Senior Application Security Engineer II
New
S
Spring HealthMental health technology
This is a full-time, fully remote position open to candidates residing within the United States.Full-TimeSenior
Salary$180K - $202.5K; $180K – $202.5K • Offers Equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of professional experience in application security or a closely related security engineering discipline
- Required Skills
- AWSGCPAzureGo
Requirements
- Have 7+ years of professional experience in application security or a closely related security engineering discipline.
- Have experience independently working on complex, ambiguous problem areas.
- Have hands-on experience with DAST, SAST, and SCA tools and manual testing techniques, including OWASP and SANS Top 25.
- Have experience securing CI/CD pipelines with commercial and custom-built tooling.
- Have experience with IaaS cloud infrastructure such as AWS, Azure, or GCP, container technologies, and service-oriented architectures.
- Have security automation experience in at least one of Go, Python, JavaScript, or Ruby.
- Be familiar with AI/ML security concepts, including prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
- Have working knowledge of AI and LLM tooling such as OpenAI, Anthropic, or LangChain, sufficient to assess security risk and integrate tools into automated workflows.
- Have experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
- Have a bachelor’s degree in Computer Science, Engineering, MIS, or IT, or equivalent work experience.
- Nice to have: 3+ years of security architecture experience designing and reviewing controls across cloud-based, distributed, or service-oriented systems.
- Nice to have: experience developing a formal threat modeling program, evaluating or implementing AI security tooling, managing a bug bounty or vulnerability disclosure program, or working in digital health or HIPAA-regulated environments.
Responsibilities
- Advance secure-by-design practices through architecture reviews, design consultations, and security guidance across the development lifecycle.
- Mentor engineers on secure coding practices, AppSec fundamentals, and career growth.
- Develop an AI-assisted threat modeling program covering risk identification, security architecture, and program maturity.
- Mature SAST, SCA, and DAST programs through rule tuning, coverage improvements, and stronger security controls.
- Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
- Assess vulnerability impact, propose solutions, and validate fixes through established remediation workflows.
- Implement process improvements and security automation using Go, Python, JavaScript, or Ruby, including AI tooling integrations.
- Assess AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, for security risks.
- Research, design, and develop a Secure AI Development Lifecycle in accordance with OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
- Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review.
View Full Description & ApplyYou'll be redirected to the employer's site