Application Security Engineer
Application Security
Cloud Platforms
Cybersecurity Tools
Data Security
Engineer
Facilities Management
Identity and Access Management
Information Security
InfoSec
Project Management
Risk Management
Secure Software Development
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Solution Architecture
Job Description
Strive Health is seeking an Application Security Engineer to embed application security into the product development lifecycle. This role partners closely with Product and Engineering to define security requirements, establish review gates, run testing frameworks, and drive consistent remediation practices to support a secure and compliant delivery pipeline.
Key Responsibilities
- Conduct threat modeling and set a security baseline for internal environments, patient portals, mobile applications, and integration services.
- Maintain data-flow and trust-boundary diagrams, including assessment of identity, operational data, and PHI data classifications.
- Partner with engineering teams to incorporate security acceptance criteria into PRDs, technical plans, and Jira stories.
- Lead architecture reviews with a focus on tenant boundaries, server-side authorization, prevention of IDOR (insecure direct object references), and lateral movement guardrails.
- Develop and enforce merge request (MR) checklists for authentication, input validation, secrets management, and cryptography.
- Design, deploy, and operate application security testing tooling, including SAST, DAST, Software Composition Analysis (SCA), and container/IaC scanning.
- Perform authenticated testing of browser workflows and APIs using tools such as Burp Suite Enterprise.
- Execute manual testing for complex vulnerabilities, including privilege escalation, SSRF, and business-logic abuse.
- Manage a vulnerability intake pipeline, assign severities, and track remediation according to internal SLAs.
- Run recurring vulnerability review sessions with Security, Product, and Engineering stakeholders.
- Coordinate external penetration tests, including scoping, vendor selection, and tracking remediation and retesting.
- Ensure alignment between security requirements, threat models, testing evidence, and remediation documentation with internal compliance needs, such as HITRUST and SOC 2.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 3+ years (Engineer) to 5+ years (Senior) of experience in information security, with a strong focus on Application Security, DevSecOps, or software engineering.
- Demonstrable experience integrating security tools into CI/CD pipelines (e.g., SAST, DAST, SCA).
- Experience leading or performing application threat modeling, architecture reviews, and manual security testing.
- Familiarity with securing cloud environments (SaaS, IaaS, PaaS) and an understanding of cloud architecture.
- Internet connectivity: minimum speeds of 3.8 Mbps down / 3.0 Mbps up, with latency under 60 ms.
- Ability to travel and be onsite to meet business needs.
Technologies
- SAST, DAST, Software Composition Analysis (SCA)
- Container/IaC scanning
- Burp Suite Enterprise
- CI/CD
- HITRUST, SOC 2
- Jira, PRDs
- SaaS, IaaS, PaaS
Preferred Qualifications
- Experience in the healthcare sector, securing environments that manage PHI and complying with frameworks like HITRUST.
- Deep expertise in identifying and exploiting vulnerabilities, including OWASP Top 10, IDOR, SSRF, and authentication bypass.
- Experience testing and securing complex API integrations, mobile application releases, and web-based portals.
- Familiarity with enterprise dynamic testing tools such as Burp Suite Enterprise and automating security testing against deployed applications.
- Advanced certifications in application security or information security, such as CSSLP, GWAPT, CISSP, or CEH.
Compensation and Location
Location: Denver, CO (hybrid)
Annual Salary Range: USD 108,500 - 136,000 per year
Target Bonus: 10% annual bonus
Final compensation is determined based on location, experience, and qualifications.
Benefits
- Hybrid-Remote Flexibility
- Medical, dental, and vision insurance
- Employee assistance programs
- Employer-paid and voluntary life and disability insurance
- Health and flexible spending accounts
- 401k with employer match
- Financial wellness resources
- Paid holidays
- Vacation time and sick time
- Paid birthgiving, bonding, sabbatical, and living donor leaves
- Family forming services through Maven Maternity at no cost
- Physical wellness perks
- Mental health support
- Annual professional development stipend
Additional Information
- Strive Health is an equal opportunity employer and drug free workplace.
- Strive Health is unable to provide work visa sponsorship.
- Unsolicited resumes from outside recruiters or placement agencies are not accepted.