← Back to jobs

Remote job

Senior Application Security Engineer

Other Full-time Permanent Remote

Job details

$172K – $200K • Offers Equity Salary
Remote Eligibility
Senior Experience
Full-time Employment

About this role

Role overview

This fully remote U.S.-based role owns application-layer security for a healthcare price transparency platform, serving as the software counterpart to infrastructure security. The position drives the application security scanning program and partners closely with engineering teams on design, architecture, and remediation across the product.

Responsibilities

- Build and run the application security scanning program across SAST, DAST, dependency/SCA, container, and IaC scanning, tuning tools to reduce noise and surface real risk. - Triage findings from scans, penetration tests, and bug bounty reports, prioritizing by risk and tracking remediation through to closure. - Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance. - Perform threat modeling, maintain secure-coding standards, and support incident response for application-layer security issues. - Coordinate third-party penetration tests and report on security posture metrics such as open vulnerabilities, remediation SLAs, and scan coverage.

Requirements

- 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus. - Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, with the judgment to distinguish real risk from noise. - Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.) and the ability to review code and architecture to spot issues and propose fixes. - Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines. - Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders.

Nice to have

- Experience in healthcare, fintech, or another regulated industry, or working within HIPAA, SOC 2, or GDPR frameworks. - Security certifications such as OSCP, GWAPT, or CSSLP. - Experience building or maturing an AppSec program from an early stage. - Scripting or automation experience with Python, Go, or Terraform. - Red team experience performing internal campaigns and producing remediation reports.

Benefits and work setup

- Competitive pay with equity options. - Medical, dental, and vision plans with FSA, DCFSA, and HSA options; company-sponsored disability and life insurance. - Unlimited PTO, 401(k) with 4% match, and generous paid family leave. - Fully remote work with flexible hours, $750 work-from-home setup budget, $100 monthly health and wellness benefit, $150 quarterly co-working stipend, and $1,200 annual learning and development stipend. - Paid biannual in-person company summits. - U.S.-based candidates only; visa sponsorship is not available for this role.

Skills detected in the listing

PythonGoStakeholder ManagementGDPRAWSTerraform
Detected Oct 3, 2026
Last verified Oct 6, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight