--- title: 'Senior Software Engineer - Encryption & PHI at StackAI' canonical: 'https://feeny.ai/job/senior-software-engineer-encryption-phi-stackai-san-francisco-zckvmt1s3rwh' type: 'job' last_seen: '2026-09-11' --- # Senior Software Engineer - Encryption & PHI at StackAI - **Company:** StackAI - **Location:** San Francisco, CA - **Compensation:** $248k–$282k - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-09-02 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/stack-ai/33a5f6e2-0cc9-4bb8-8202-4214af649f90 ## Job description ## About StackAI StackAI is the enterprise AI transformation platform for organizations with regulated and complex operations. It gives teams one place to build, deploy, govern, and scale AI agents that can analyze data, connect to business systems, and carry out business-critical workflows. Those agents need to work wherever an enterprise’s data and systems live. StackAI supports more than 100 enterprise integrations and can be deployed in our multi-tenant cloud, in a customer’s VPC, or on-premises—allowing organizations to bring AI into sensitive operational work while retaining control over where their agents and data run. StackAI is an Asana company and continues to operate as its own product and brand. ## About the role We are looking for a senior Python engineer who has built security-critical product systems. You will join the Core Engineering team and build the systems that determine how StackAI encrypts customer data, manages keys and signatures, handles PHI and PII, protects customer credentials, and enforces tenant and authentication boundaries. We’re looking for an engineer who brings strong security judgment to the software they build: someone who can move between architecture and implementation, reason carefully about trust boundaries, and turn security requirements into reliable product capabilities. This is hands-on backend engineering in an existing, fast-moving codebase. You will write production Python and take projects from initial investigation and design through implementation, migration, rollout, and operation. The systems you build will shape which sensitive and regulated workloads enterprises can run on StackAI and how confidently they can put them into production. ## What you’ll do - Build encryption and key-management systems. Design and evolve how customer data is encrypted, how keys are scoped and rotated, and how these systems work across hosted, VPC, and on-premises deployments. - Protect sensitive data. Build the controls that detect, transform, and safely handle PHI, PII, and other sensitive data across workflows, connectors, model calls, logs, and storage. - Secure customer credentials. Protect the credentials and tokens customers provide to StackAI, from storage and access control through their use at runtime. - Strengthen product trust boundaries. Improve tenant isolation, signing and verification, session and token handling, and service-to-service authentication. - Create shared security foundations. Build Python services, libraries, and APIs that make security-critical behavior consistent and straightforward for other engineers to use. - Evolve live systems safely. Plan and execute migrations, compatibility periods, staged rollouts, observability, recovery, and rollback. ## What we’re looking for - 4+ years of experience building and operating production backend systems. - Strong professional experience with Python in a substantial production codebase. - Hands-on experience implementing and operating security-critical product systems, including the code that enforces their guarantees. - Depth in at least one of the following: - Encryption and key management - Signing, authentication, sessions, or token infrastructure - Multi-tenant isolation - Sensitive-data processing - Secure storage and runtime use of customer credentials - Practical knowledge of applied cryptography - Experience changing critical systems without disrupting existing customers or making previously stored data inaccessible. - Strong judgment around trust boundaries, failure modes, and the consequences of compromise. - The ability to take an ambiguous technical problem from investigation through production rollout. You do not need to have worked in every area listed above. We are looking for a strong software engineer with meaningful depth in security-critical systems and the ability to take ownership of adjacent problems. Prior healthcare experience is helpful but not required. We care more about your ability to understand sensitive-data requirements and turn them into reliable product behavior. Bonus points - Experience with HashiCorp Vault, cloud KMS products, HSMs, envelope encryption, or key rotation - PHI or PII detection, redaction, pseudonymization, or tokenization - PKI, certificate systems, or cryptographic signing - Multi-tenant SaaS products handling sensitive customer data - Experience in healthcare, payments, identity, financial infrastructure, or another security-sensitive domain - Self-hosted, VPC, on-premises, or air-gapped deployments - AI-agent, LLM, or connector-based application architecture - Startup or growth-stage product experience ## How we work The Core Engineering team owns the systems at the center of StackAI. Engineers take problems end to end: defining the approach, writing the code, planning the migration, and remaining accountable for how the system behaves in production. The work moves quickly, and decisions are made close to the implementation. We value engineers who can make sound trade-offs under ambiguity, ship durable systems, and continue improving them as the product and its requirements evolve. As part of Asana, you will be able to draw on established security and infrastructure teams when a problem crosses application and platform boundaries. This role remains embedded in Core Engineering, with direct ownership of the product systems you build. ## About StackAI ## Company Overview - **One-liner**: StackAI provides a no-code, enterprise-grade platform for building, deploying, and governing AI agents and workflow automations, trusted by regulated industries like finance, healthcare, and defense. - **Entity Type**: Private (acquired by Asana in May 2026; continues to operate as its own product and brand) - **Headquarters**: Cambridge, Massachusetts, United States (also lists San Francisco as a headquarters location) - **Founded**: 2023 - **Founders**: Tony Rosinol (Co-Founder & CEO) and Bernard Aceituno (Co-Founder & President) ## Core Business - **Primary Industry**: Enterprise AI platform / Agentic workflow automation - **Target Customers**: B2B Enterprise – IT, finance, legal, risk/compliance, healthcare, defense, and other regulated organizations - **Mission/Purpose**: To bring safe, scalable, agentic AI into the world’s most regulated enterprises, enabling teams to automate manual work with security and governance. ## Products & Services - **[StackAI Platform](https://www.stackai.com/)**: A no-code, drag-and-drop platform for building enterprise AI agents. Key capabilities include: - Visual agent builder with 100+ integrations (SAP, SharePoint, ServiceNow, Slack, etc.) - LLM-agnostic – deploy the best model for each task - One-click RAG pipelines for context-rich responses - Export agents as chatbots, forms, APIs, and more - Role-based access control, audit logs, PII detection/redaction - Deploy anywhere: multi-tenant, VPC, on-premise - Compliance certifications: SOC 2 Type II, HIPAA, GDPR, ISO 27001 (in progress) ## Market Standing - **Valuation**: Not disclosed (acquired by Asana; acquisition terms not publicly announced) - **Key Metric**: Total funding raised – **$19.5M** (across 3 rounds) - **Notable Investors/Partners**: Asana (acquirer), Y Combinator, Gradient Ventures (Google AI fund), Epakon Capital, Soma Capital, and others - **Growth Signals**: - Acquired by Asana in May 2026, signaling strong product-market fit and strategic value - Employee headcount grew **352.9% YoY** (from ~14 to 64 employees as of mid-2026) - Operates in 11 countries; 32 active job postings as of July 2026 - Customers include YMCA Retirement and LifeMD ## Competitive Advantages - **Enterprise-Grade Security & Compliance**: SOC 2, HIPAA, GDPR, ISO 27001 (in progress) – certified for handling sensitive data in regulated industries. - **No-Code + Deep Integrations**: 100+ pre-built connectors (SAP, ServiceNow, SharePoint, etc.) allow non-technical teams to build agents quickly. - **LLM Agnostic**: Choose the best model per task (Anthropic, OpenAI, Google, etc.), avoiding vendor lock-in. - **White-Glove Support**: Dedicated AI strategists and forward-deployed engineers assist customers from pilot to scale. - **Deployment Flexibility**: Multi-tenant, VPC, or on-premise options satisfy strict data residency requirements. ## Strategic Focus - Post-acquisition by Asana, StackAI will continue operating as its own product while benefiting from Asana’s resources to accelerate feature development and expand use cases. - Near-term priorities include deeper integration with Asana’s work management platform (shared plans, memory, goals) while maintaining all existing integrations and workflows. - Hiring push: “doubling our team size in 2026” (from LinkedIn), with roles across engineering, product, and customer success. ## Why Work Here - **Culture**: Described as “a small dedicated team of insanely talented individuals” that is “user-centric, craft-focused, creative” – ambitious yet pragmatic, moving fast while caring about details. - **Impact**: Build a category-defining product with strong customer momentum in high-stakes industries (finance, healthcare, defense). - **Growth**: High headcount growth (352% YoY) and active hiring across 32 roles as of July 2026. - **Work Environment**: Hybrid/office presence likely (Cambridge and San Francisco offices); remote-friendly given employees in 11 countries. - **Engineering Culture**: Technical team makes up 51% of workforce; founders are MIT PhDs; strong emphasis on AI, security, and enterprise architecture. ## Sources 1. [stackai.com](https://www.stackai.com/) – Official product and platform information 2. [cbinsights.com](https://www.cbinsights.com/company/stack-ai) – Funding, headquarters, investors, customers 3. [linkedin.com](https://www.linkedin.com/company/stackai) – Employee count, growth, locations, culture 4. [stackai.com/blog/stackai-joins-asana-to-build-the-future-of-agentic-work-management](https://www.stackai.com/blog/stackai-joins-asana-to-build-the-future-of-agentic-work-management) – Acquisition announcement and FAQ 5. [stackai.com/blog/stackai-explained](https://www.stackai.com/blog/stackai-explained) – Detailed feature and security overview ## Other roles at StackAI - [Senior DevOps Engineer](https://feeny.ai/job/senior-devops-engineer-stackai-san-francisco-3ca3vyy24k6j) — San Francisco, CA - [Lead QA Engineer](https://feeny.ai/job/lead-qa-engineer-stackai-united-states-d54pkfw2tweg) — United States - [Sales Development Representative (Healthcare)](https://feeny.ai/job/sales-development-representative-healthcare-stackai-new-york-a8rkvqvfe9f9) — New York, NY - [Solution Engineer](https://feeny.ai/job/solution-engineer-stackai-new-york-wez31d6zj86e) — New York, NY - [Product Marketing Manager](https://feeny.ai/job/product-marketing-manager-stackai-new-york-pq87q9g20p52) — New York, NY - [Product Security Engineer](https://feeny.ai/job/product-security-engineer-stackai-warsaw-t96grawx8dr9) — Warsaw, Poland - [Senior Software Engineer, Identity & Access](https://feeny.ai/job/senior-software-engineer-identity-access-stackai-warsaw-cdnv3axsvx36) — Warsaw, Poland - [Senior Software Engineer, Engine & Distributed Systems](https://feeny.ai/job/senior-software-engineer-engine-distributed-systems-stackai-warsaw-2nvech1y24sc) — Warsaw, Poland - [Platform Engineer, APIs & Observability](https://feeny.ai/job/platform-engineer-apis-observability-stackai-warsaw-prpftdzjtmaw) — Warsaw, Poland - [Senior Digital Marketing Manager](https://feeny.ai/job/senior-digital-marketing-manager-stackai-new-york-th9sdv5qt0c1) — New York, NY