Senior Security Engineer - Application Security
Quick Summary
Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
4+ years of professional experience in application, product or software security, operating as an individual contributor,
About the Role
~1 min read- Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
- Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
- Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
- Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
- Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
- Develop secure coding standards with developer-focused documentation
- Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
- Evaluate third party applications, libraries and APIs and integrations for security risk
- Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.
- 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
- Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
- Experience performing manual security testing of modern web applications, APIs and distributed systems
- Ability to review application architecture and source code for security weaknesses
- Experience integrating application security tools into modern CI/CD workflows
- Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
- Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
- Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
- Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.
What We Offer
~3 min readBehind every leading health system is K Health’s AI-powered virtual care engine.
Esteemed health systems like Mayo Clinic, Cedars-Sinai, Mass General Brigham, Hackensack Meridian Health, and Hartford Healthcare partner with K Health to build and run modern primary virtual care clinics on their behalf.
Our deeply integrated model modernizes the primary care loop by using AI to put humans first. For our patients, we offer clinical AI (i.e., PatientGPT) and unparalleled access to close care gaps around the clock. For our Providers, we deliver provider-serving agentic solutions (i.e., Perfect Note) to eliminate administrative overload and burnout. And for the health systems, we deploy our top-grade Virtualists in AI-powered virtual clinics 24/7 to capture the patients' care journeys at step one, retain the journey through the system for longitudinal care, and strengthen profitability.
We’re founded in 2016, headquartered in New York City, and backed by nearly $400 million from leading investors including Valor Equity Partners, Claure Group, Mangrove Capital Partners, 14W, Notable Capital, Lerer Hippeau, Primary Venture Partners, Comcast Ventures, PICO Venture Partners, Max Ventures, and other strategic healthcare partners.
We offer competitive compensation packages based on industry benchmarks for function, level, and geographic location. Offer amounts are determined by multiple factors such as a candidate's experience and expertise.
We are proud to be an Equal Opportunity Employer and consider applicants for employment regardless of race, ethnicity, religion, color, national origin, ancestry, disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, sexual orientation, pregnancy, childbirth and breastfeeding, age, citizenship, military or veteran status, or any other class protected by applicable federal, state, and local laws. We’re deeply committed to building teams as diverse as the patients we serve and strive to cultivate an environment where everyone can bring their most authentic self to work. We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our users.
We are committed to maintaining the integrity of our hiring process and ensuring a safe environment for all candidates. All communication for job offers from K Health will come from email addresses ending in @khealth.com. K Health will never ask you to provide financial information about yourself during the recruitment process. We will never use personal email accounts or other domains for official correspondence. Our official job postings are only listed on our official website and reputable job boards. Be cautious of job offers from sources other than these platforms.
Location & Eligibility
Listing Details
- Posted
- August 7, 2026
- First seen
- August 7, 2026
- Last seen
- August 8, 2026
Posting Health
- Days active
- 0
- Repost count
- 1
- Trust Level
- 64%
- Scored at
- August 7, 2026
Signal breakdown
Please let Khealthcareers know you found this job on Jobera.
3 other jobs at Khealthcareers
View all →Explore open roles at Khealthcareers.
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.