Senior Application Security Engineer
Quick Summary
At Commure, our mission is to simplify healthcare. We have bold ambitions to reimagine the healthcare experience, setting a new standard for how care is delivered and experienced across the industry.
Design high-fidelity detections and correlation logic in Splunk Enterprise Security and AWS OpenSearch — tuning for coverage and signal-to-noise.
Splunk Certified Architect or Developer; CISSP, CEH, or GIAC GCED. Experience applying ML to anomaly detection, behavioral analytics, or security NLP. Background in healthcare, financial services, or other regulated industries.
At Commure, we're building the AI Operating System for healthcare, the foundation that defines how care is delivered, documented, and financed. Our platform spans the full care journey: Ambient AI and Dictation eliminating documentation burden at the point of care, intelligent Agents automating patient and revenue workflows, and autonomous RCM processing billions in claims, all on a single AI-native platform integrated with 60+ EHRs.
Healthcare carries a $1 trillion administrative burden and we're at the center of transforming it. Today, 500,000+ clinicians across 500+ healthcare organizations nationwide trust Commure to handle $25B+ in annual claims and support over 200 million patient interactions. Our latest $70M raise at a $7B valuation reflects the confidence the market has placed in this mission. We've also been named to the Fortune Future 50 list and the 2026 AI Breakthrough Awards for “Overall NLP Company of the Year.”
Our team works directly alongside clinicians, not through layers of process, which means the gap between what you build and its impact on patient care is immediate. We move fast, deploy daily, and take full ownership from early thinking to production. If you're energized by hard problems, high stakes, and a team that holds itself to a high bar, you'll find your people here.
The future of healthcare is being built right now. Come deliver this transformation.
About the Role
~1 min readSecurity patterns that worked 20 years ago don't hold up anymore, especially as AI changes how fast engineering teams ship code. We're looking for an Application Security Engineer who combines real engineering depth with security fundamentals — someone who gets into the code, spots systemic patterns, and builds the tooling and fixes that address them at scale, rather than flagging issues for someone else to resolve.
This isn't an audit-from-a-distance role. You'll work directly with engineering, with no interim layer needed, and you'll be equally comfortable owning a project end-to-end as you are looping in support when it counts.
Full Time position requires working 3 days a week in our Mountain View office (Hybrid)
Responsibilities
~1 min read- →
Identify systemic security gaps in our codebase and engineering workflows, and drive durable fixes with engineering, not just one-off patches
- →
Build security tooling and automation, including SAST/SCA integration and custom checks, that catches issues earlier rather than after they ship
- →
Conduct code reviews and security design reviews for major product initiatives, including agentic AI systems and data pipelines
- →
Drive threat modeling for new features and translate requirements into guidance engineers actually use
- →
Think through what AI-accelerated development means for how we find, prioritize, and fix risk, and use AI tooling where it genuinely helps
- →
Present our security posture to enterprise customers, including healthcare and regulated-data conversations
5+ years of hands-on application security or software engineering experience, not mainly audit or compliance work
Genuine engineering depth: you can read and reason about code well enough to find real bugs and root causes
Strong AppSec fundamentals: threat modeling, secure code review, and OWASP-aligned vulnerability knowledge
Comfort operating independently with good judgment in a fast-moving environment
Clear communication that earns trust with engineers
Nice to Have
~1 min readExperience securing agentic AI or LLM-powered systems
Experience building SAST pipelines or custom static analysis rules
Healthcare or other regulated-industry security experience (PHI, HIPAA)
Offensive security background (bug bounty, CTF, pentesting)
Direct enterprise customer experience
Please be aware that all official communication from us will come exclusively from email addresses ending in @commure.com. Any emails from other domains are not affiliated with our organization.
Employees will act in accordance with the organization’s information security policies, to include but not limited to protecting assets from unauthorized access, disclosure, modification, destruction or interference nor execute particular security processes or activities. Employees will report to the information security office any confirmed or potential events or other risks to the organization. Employees will be required to attest to these requirements upon hire and on an annual basis.
Location & Eligibility
Listing Details
- Posted
- May 4, 2026
- First seen
- May 6, 2026
- Last seen
- August 7, 2026
Posting Health
- Days active
- 93
- Repost count
- 0
- Trust Level
- 18%
- Scored at
- August 7, 2026
Signal breakdown
Please let commure know you found this job on Jobera.
4 other jobs at commure
View all →Explore open roles at commure.
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.