Application Security Engineer

Myfitnesspal

Austin (TX)

On-site

USD 90,000 - 130,000

Full time

17 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Healthcare
401(k) plan
Annual bonus
Wellness allowance
Time Off policy

Job summary

MyFitnessPal is hiring a Security Engineer II to own the day-to-day application security vulnerability management and partner with product teams to remediate findings. You will leverage AI-assisted tooling to accelerate security workflows and build automation that scales vulnerability intake and reporting.

The role includes program ownership, triage of SAST/DAST/SCA findings, bug bounty operations, and collaboration across Security and TechOps to enable secure development at scale.

Qualifications

  • 2-4 years of experience in security engineering or related role.
  • Understanding of app security assessment techniques (SAST/DAST/SCA) and remediation steps.
  • Knowledge of secure development for web/mobile apps (OWASP Top 10/MASVS).
  • Experience with AI/agentic-assisted tooling and applying to security work.
  • Security triage, investigation, and remediation communication to engineers.
  • Familiarity with cloud microservices, containers, Kubernetes, IaC.

Responsibilities

  • Own day-to-day application security vulnerability management and triage findings.
  • Operate and grow the bug bounty program: scope, triage, validate, coordinate with vendors.
  • Leverage AI tooling to accelerate security workflows and secure AI-enabled development practices.
  • Build security automation that normalizes intake, drives SLAs, and reports metrics.
  • Collaborate with product teams on remediation and explain security as a business enabler.
  • Perform security reviews of new features, services, and third-party integrations.
  • Advocate secure coding and contribute to developer-facing security docs/training.
  • Administer and tune CS tooling across the SDLC; evaluate new security tech.
  • Support identity and access management workflows and automation.

Skills

SAST & DAST
SCA
Penetration testing
CI/CD security
Kubernetes
Communication skills
Threat modeling

Education

Bachelor in CS/IS

Tools

Python
SOAR platforms

Job description

At MyFitnessPal, we believe good health starts with what you eat. We provide tools, resources and support to enable users to reach their health goals.

We are looking for a Security Engineer II with a focus on Application Security to join the MyFitnessPal Security team. Our users rely on MyFitnessPal to power their health and fitness journeys every day, and you will leverage your technical skills to secure the code, applications, and development processes that create the MyFitnessPal product experience. In addition to technical expertise, you'll find that your teammates value collaboration, mentorship, and inclusive environments.

About the team:

The Productivity Engineering: Automation & Self-Service (PEAS) team is responsible for the automation, CI/CD, and self-service platforms that product teams rely on to build, test, and ship features quickly and safely.

The PEAS team is part of the Technology Operations (TechOps) organization, which includes IT, Infrastructure, Security, Reliability, and DevOps/DevEx disciplines. TechOps seeks to enable MyFitnessPal to "ship with confidence" by delivering a secure, reliable, and low-friction runway to build and operate software at scale. Within TechOps, you'll represent the Security discipline — protecting the applications and development processes that keep our mobile and backend software safe for millions of users.

As a Security Engineer II, you will own the day-to-day operation of our application security vulnerability management program and act as a trusted security partner to product engineering teams. You'll triage what our tooling and researchers find, drive it to remediation, and build the automation that makes the whole program run with less manual effort. This is a hands-on technical position with real ownership and substantial opportunity for growth.

What you'll be doing:
  • Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets through our SVM process to resolution
  • Operate and grow our bug bounty program — scoping engagements, triaging researcher submissions, validating findings, and coordinating with vendors
  • Leverage AI and agentic tooling (for example, Claude Code and agentic pipelines) to accelerate security workflows — from vulnerability triage and enrichment to automated remediation support — and help ensure our AI-assisted development practices remain secure
  • Build and maintain security automation (for example, in our SOAR platform and with Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces the metrics and reporting that keep the program transparent
  • Partner with product engineering teams on remediation — joining triage and refinement discussions, answering questions, and representing security as a business enabler rather than a blocker
  • Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance
  • Advocate secure coding practices and contribute to developer-facing security documentation and training
  • Administer and tune application security tooling across the SDLC, and help evaluate and implement new security technology
  • Support identity and access management workflows and the automation behind them
Qualifications to be successful in this role:
  • 2-4 years of experience in security engineering, application security, software engineering, or a closely related role
  • Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
  • Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
  • Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
  • Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
  • Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code)
  • Strong communication skills, enabling collaboration across cross-functional teams, and the judgment to raise a security finding and land it as a shared problem to solve, not a fight to win
  • Ability to create documentation that describes technical details clearly, including for non-technical audiences
  • Ability & desire to learn new product lines and technologies quickly & efficiently
  • Education and/or certifications equivalent to BS in Computer Science or IS related field; GIAC (e.g., GWEB, GCIH), OSCP, CSSLP, Security+, or vendor-specific certifications are a plus

Preferred Qualifications:

  • Experience automating security processes (e.g., Python, SOAR platforms, workflow automation) is strongly preferred
  • Experience with security scanning in CI/CD pipelines and orchestration tools (e.g., GitHub Actions) is a plus
  • Experience operating or triaging for a bug bounty program is a plus
  • Be Kind and Care — build with empathy; assume positive intent; support teammates and members.
  • Live Good Health — champion healthy habits and balance in how we work and what we ship.
  • Be Data-Inspired — ground decisions in research and data; measure what matters.
  • Champion Change — lean into ambiguity; iterate, learn, and improve continuously.
  • Leave it Better than You Found It — raise quality, clarify systems, and document as you go.
  • Make It Happen — bias to action; deliver impact with craft and accountability.

The reasonably estimated salary for this role at MyFitnessPal ranges from $90,000 - $130,000. Actual compensation is based on factors such as the candidate’s skills, qualifications, and experience. In addition, MyFitnessPal offers a wide range of comprehensive and inclusive employee benefits for this role including healthcare, parental planning, mental health benefits, annual performance bonus, a 401(k) plan and match, responsible time off, monthly wellness and technology allowances, and others.

Exciting Full-Time Employee Benefits, Perks and Culture

Face-to-Face Connections: We value personal connections. Enjoy opportunities to meet and connect with your team members in person to help forge meaningful relationships that extend beyond the virtual realm. Teams meet as often as needed and all of MyFitnessPal gathers annually.

Flexibility At Its Best: Achieve the work-life balance you deserve. Enjoy a flexible time-off policy with our Responsible Time Off benefit.

Give Back: Use your volunteer days off to support what matters most to you. Each full time teammate receives 2 days per calendar year to give back to their community through service.

Mentorship Program: Take control of your career through our mentorship program where, if you’d like, you will be matched with a teammate who can help you scale your skills and propel your growth.

Family-Friendly Support: Embrace the journey with confidence and care. Enjoy our paid maternity and paternity leave, to provide time to balance family responsibilities with your career and take the time needed to strengthen family relationships. We understand the complexities of starting or expanding a family, which is why we provide best-in-class comprehensive assistance for fertility-related matters.

Wellness Comes First: Live Good Health is one of our core values. Receive a monthly Wellness Allowance, empowering you to focus on your physical and mental well-being by choosing from a range of wellness initiatives, including dedicated mental health days.

Celebrate Greatness:Your hard work deserves recognition! Our reward and recognition platform empowers peers to acknowledge and reward each other for the exceptional contributions they make.

Elevate Your Health & Fitness: Get access to MyFitnessPal Premium, allowing you to take your fitness, health and wellness journey to new heights.

Unlock Your Potential: Access our virtual learning and development library, and participate in training opportunities to continuously grow and enhance your skills.

Championing Inclusion: Our dedicated DEI Committee actively fosters a diverse and inclusive workplace by setting actionable goals and evaluating progress across the organization.

Healthcare Matters: Your well-being is our priority. Take advantage of our competitive medical, dental, and vision benefits that cater to your holistic healthcare needs. Feel secure and supported on your wellness journey.

Secure Your Future: Benefit from our retirement savings program, giving you peace of mind for your financial goals. Reach them sooner with MyFitnessPal’s competitive employer match.

At MyFitnessPal, our mission is to enable people to make healthy choices. And it wouldn't be possible without our team. We celebrate the unique POV that each person brings to the table and believe in a collaborative and inclusive environment. As an equal opportunity employer, we prohibit any unlawful discrimination on the basis of race, religion, military or veteran status, sex, gender, marital status, gender identity or expression, sexual orientation, national origin, age, or disability. These are our guiding ideologies and apply across all aspects of employment.

MyFitnessPal participates in E-Verify.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Socket.dev • Northern (KY)

Hybrid
USD 90,000 - 130,000
Health Insurance
401(k) with match
Flexible time off
+3
Site Reliability Engineer
Site Reliability Engineer

MyFitnessPal • United States

On-site
USD 120,000 - 165,000
Healthcare benefits
401(k) with company match
Annual performance bonus
+4
Software Engineer II, Android - Partnerships
Software Engineer II, Android - Partnerships

Myfitnesspal • United States

On-site
USD 115,000 - 130,000
Healthcare benefits
Parental planning support
Mental health benefits
+4
Director, Product Analytics New Remote - US
Director, Product Analytics New Remote - US

MyFitnessPal, Inc. • Northern (KY)

Hybrid
USD 180,000 - 270,000
Healthcare benefits
Parental planning
Mental health benefits
+5
Lead, Brand Marketing
Lead, Brand Marketing

Myfitnesspal • Austin (TX)

On-site
USD 110,000 - 175,000
Healthcare
401(k) plan with match
Wellness & technology allowances
+2
Sr. BI Engineer
Sr. BI Engineer

MyFitnessPal • United States

On-site
USD 110,000 - 170,000
Face-to-face connections
Flexible time-off policy
Volunteer days off
+8
Sr. BI Engineer Remote - US
Sr. BI Engineer Remote - US

MyFitnessPal, Inc. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Face-to-Face Connections
Flexible Time Off
Volunteer Days
+9
Software Engineer III, Android - Ads
Software Engineer III, Android - Ads

Myfitnesspal • New York (NY)

On-site
USD 140,000 - 160,000
Flexible time-off policy
Wellness Allowance
Mentorship program
+2
Lead, Brand Marketing New Remote - US
Lead, Brand Marketing New Remote - US

MyFitnessPal, Inc. • Northern (KY)

Hybrid
USD 105,000 - 175,000
Healthcare
Parental planning
Mental health benefits
+5
Lead, Brand Marketing
Lead, Brand Marketing

MyFitnessPal • United States

On-site
USD 110,000 - 175,000
Healthcare benefits
401(k) match
Annual bonus
+2