Application Security Engineer New Denver, CO

Strive Health

Denver, Northern (CO, KY)

Hybrid

USD 109,000 - 136,000

Full time

31 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid-Remote Flexibility
Comprehensive Benefits
Financial & Retirement Support
Time Off & Leave
Wellness & Growth

Job summary

Strive Health in Denver hybrid environment seeks an Application Security Engineer to embed security into the product development lifecycle, supporting Canvas Medical and patient apps. You’ll partner with Product and Engineering to set requirements, review gates, and implement secure design and testing practices.

You’ll design threat models, run SAST/DAST/SCA tooling, manage vulnerabilities, coordinate audits for HITRUST/SOC2, and mentor teams on secure coding.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 3+ years (Engineer) to 5+ years (Senior) of information security experience with focus on Application Security/DevSecOps.
  • Experience integrating security tools into CI/CD pipelines (SAST, DAST, SCA).
  • Experience leading or performing application threat modeling, architecture reviews, and manual security testing.

Responsibilities

  • Embed security into Strive’s product development lifecycle for Canvas Medical and related apps.
  • Serve as the primary security partner for Product and Engineering, establishing requirements, review gates, testing frameworks, and remediation rhythms.

Skills

Application Security
DevSecOps
Threat Modeling
CI/CD Security
Security Testing

Education

Bachelor's degree in Computer Science/Information Security

Tools

SAST
DAST
SCA
Burp Suite Enterprise

Job description

At Strive Health, patients come first. We’re on a mission to transform chronic conditions by identifying risk earlier, coordinating thoughtful care, and supporting people through every stage of their health journey.

Our work reduces emergency visits, improves outcomes, and helps patients live fuller lives. You’ll work alongside passionate Strivers who care deeply about making an impact, show up for one another as One Team, and find ways to elevate the everyday.

If you’re looking for meaningful work where your contributions truly matter, you’ll feel right at home at Strive!

  • Hybrid-Remote Flexibility – Work from home while fulfilling in-person needs at the office, clinic, or patient home visits.
  • Comprehensive Benefits – Medical, dental, and vision insurance, employee assistance programs, employer-paid and voluntary life and disability insurance, plus health and flexible spending accounts.
  • Financial & Retirement Support – Competitive compensation with a performance-based bonus program, 401k with employer match, and financial wellness resources.
  • Time Off & Leave – Paid holidays, vacation time, sick time, and paid birthgiving, bonding, sabbatical, and living donor leaves.
  • Wellness & Growth – Family forming services through Maven Maternity at no cost and physical wellness perks, mental health support, and an annual professional development stipend.
What You’ll Do

The Application Security Engineer is responsible for embedding application security directly into Strive’s product development lifecycle, specifically supporting the deployment of Canvas Medical, patient-facing experiences, and future mobile applications. You will serve as the primary security partner for Product and Engineering, ensuring that applications are built securely from the design phase through to production. Rather than treating security as a late-stage penetration test, you will establish the re quirements, review gates, testing frameworks, and remediation operating rhythms necessary to support a secure and compliant development pipeline.

The Day to Day
Security Discovery and Threat Modeling:
  • Perform threat modeling and establish a security baseline for internal environments, patient portals, mobile applications, and integration services.
  • Maintain data-flow and trust-boundary diagrams, assessing identity, operational, and PHI data classifications.
  • Collaborate with engineering teams to embed security acceptance criteria into PRDs, technical plans, and Jira stories.
  • Conduct architecture reviews focusing on tenant boundaries, server-side authorization, prevention of IDOR (insecure direct object references), and lateral movement guardrails.
  • Develop and enforce merge request (MR) checklists covering authentication, input validation, secrets management, and cryptography.
Application Security Testing Framework:
  • Design, deploy, and operate application security testing tools including SAST, DAST, Software Composition Analysis (SCA), and container/ IaC scanning.
  • Conduct manual testing for complex vulnerabilities such as privilege escalation, SSRF, and business-logic abuse.
Vulnerability Management & Remediation:
  • Manage the vulnerability intake pipeline, assign severities, and track remediation aligned with internal SLAs.
  • Lead recurring vulnerability review sessions with Security, Product, and Engineering stakeholders.
  • Coordinate external penetration tests, including scoping, vendor selection, and tracking of remediation/retesting.
Compliance & Audit Readiness:
  • Ensure all security requirements, threat models, testing evidence, and remediation documentation align with internal compliance needs (e.g., HITRUST, SOC 2).
Minimum Qualifications
  • Bachelor’s degree in Computer Science , Information Security, or a related field.
  • 3+ years (Engineer) to 5+ years (Senior) of experience in information security, with a strong focus on Application Security, DevSecOps , or software engineering.
  • Demonstrable experience integrating security tools into CI/CD pipelines (e.g., SAST, DAST, SCA).
  • Experience leading or performing application threat modeling, architecture reviews, and manual security testing.
  • Familiarity with securing cloud environments (SaaS, IaaS, PaaS) and understanding of cloud architecture.
  • Internet Connectivity - Min Speeds: 3.8Mbps/3.0Mbps (up/down): Latency <60 ms.
  • Ability to travel and be onsite to meet business needs.
Preferred Qualifications
  • Experience within the healthcare sector, securing environments that manage PHI and complying with frameworks like HITRUST.
  • Deep expertise in identifying and exploiting vulnerabilities (OWASP Top 10, IDOR, SSRF, authentication bypass).
  • Experience with testing and securing complex API integrations, mobile application releases, and web-based portals.
  • Familiarity with enterprise dynamic testing tools (e.g., Burp Suite Enterprise) and automating security testing against deployed applications.
  • Advanced certifications in application security or information security (e.g., CSSLP, GWAPT, CISSP, CEH).
About You
  • Excellent problem-solving and analytical skills, able to assess complex application security issues and provide practical, developer-friendly solutions.
  • Strong communication and collaboration skills; capable of articulating technical risk to both technical and non-technical stakeholders.
  • Proactive and adaptable, comfortable embedding directly with engineering pods to shift security “left ”.
Annual Salary Range: $108,500 - $136,000. This position is also eligible for a target annual bonus of 10%

Final compensation will be determined based on location, experience, and qualifications.

Strive Health is an equal opportunity employer and drug free workplace. At this time Strive Health is unable to provide work visa sponsorship. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Please apply even if you feel you do not meet all qualifications. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to talentacquisition@strivehealth.com.

We do not accept unsolicited resumes from outside recruiters/placement agencies. Strive Health will not pay fees associated with resumes presented through unsolicited means.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Strive Health’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Strive Health • Denver (CO)

Hybrid
USD 109,000 - 136,000
Hybrid-Remote Flexibility
Comprehensive Benefits
401k with employer match
+2
Lead DevOps Engineer
Lead DevOps Engineer

STR • Woburn (MA)

On-site
USD 175,000 - 240,000
Staff DevSecOps Engineer (Health 100)
Staff DevSecOps Engineer (Health 100)

9025 CVS Shared Services Resources LLC • Massachusetts

Hybrid
USD 130,000 - 260,000
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • Philadelphia

On-site
USD 110,000 - 150,000
Salary up to $150k
Insurance
Retirement plan
+5
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+8
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4
System Administrator
System Administrator

Strive Health Services LLC • Denver (CO)

Hybrid
USD 86,000 - 104,000
Hybrid-Remote Flexibility
Comprehensive Benefits
401k with employer match
+2
Nurse Practitioner - OH
Nurse Practitioner - OH

Strive Health • Cleveland (OH)

Hybrid
USD 112,000 - 140,000
Hybrid-Remote Flexibility
Comprehensive Benefits
Financial & Retirement Support
+2
VP, Data Platform Denver, CO
VP, Data Platform Denver, CO

Strive Health • Denver (CO), Northern (KY)

Hybrid
USD 173,000 - 231,000
Hybrid-Remote Flexibility
Comprehensive Benefits
Financial & Retirement Support
+2
System Administrator
System Administrator

Socket.dev • Denver (CO)

Hybrid
USD 86,000 - 104,000
Hybrid-Remote Flexibility
Comprehensive Benefits
401k with employer match
+2