Remote job
Senior Application Security Engineer
Job details
About this role
Role overview
This fully remote U.S.-based role owns application-layer security for a healthcare price transparency platform, serving as the software counterpart to infrastructure security. The position drives the application security scanning program and partners closely with engineering teams on design, architecture, and remediation across the product.
Responsibilities
- Build and run the application security scanning program across SAST, DAST, dependency/SCA, container, and IaC scanning, tuning tools to reduce noise and surface real risk. - Triage findings from scans, penetration tests, and bug bounty reports, prioritizing by risk and tracking remediation through to closure. - Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance. - Perform threat modeling, maintain secure-coding standards, and support incident response for application-layer security issues. - Coordinate third-party penetration tests and report on security posture metrics such as open vulnerabilities, remediation SLAs, and scan coverage.
Requirements
- 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus. - Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, with the judgment to distinguish real risk from noise. - Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.) and the ability to review code and architecture to spot issues and propose fixes. - Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines. - Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders.
Nice to have
- Experience in healthcare, fintech, or another regulated industry, or working within HIPAA, SOC 2, or GDPR frameworks. - Security certifications such as OSCP, GWAPT, or CSSLP. - Experience building or maturing an AppSec program from an early stage. - Scripting or automation experience with Python, Go, or Terraform. - Red team experience performing internal campaigns and producing remediation reports.
Benefits and work setup
- Competitive pay with equity options. - Medical, dental, and vision plans with FSA, DCFSA, and HSA options; company-sponsored disability and life insurance. - Unlimited PTO, 401(k) with 4% match, and generous paid family leave. - Fully remote work with flexible hours, $750 work-from-home setup budget, $100 monthly health and wellness benefit, $150 quarterly co-working stipend, and $1,200 annual learning and development stipend. - Paid biannual in-person company summits. - U.S.-based candidates only; visa sponsorship is not available for this role.