Senior Application Security Engineer II

New
S
Spring HealthMental health technology
This is a full-time, fully remote position open to candidates residing within the United States.Full-TimeSenior
Salary$180K - $202.5K; $180K – $202.5K • Offers Equity
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of professional experience in application security or a closely related security engineering discipline
Required Skills
AWSGCPAzureGo

Requirements

  • Have 7+ years of professional experience in application security or a closely related security engineering discipline.
  • Have experience independently working on complex, ambiguous problem areas.
  • Have hands-on experience with DAST, SAST, and SCA tools and manual testing techniques, including OWASP and SANS Top 25.
  • Have experience securing CI/CD pipelines with commercial and custom-built tooling.
  • Have experience with IaaS cloud infrastructure such as AWS, Azure, or GCP, container technologies, and service-oriented architectures.
  • Have security automation experience in at least one of Go, Python, JavaScript, or Ruby.
  • Be familiar with AI/ML security concepts, including prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
  • Have working knowledge of AI and LLM tooling such as OpenAI, Anthropic, or LangChain, sufficient to assess security risk and integrate tools into automated workflows.
  • Have experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
  • Have a bachelor’s degree in Computer Science, Engineering, MIS, or IT, or equivalent work experience.
  • Nice to have: 3+ years of security architecture experience designing and reviewing controls across cloud-based, distributed, or service-oriented systems.
  • Nice to have: experience developing a formal threat modeling program, evaluating or implementing AI security tooling, managing a bug bounty or vulnerability disclosure program, or working in digital health or HIPAA-regulated environments.

Responsibilities

  • Advance secure-by-design practices through architecture reviews, design consultations, and security guidance across the development lifecycle.
  • Mentor engineers on secure coding practices, AppSec fundamentals, and career growth.
  • Develop an AI-assisted threat modeling program covering risk identification, security architecture, and program maturity.
  • Mature SAST, SCA, and DAST programs through rule tuning, coverage improvements, and stronger security controls.
  • Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
  • Assess vulnerability impact, propose solutions, and validate fixes through established remediation workflows.
  • Implement process improvements and security automation using Go, Python, JavaScript, or Ruby, including AI tooling integrations.
  • Assess AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, for security risks.
  • Research, design, and develop a Secure AI Development Lifecycle in accordance with OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
  • Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review.
View Full Description & ApplyYou'll be redirected to the employer's site
$180K - $202.5K; $180K – $202.5K • Offers Equity
Apply Now