Strive Health

Application Security Engineer

Strive Health
Apply
4 hours ago
Denver, CO, USAMid Level

Base Salary

$109k - $136k/yr

Responsibilities

  • Perform threat modeling and establish security baselines for internal environments, patient portals, mobile applications, and integration services.
  • Maintain data-flow and trust-boundary diagrams and assess identity, operational, and PHI data classifications.
  • Embed security acceptance criteria into PRDs, technical plans, and Jira stories and conduct architecture reviews covering tenant boundaries, authorization, IDOR prevention, and lateral-movement guardrails.
  • Develop and enforce merge-request checklists for authentication, input validation, secrets management, and cryptography.
  • Design, deploy, and operate SAST, DAST, SCA, container, and infrastructure-as-code security scanning.
  • Perform authenticated browser and API testing, manual testing for privilege escalation, SSRF, and business-logic abuse, and coordinate external penetration tests.
  • Manage vulnerability intake, severity assignment, remediation tracking, review sessions, and retesting.
  • Ensure security requirements, threat models, testing evidence, and remediation documentation support internal compliance needs including HITRUST and SOC 2.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • At least 3 years of information security experience for the Engineer level, with a focus on Application Security, DevSecOps, or software engineering.
  • Experience integrating SAST, DAST, and SCA tools into CI/CD pipelines.
  • Experience leading or performing application threat modeling, architecture reviews, and manual security testing.
  • Familiarity with securing SaaS, IaaS, and PaaS environments and understanding cloud architecture.
  • Ability to travel and work onsite as business needs require; required home internet minimum speeds are 3.8 Mbps download and 3.0 Mbps upload with latency below 60 ms.
  • Preferred experience securing healthcare environments involving PHI and complying with HITRUST.
  • Preferred expertise with OWASP Top 10, IDOR, SSRF, authentication bypass, API integrations, mobile application releases, and web-based portals.
  • Preferred familiarity with Burp Suite Enterprise and automation of security testing against deployed applications.
  • Advanced application or information security certifications such as CSSLP, GWAPT, CISSP, or CEH are preferred.
  • Strong problem-solving, analytical, communication, collaboration, and technical-risk explanation skills are preferred.

Benefits

  • Hybrid-remote flexibility with work from home and in-person needs at offices, clinics, or patient home visits.
  • Medical, dental, and vision insurance; employee assistance programs; life and disability insurance; and health and flexible spending accounts.
  • Performance-based bonus program, 401(k) with employer match, and financial wellness resources.
  • Paid holidays, vacation and sick time, birthgiving, bonding, sabbatical, and living donor leave.
  • Family-forming services through Maven Maternity, physical wellness perks, mental health support, and an annual professional development stipend.

Categories

Strive Health

About Strive Health

501-1,000 employees

Strive Health delivers value-based kidney care, integrating a technology platform with local provider networks to manage patients from chronic kidney disease through end-stage kidney disease. It partners with commercial and Medicare Advantage payors, Medicare, health systems and physicians through value-based, often risk-based, contracts; founded in 2018 and headquartered in Denver, the privately held company’s case management programs are NCQA-accredited and its CareMultiplier platform is HITRUST-certified, serving 145,000+ patients across all 50 states with 6,500+ provider partners.

Contact me