1 month ago
Base Salary
$150k - $200k/yr
Responsibilities
- Lead development and implementation of application security protocols throughout the software development lifecycle.
- Partner with engineering teams to integrate security into architecture, design, development, testing, and deployment.
- Perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
- Build and improve automated security testing for static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
- Evaluate application security tools, improve finding quality, and reduce unnecessary findings and developer friction.
- Develop secure coding standards and developer-focused documentation.
- Contribute application security expertise to vulnerability management, security incidents and investigations, and post-incident reviews.
- Evaluate third-party applications, libraries, APIs, and integrations for security risk.
- Ensure healthcare regulatory and compliance requirements, including HIPAA and GDPR, are followed across products and systems.
Requirements
- At least 4 years of professional experience in application, product, or software security, or as a software engineer who transitioned into security.
- Strong understanding of application security vulnerabilities, attack techniques, OWASP Top 10, and API security risks.
- Experience manually testing modern web applications, APIs, and distributed systems and reviewing architecture and source code for security weaknesses.
- Experience integrating application security tools into CI/CD workflows, including static analysis, dynamic testing, secrets detection, container security, and infrastructure-as-code scanning.
- Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design.
- Strong expertise in AWS, GCP, or Azure, modern programming languages, generative coding utilities, and the security implications of AI code development utilities.
- Demonstrated experience researching, establishing, and rolling out enterprise-wide security policies and guidelines.
- Experience with tools and technologies including Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, or Prisma is a bonus.
Benefits
- Hybrid work arrangement is indicated.
- Competitive compensation package based on function, level, and geographic location.
Tech Stack
Categories
About K Health
K Health builds an AI-enabled platform for virtual and in-person primary care, delivered via a mobile app and through health-system partnerships. The company licenses its clinical AI (PatientGPT) and staffs 24/7 virtual clinics to help partners manage large patient populations and close care gaps. Founded in 2016 and headquartered in New York City, K Health’s partners include Mayo Clinic and Mass General Brigham.
