3 дня назад
Senior Application Security Engineer (Application Security)
172 000 - 200 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer (Application Security): Building and operating application security scanning programs for a healthcare price transparency platform with an accent on SAST, DAST, dependency scanning, threat modeling, and secure software development. Focus on triaging vulnerabilities, guiding code-level remediation, coordinating penetration testing, and measuring security posture across US-based applications and data.
Location: Fully remote in the United States; US-based candidates only. Work follows US business hours. Current US work authorization is required; visa sponsorship is not available.
Salary: $172,000–$200,000 per year, plus equity.
Company
is a Series C healthcare price transparency platform that provides infrastructure for a more open and efficient healthcare marketplace and serves more than 300 enterprise organizations.
What you will do
- Build and operate application security scanning across SAST, DAST, dependency/SCA, container, and infrastructure-as-code tools.
- Triage findings from scans, penetration tests, and bug bounty reports, prioritizing risk and tracking remediation to closure.
- Partner with engineering teams on vulnerability remediation, debugging, architecture reviews, and secure coding.
- Drive threat modeling, secure development practices, and security integration throughout CI/CD pipelines.
- Support application-layer incident response and coordinate third-party penetration tests.
- Track security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage.
Requirements
- 5+ years of experience in application security, security engineering, or security-focused software engineering.
- Hands-on experience with SAST, DAST, and dependency/SCA scanning, including distinguishing real risk from noise.
- Strong knowledge of OWASP Top 10, authentication and authorization flaws, injection, SSRF, code review, and secure architecture.
- Experience securing cloud environments, preferably AWS, and modern CI/CD pipelines.
- Strong communication skills and a collaborative, pragmatic approach to balancing security with delivery speed.
- Current authorization to work in the United States; US-based location and US business-hours availability required.
Nice to have
- Experience in healthcare, fintech, or another regulated industry.
- Experience with HIPAA, SOC 2, or GDPR compliance frameworks.
- OSCP, GWAPT, CSSLP, or another security certification.
- Experience building or maturing an application security program from an early stage.
- Scripting or automation with Python, Go, Terraform, or similar infrastructure-as-code tools, plus red team experience.
Culture & Benefits
- Fully remote work with flexible working hours.
- Equity options and competitive compensation.
- Medical, dental, vision, FSA, DCFSA, and HSA options.
- Unlimited PTO, paid family leave, disability and life insurance, and a 401(k) with 4% matching.
- $750 home-office setup budget, $1,200 annual learning and development stipend, and health and wellness benefits.
- Paid biannual company summits and quarterly coworking meetups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Secure Software Engineer (Application Security)
100 000 - 150 000$
Affirm
4 дня назад
Staff Product Security Engineer (AI)
220 000 - 280 000$
6 дней назад
Application Security Engineer (Fintech)
5 дней назад
Application Security Engineer - Senior (Information Security)
3 дня назад
Senior Product Security Engineer
90 000 - 100 000GBP
5 дней назад
Senior Security Engineer (AWS)
150 000 - 160 000$