K Health

Senior Security Engineer - Application Security

K Health
Apply
1 month ago

Base Salary

$150k - $200k/yr

Responsibilities

  • Lead development and implementation of application security protocols throughout the software development lifecycle.
  • Partner with engineering teams to integrate security into architecture, design, development, testing, and deployment.
  • Perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
  • Build and improve automated security testing for static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
  • Evaluate application security tools, improve finding quality, and reduce unnecessary findings and developer friction.
  • Develop secure coding standards and developer-focused documentation.
  • Contribute application security expertise to vulnerability management, security incidents and investigations, and post-incident reviews.
  • Evaluate third-party applications, libraries, APIs, and integrations for security risk.
  • Ensure healthcare regulatory and compliance requirements, including HIPAA and GDPR, are followed across products and systems.

Requirements

  • At least 4 years of professional experience in application, product, or software security, or as a software engineer who transitioned into security.
  • Strong understanding of application security vulnerabilities, attack techniques, OWASP Top 10, and API security risks.
  • Experience manually testing modern web applications, APIs, and distributed systems and reviewing architecture and source code for security weaknesses.
  • Experience integrating application security tools into CI/CD workflows, including static analysis, dynamic testing, secrets detection, container security, and infrastructure-as-code scanning.
  • Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design.
  • Strong expertise in AWS, GCP, or Azure, modern programming languages, generative coding utilities, and the security implications of AI code development utilities.
  • Demonstrated experience researching, establishing, and rolling out enterprise-wide security policies and guidelines.
  • Experience with tools and technologies including Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, or Prisma is a bonus.

Benefits

  • Hybrid work arrangement is indicated.
  • Competitive compensation package based on function, level, and geographic location.

Categories

K Health

About K Health

201-500 employees

K Health builds an AI-enabled platform for virtual and in-person primary care, delivered via a mobile app and through health-system partnerships. The company licenses its clinical AI (PatientGPT) and staffs 24/7 virtual clinics to help partners manage large patient populations and close care gaps. Founded in 2016 and headquartered in New York City, K Health’s partners include Mayo Clinic and Mass General Brigham.

Contact me