Senior Application Security Engineer – Cloud & AppSec

K Health

New York (NY)

On-site

USD 150,000 - 200,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

K Health, based in New York, is seeking a Senior Security Engineer focused on AppSec to safeguard our healthcare platform. You will drive secure software practices across the SDLC, partner with product and engineering teams, and perform hands-on testing of web apps, APIs, and cloud services.

Responsibilities include building automated security testing in CI/CD, refining security tooling, and shaping enterprise‑scale security policies to protect patient data and ensure regulatory compliance.

Qualifications

  • 4 years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
  • Strong understanding of application security vulnerabilities and attack techniques, including OWASP Top 10 and API security risks
  • Experience performing manual security testing of modern web applications, APIs and distributed systems
  • Ability to review application architecture and source code for security weaknesses
  • Experience integrating application security tools into modern CI/CD workflows
  • Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure‑as‑code scanning
  • Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
  • Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
  • Demonstrated experience researching, establishing, and successfully rolling out enterprise‑wide security policies and guidelines.

Responsibilities

  • Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
  • Perform hands‑on security testing of web applications, APIs, cloud‑native services and supporting infrastructure
  • Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
  • Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
  • Develop secure coding standards with developer‑focused documentation
  • Contribute application security expertise to vulnerability management, during security incidents/investigations and post‑incident reviews
  • Evaluate third party applications, libraries and APIs and integrations for security risk
  • Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.

Skills

Application security
OWASP Top 10
API security
Security testing
CI/CD integration
Cloud security
Security architecture review
Automation

Tools

Datadog
Sumo Logic
Torq
flare.io
GCP
Entitle
Okta
Orca
GitLab
Prisma

Job description

K Health, based in New York, is seeking a Senior Security Engineer focused on AppSec to safeguard our healthcare platform. You will drive secure software practices across the SDLC, partner with product and engineering teams, and perform hands-on testing of web apps, APIs, and cloud services.

Responsibilities include building automated security testing in CI/CD, refining security tooling, and shaping enterprise‑scale security policies to protect patient data and ensure regulatory compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer - AppSec & SDLC
Senior Application Security Engineer - AppSec & SDLC

K Health • New York (NY)

On-site
USD 150,000 - 200,000
Senior Security Engineer - Cloud & AppSec (Healthcare tech)
Senior Security Engineer - Cloud & AppSec (Healthcare tech)

Khealthcareers • New York (NY)

Hybrid
USD 150,000 - 200,000
Hybrid work schedule
18 vacation days
401(k) benefit
+2
Senior AppSec Engineer: Secure SDLC & Cloud Security (Hybrid)
Senior AppSec Engineer: Secure SDLC & Cloud Security (Hybrid)

Doist • New York (NY)

Hybrid
USD 150,000 - 200,000
Senior App Security Engineer | Cloud & Healthcare
Senior App Security Engineer | Cloud & Healthcare

Phase2 Technology • Austin (TX)

Hybrid
USD 95,000 - 125,000
Senior App Security Engineer — Threat Research & Cloud
Senior App Security Engineer — Threat Research & Cloud

Stryker Corporation • Austin (TX)

On-site
Confidential
Application Security Engineer
Application Security Engineer

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 100,000 - 130,000
Competitive compensation
Hybrid work flexibility
Opportunities for advancement
Senior App Security Engineer - Threat Research & Cloud
Senior App Security Engineer - Threat Research & Cloud

Koitecc Solutions • Salem (OR)

On-site
USD 107,000 - 284,000
Senior App Security Engineer — Remote, Tooling & SDLC Leader
Senior App Security Engineer — Remote, Tooling & SDLC Leader

Ensemble Health Partners • United States

On-site
USD 101,000 - 152,000
Healthcare benefits
Tuition reimbursement
Professional certification support
App Security Engineer: Threat Research & Cloud DevSecOps
App Security Engineer: Threat Research & Cloud DevSecOps

Hispanic Alliance for Career Enhancement • Juneau (AK)

On-site
USD 107,000 - 284,000
Medical, dental, and vision coverage
Paid time off
Retirement savings options
+1
Senior App Security Engineer: Threat Research
Senior App Security Engineer: Threat Research

Koitecc Solutions • Indianapolis (IN)

On-site
USD 107,000 - 284,000
Comprehensive benefits
Bonus eligibility
Career development