Jobs Companies Strive Health Application Security Engineer

Über diese Application Security Engineer Stelle bei Strive Health

Strive Health · Hybrid · Denver, CO

How You’ll Make An Impact

At Strive Health, patients come first. We’re on a mission to transform chronic conditions by identifying risk earlier, coordinating thoughtful care, and supporting people through every stage of their health journey.

Our work reduces emergency visits, improves outcomes, and helps patients live fuller lives. You’ll work alongside passionate Strivers who care deeply about making an impact, show up for one another as One Team, and find ways to elevate the everyday.

If you’re looking for meaningful work where your contributions truly matter, you’ll feel right at home at Strive! 

Benefits & Perks 

  • Hybrid-Remote Flexibility Work from home while fulfilling in-person needs at the office, clinic, or patient home visits.
  • Comprehensive Benefits – Medical, dental, and vision insurance, employee assistance programs, employer-paid and voluntary life and disability insurance, plus health and flexible spending accounts.
  • Financial & Retirement Support – Competitive compensation with a performance-based bonus program, 401k with employer match, and financial wellness resources.
  • Time Off & Leave – Paid holidays, vacation time, sick time, and paid birthgiving, bonding, sabbatical, and living donor leaves.
  • Wellness & Growth – Family forming services through Maven Maternity at no cost and physical wellness perks, mental health support, and an annual professional development stipend.

To learn more about our offerings, click here. 

What You’ll Do 

The Application Security Engineer is responsible for embedding application security directly into Strive’s product development lifecycle, specifically supporting the deployment of Canvas Medical, patient-facing experiences, and future mobile applications. You will serve as the primary security partner for Product and Engineering, ensuring that applications are built securely from the design phase through to production. Rather than treating security as a late-stage penetration test, you will establish the requirements, review gates, testing frameworks, and remediation operating rhythms necessary to support a secure and compliant development pipeline. 

The Day to Day 

Security Discovery and Threat Modeling: 

  • Perform threat modeling and establish a security baseline for internal environments, patient portals, mobile applications, and integration services. 
  • Maintain data-flow and trust-boundary diagrams, assessing identity, operational, and PHI data classifications. 

Architecture & Secure Product Development: 

  • Collaborate with engineering teams to embed security acceptance criteria into PRDs, technical plans, and Jira stories. 
  • Conduct architecture reviews focusing on tenant boundaries, server-side authorization, prevention of IDOR (insecure direct object references), and lateral movement guardrails. 
  • Develop and enforce merge request (MR) checklists covering authentication, input validation, secrets management, and cryptography. 

Application Security Testing Framework: 

  • Design, deploy, and operate application security testing tools including SAST, DAST, Software Composition Analysis (SCA), and container/IaC scanning. 
  • Perform authenticated testing of browser workflows and APIs (e.g., using Burp Suite Enterprise). 
  • Conduct manual testing for complex vulnerabilities such as privilege escalation, SSRF, and business-logic abuse. 

Vulnerability Management & Remediation: 

  • Manage the vulnerability intake pipeline, assign severities, and track remediation aligned with internal SLAs. 
  • Lead recurring vulnerability review sessions with Security, Product, and Engineering stakeholders. 
  • Coordinate external penetration tests, including scoping, vendor selection, and tracking of remediation/retesting. 

Compliance & Audit Readiness: 

  • Ensure all security requirements, threat models, testing evidence, and remediation documentation align with internal compliance needs (e.g., HITRUST, SOC 2). 

Minimum Qualifications 

  • Bachelor’s degree in Computer Science, Information Security, or a related field. 
  • 3+ years (Engineer) to 5+ years (Senior) of experience in information security, with a strong focus on Application Security, DevSecOps, or software engineering. 
  • Demonstrable experience integrating security tools into CI/CD pipelines (e.g., SAST, DAST, SCA). 
  • Experience leading or performing application threat modeling, architecture reviews, and manual security testing. 
  • Familiarity with securing cloud environments (SaaS, IaaS, PaaS) and understanding of cloud architecture. 
  • Internet Connectivity - Min Speeds: 3.8Mbps/3.0Mbps (up/down): Latency <60 ms. 
  • Ability to travel and be onsite to meet business needs. 

Preferred Qualifications 

  • Experience within the healthcare sector, securing environments that manage PHI and complying with frameworks like HITRUST. 
  • Deep expertise in identifying and exploiting vulnerabilities (OWASP Top 10, IDOR, SSRF, authentication bypass). 
  • Experience with testing and securing complex API integrations, mobile application releases, and web-based portals. 
  • Familiarity with enterprise dynamic testing tools (e.g., Burp Suite Enterprise) and automating security testing against deployed applications. 
  • Advanced certifications in application security or information security (e.g., CSSLP, GWAPT, CISSP, CEH). 

About You 

  • Excellent problem-solving and analytical skills, able to assess complex application security issues and provide practical, developer-friendly solutions. 
  • Strong communication and collaboration skills; capable of articulating technical risk to both technical and non-technical stakeholders. 
  • Proactive and adaptable, comfortable embedding directly with engineering pods to shift security “left”. 

 

Annual Salary Range: $108,500 - $136,000. This position is also eligible for a target annual bonus of 10%

Final compensation will be determined based on location, experience, and qualifications. 

Strive Health is an equal opportunity employer and drug free workplace. At this time Strive Health is unable to provide work visa sponsorship. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Please apply even if you feel you do not meet all qualifications. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to [email protected].

We do not accept unsolicited resumes from outside recruiters/placement agencies. Strive Health will not pay fees associated with resumes presented through unsolicited means.

Bereit, sich bei Strive Health zu bewerben?
Bei Strive Health bewerben

Wie sich dieses Gehalt für Application Security vergleicht

Diese Stelle zahlt $122,250/yrunter der üblichen Spanne für Application Security Stellen.

$115,330 dem Median $180,000 $261,980

Übliche Spanne $145,500–$228,500/yr, aus 252 vergleichbaren Application Security Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Application Security ansehen →

Über Strive Health

Why Strive

Strive Health is more than a career. It’s an opportunity
to make a difference and change the healthcare landscape
for generations to come. What do you Strive for?

Alle Jobs bei Strive Health ansehen →

Ähnliche Jobs

Candid Health
Product Security Engineer
Candid Health
⚡ Früh bewerben San Francisco (CA), Denver (C... Vor Ort $180,000–$258,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Wo.
TraceLink, Inc
Product Security Engineer, Senior
TraceLink, Inc
⚡ Früh bewerben APAC - India - Pune Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
ME
Platform Engineer, Application Security
Metr
⚡ Früh bewerben Berkeley Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
Anduril Industries
Technical Security Application Engineer, Secured Spaces
Anduril Industries
⚡ Früh bewerben Costa Mesa, California, United... Vor Ort $146,000–$194,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Anduril Industries
Technical Security Application Engineer, Secured Spaces
Anduril Industries
⚡ Früh bewerben Washington, District of Columb... Vor Ort $146,000–$194,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Anduril Industries
Technical Security Application Engineer, Manufacturing
Anduril Industries
⚡ Früh bewerben Ashville, Ohio, United States Vor Ort $126,000–$167,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
Cloudflare
Senior Systems Engineer - Application Security
Cloudflare
⚡ Früh bewerben Hybrid Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
WRITER
Security engineer, application security (UK)
WRITER
⚡ Früh bewerben London, UK Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
Yoodli AI Roleplays
Senior Software Engineer- Backend (Product & Cloud Security)
Yoodli AI Roleplays
⚡ Früh bewerben Seattle, WA Hybrid $160,000–$190,000
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Strive Health

Alle Jobs bei Strive Health ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos