About this Associate Security Engineer (College Grad 2027) role at Solace
About Solace
Healthcare in the U.S. is fundamentally broken. The system is so complex that 88% of U.S. adults do not have the health literacy necessary to navigate it without help. Solace cuts through the red tape of healthcare by pairing patients with expert advocates and giving them the tools to make better decisions—and get better outcomes.
We're a Series C startup, founded in 2022 and backed by Inspired Capital, Craft Ventures, Torch Capital, Menlo Ventures, Signalfire, and IVP. Our U.S. based team is lean, mission-driven, and growing quickly.
Solace isn't a place to coast. We're here to redefine healthcare—and that demands urgency, precision, and heart. If you're looking to stretch yourself, sharpen your edge, and do the best work of your life alongside a team that cares deeply, you're in the right place. We’re intense, and we like it that way.
Read more in our Bloomberg funding announcement here.
About the Role
Are you a new grad who wants to defend something that matters from day one? As an Associate Security Engineer, you won't be relegated to ticket triage or endless compliance checklists. You'll be doing real security work that protects real patient data within your first weeks. This isn't a hand-holding job. You'll be challenged daily, expected to move fast, learn faster, and take ownership of your work like a seasoned engineer.
You'll join a small, security team that built this program from scratch. We will push you to grow, but you'll also be expected to think independently, ask the right questions, and own your work from start to finish.
You are scrappy, resourceful, and eager to prove yourself. You don't need all the answers; you need the drive to find them. You're not afraid of ambiguity or hard problems; in fact, they excite you. You take feedback like fuel, and you're looking for a place that will invest in making you exceptional, not comfortable.
This is an in person role in our Redwood City office, 3 days a week.
What You'll Do
Do real security work in your first week: no shadowing period, no toy projects.
Rotate across the full breadth of a security program: incident response, cloud security, identity and access management, endpoint security, application security, vendor reviews, and compliance engineering. You'll find out what you're great at by doing all of it.
Take ownership of projects end-to-end. You'll be accountable for what you find and fix, and you'll feel the weight and pride of that responsibility.
Work directly with senior security engineers, platform engineers, and compliance. You'll have mentorship, but you'll also be expected to drive your own work forward.
Investigate incidents, review access, harden systems, and close out risks. Not glamorous, but essential, and you'll learn more from this than any certification could teach you.
Automate the boring stuff. If you do something twice by hand, we expect you to script it the third time.
Participate in incident reviews, vendor security reviews, and risk discussions. Your voice matters here, even on day one.
What You Bring to the Table
A bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field (or equivalent practical experience), graduating between December 2026 and June 2027.
Solid fundamentals in networking, operating systems, and how the web actually works (HTTP, DNS, TLS, authentication).
Scripting ability in at least one language (Python, TypeScript, Bash, etc.). You don't need to be a software engineer, but you need to be able to read code and write automation.
Evidence you can actually do security: CTFs, home labs, security projects, internships, bug bounty submissions, open source contributions. We care about what you've broken and fixed, not just what you studied.
A hunger to learn and an ego small enough to admit when you don't know something.
Grit. You don't give up when things get hard. You Google, you read the docs, you ask questions, you figure it out.
Strong communication skills. You can explain a finding to an engineer, take feedback without defensiveness, and translate risk for people who aren't technical.
Sound judgment and discretion. We're a healthcare company handling protected health information, and you'll be trusted with sensitive access and sensitive situations.
Extreme bias toward action. You'd rather ship something imperfect and iterate than wait for perfect.
What You'll Learn
You'll get hands-on experience across every domain of a modern security program:
Incident response and investigations
Cloud security across AWS and GCP
Identity and access management (Okta, Google Workspace)
Security monitoring and detection
Endpoint and corporate security
Application and product security
HIPAA compliance and security automation
Why Join as a New Grad?
Most companies will pigeonhole you into one narrow function for years. Here you'll touch every part of a security program and figure out where you shine. Most companies will give you canned training scenarios. We'll give you real incidents, real systems, and real patient data to protect. You'll grow faster here in one year than you would in three years at a big company. It will be hard. You will struggle. And you will come out the other side a dramatically better security engineer.
This is not a job for someone looking for a gentle onboarding process. This is for the new grad who wants to prove they can hang with engineers who have years of experience. If that's you, we can't wait to meet you.
Applicants must be based in the United States.
Up for the Challenge?
We look forward to meeting you.
Fraudulent Recruitment Advisory: Solace Health will NEVER request bank details or offer employment without an interview. All legitimate communications come from official solace.health emails only or ashbyhq.com. Report suspicious activity to [email protected] or [email protected].