EngineerJobs.io
← Back to all jobs

Job Description

Strive Health is seeking an Application Security Engineer to embed application security into the product development lifecycle. The role partners closely with Product and Engineering to define security requirements, establish review and testing gates, and drive remediation practices that support a secure and compliant development pipeline.

Key Responsibilities

  • Lead threat modeling and define a security baseline across internal environments, patient portals, mobile applications, and integration services.
  • Maintain data-flow and trust-boundary diagrams, evaluating identity, operational data, and PHI data classifications.
  • Work with engineering teams to incorporate security acceptance criteria into PRDs, technical plans, and Jira stories.
  • Perform architecture reviews with a focus on tenant boundaries, server-side authorization, IDOR prevention (insecure direct object references), and lateral movement guardrails.
  • Create and enforce merge request (MR) checklists for authentication, input validation, secrets management, and cryptography.
  • Design, deploy, and operate application security testing tools, including SAST, DAST, Software Composition Analysis (SCA), and container/IaC scanning.
  • Conduct authenticated testing of browser workflows and APIs, including work with Burp Suite Enterprise.
  • Execute manual testing for complex vulnerabilities such as privilege escalation, SSRF, and business-logic abuse.
  • Manage the vulnerability intake pipeline, assign severities, and track remediation aligned to internal SLAs.
  • Run recurring vulnerability review sessions with Security, Product, and Engineering stakeholders.
  • Coordinate external penetration tests, including scoping, vendor selection, and remediation and retesting tracking.
  • Ensure security requirements, threat models, testing evidence, and remediation documentation align with internal compliance needs such as HITRUST and SOC 2.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 3+ years (Engineer) to 5+ years (Senior) of experience in information security, with strong focus on Application Security, DevSecOps, or software engineering.
  • Experience integrating security tools into CI/CD pipelines, including SAST, DAST, and SCA.
  • Demonstrated experience performing application threat modeling, architecture reviews, and manual security testing.
  • Familiarity with securing cloud environments (SaaS, IaaS, PaaS) and understanding of cloud architecture.
  • Internet Connectivity: minimum speeds of 3.8 Mbps down / 3.0 Mbps up, with latency under 60 ms.
  • Ability to travel and be onsite as needed for business requirements.

Technologies

  • SAST, DAST, Software Composition Analysis (SCA)
  • Container/IaC scanning
  • Burp Suite Enterprise
  • CI/CD
  • HITRUST, SOC 2
  • Jira, PRDs
  • SaaS, IaaS, PaaS

Preferred Qualifications

  • Experience securing healthcare environments that manage PHI and meet HITRUST-related requirements.
  • Deep expertise in identifying and exploiting vulnerabilities, including OWASP Top 10 topics, IDOR, SSRF, and authentication bypass.
  • Experience testing and securing complex API integrations, mobile application releases, and web-based portals.
  • Familiarity with enterprise dynamic testing tools (for example, Burp Suite Enterprise) and automating security testing against deployed applications.
  • Advanced certifications in application or information security, such as CSSLP, GWAPT, CISSP, or CEH.

Compensation and Work Location

Location: Denver, CO (hybrid)

Annual Salary Range: USD 108,500 - 136,000 per year

Bonus: Target annual bonus of 10%

Final compensation will be determined based on location, experience, and qualifications.

Benefits

  • Hybrid-remote flexibility
  • Medical, dental, and vision insurance
  • Employee assistance programs
  • Employer-paid and voluntary life and disability insurance
  • Health and flexible spending accounts
  • 401k with employer match
  • Financial wellness resources
  • Paid holidays
  • Vacation time and sick time
  • Paid birthgiving, bonding, sabbatical, and living donor leaves
  • Family forming services through Maven Maternity at no cost
  • Physical wellness perks
  • Mental health support
  • Annual professional development stipend

About This Role

  • Strong problem-solving and analytical skills to assess application security issues and provide practical, developer-friendly solutions.
  • Ability to communicate technical risk to technical and non-technical stakeholders.
  • Comfort collaborating directly with engineering pods to shift security practices earlier in the delivery process.

Additional Information

  • Strive Health is an equal opportunity employer and a drug free workplace.
  • Strive Health is unable to provide work visa sponsorship.
  • Unsolicited resumes are not accepted from outside recruiters/placement agencies.

Similar Jobs