits and governance initiatives - Relevant certifications such as CISSP, Security+, CCSP, AWS Security Specialty, GSEC, OSCP, or similar ## Compensation Philosophy Compensation for this position will include a base salary, equity, and a variety of comprehensive benefits. The U.S. base salary range for this role is $160,000 - $270,000. Actual base salaries will be based on candidate-specific factors, including experience, skillset, and location, and local minimum pay requirements as applicable. ## Benefits & Perks As part of our total rewards package, we offer attractive benefits and perks to our employees, including: - Free lunch in the office daily & dinner if you're in the office past 7PM - Comprehensive health, dental, & vision insurance for you and your family - Life insurance - 10 company holidays - Take what you need PTO - 4% 401k matching - $300/month company-sponsored commuter benefits - State of the art gym in the office - And more! Please note the above benefits & perks are for full-time employees ## About Mandolin ## Core Business - **Primary industry**: Healthcare IT / AI-powered administrative automation for specialty pharmaceuticals - **Target customers**: B2B – large US infusion providers, specialty and home infusion pharmacies, and health systems (e.g., Vivo Infusion, FlexCare Infusion, OI Infusion, TwelveStone Health Partners, Amber Specialty Pharmacy) - **Mission/purpose**: To improve patient access to life-saving therapies by eliminating the paperwork and delays that slow down specialty drug administration. ## Products & Services - **Mandolin AI Platform**: A multi-agent AI system that acts like a back-office employee. It reads, interprets, and acts on referral forms, lab reports, and clinical notes; performs benefits investigations by navigating payer portals and making outbound calls; calculates patient out-of-pocket costs factoring in real-time benefits, fee schedules, and co-pay assistance; compares medical policies with patient charts and compiles/submits prior authorizations; tracks claim status and automates appeals. All actions are logged and compliant with healthcare regulations. The platform requires no APIs or integrations – it works directly with EHRs, payer portals, and manufacturer hubs. ## Market Standing - **Valuation**: Not publicly disclosed - **Key Metric (Funding)**: Total raised $40M (Series A, closed June 2025) - **Notable Investors**: Greylock Partners (lead), SignalFire, Maverick Ventures, SV Angel, plus angel investors Jerry Yang (co-founder of Yahoo!) and Guillermo Rauch (CEO of Vercel) - **Growth Signals**: - Launched product in January 2025 and within six months is deployed in over 700 clinic locations serving 250,000+ new patients annually. - Customers include many of the largest US infusion providers, pharmacies, and health systems. - Reported 24x improvement in document processing speed (from 20 minutes per document to 3 minutes, end-to-end turnaround under 2 hours). - One customer eliminated a 4-day prescription backlog and reduced reliance on 2–3 full-time staff for intake. - Another customer automated 1,500+ patients per month while refocusing 13 outsourced roles on complex cases. ## Competitive Advantages - **End-to-end automation**: Unlike point solutions (e.g., just prior auth or just benefits verification), Mandolin covers the entire specialty drug lifecycle from intake through claims and appeals. - **No integration required**: The platform navigates existing systems (EHRs, payer portals, faxes, phone calls) without needing APIs – a major moat in fragmented healthcare IT. - **AI agents that reason**: Built on large language models that can interpret clinical policies, handwritten notes, and payer requirements, acting like a trained back-office specialist rather than a simple rules engine. - **Compliance-first design**: Every action is logged, traceable, and aligned with payer requirements and healthcare regulations, reducing risk for providers. ## Strategic Focus - **Scale and depth**: Continue expanding within existing customer accounts and onboarding new large health systems and pharmacies. - **Product expansion**: Likely to add more workflows (e.g., patient communication, billing) and deepen AI reasoning capabilities. - **Talent acquisition**: Actively hiring (careers page at jobs.ashbyhq.com/mandolin) – the company is building out its engineering, product, and go-to-market teams to support rapid growth. ## Why Work Here - **Mission-driven impact**: Directly helps patients access life-saving therapies faster (cancer, Alzheimer’s, autoimmune diseases) while reducing administrative burden on healthcare providers. - **High-growth environment**: A well-funded Series A startup (2024 founding, $40M raised) with early product-market fit and rapid adoption – employees can shape the company’s trajectory. - **Cutting-edge AI work**: Building multi-agent AI systems that reason, act, and comply with healthcare regulations – a challenging and meaningful engineering problem. - **Culture**: Described by investors as a team that “turns AI into a force that helps more people access the care they need.” Founders have backgrounds in neuroscience research and bioethics (Rohit) and AI/engineering (Will). The company emphasizes hiring top talent to build “the definitive AI teammate for the largest health systems in the world.” - **Location**: San Francisco (hybrid likely, though not explicitly stated; office at 2261 Market Street). - **Notable perks**: Being part of a tight-knit, early-stage team backed by top-tier VCs (Greylock, SignalFire) with strong industry connections. ## Sources 1. [Mandolin.com](https://www.mandolin.com/) – official product and case study information 2. [BusinessWire](https://www.businesswire.com/news/home/20250625104094/en/Mandolin-Raises-%2440M-to-Improve-Access-to-Life-Saving-Therapies-for-Diseases-like-Cancer-and-Alzheimers-Using-AI-Agents) – funding announcement and customer details 3. [CB Insights](https://www.cbinsights.com/company/mandolin-1) – company profile, funding total, headquarters, investors 4. [Greylock Blog](https://greylock.com/portfolio-news/mandolin-ai/) – investor perspective and hiring signal 5. [Mandolin Blog – $40M announcement](https://www.mandolin.com/post/40-million-to-obliterate-specialty-drug-paperwork) – additional context and metrics ## Other roles at Mandolin - [Member of Technical Staff, Infrastructure](https://feeny.ai/job/member-of-technical-staff-infrastructure-mandolin-san-francisco-vm143889x8p2) — San Francisco, CA - [Product Manager](https://feeny.ai/job/product-manager-mandolin-san-francisco-k30wprq21wrh) — San Francisco, CA - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-mandolin-remote-fkkjfc9yez8x) - [Member of Technical Staff, Product](https://feeny.ai/job/member-of-technical-staff-product-mandolin-san-francisco-ntbjm4brf409) — San Francisco, CA - [Member of Technical Staff, Security](https://feeny.ai/job/member-of-technical-staff-security-profound-new-york-93qznafpw5qb) — New York, NY - [Member of Technical Staff, Security](https://feeny.ai/job/member-of-technical-staff-security-anchorage-digital-united-states-cvmvegtf5wdb) — United States