Application Security Engineer
HeartFlow
Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease, the #1 cause of death worldwide, using cutting-edge technology. The flagship product-an AI-driven, non-invasive cardiac test supported by the ACC/AHA Chest Pain Guidelines called the Heartflow FFRCT Analysis-provides a color-coded, 3D model of a patient's coronary arteries indicating the impact blockages have on blood flow to the heart. Heartflow is the first AI-driven non-invasive integrated heart care solution across the CCTA pathway that helps clinicians identify stenoses in the coronary arteries (RoadMap™Analysis), assess coronary blood flow (FFRCT Analysis), and characterize and quantify coronary atherosclerosis (Plaque Analysis). Our pipeline of products is growing and so is our team; join us in helping to revolutionize precision heartcare.
Heartflow is a publicly traded company (HTFL) that has received international recognition for exceptional strides in healthcare innovation, is supported by medical societies around the world, cleared for use in the US, UK, Europe, Japan and Canada, and has been used for more than 750,000 patients worldwide.We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC). In this role, you'll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare. If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply. This role is a hybrid, requiring three days a week in our San Francisco office. What You'll Do:
- Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
- Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
- Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
- Build security awareness through training on secure coding practices, security standards and latest security threats.
- Security Communication - Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
- Programming Skills - Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
- AI Development Tools - Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
- Education & Experience - BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
- Securing SDLC - Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
- Knowledge of Modern AI Security Threats - Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
- Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
- Infrastructure as Code & Cloud - Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1 Heartflow is an Equal Opportunity Employer. We are committed to a work environment that supports, inspires, and respects all individuals and do not discriminate against any employee or applicant because of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law. This policy applies to every aspect of employment at Heartflow, including recruitment, hiring, training, relocation, promotion, and termination. Positions posted for Heartflow are not intended for or open to third party recruiters / agencies. Submission of any unsolicited resumes for these positions will be considered to be free referrals. Heartflow has become aware of a fraud where unknown entities are posing as Heartflow recruiters in an attempt to obtain personal information from individuals as part of our application or job offer process. Before providing any personal information to outside parties, please verify the following: A) all legitimate Heartflow recruiter email addresses end with "@heartflow.com" and B) the position described is found on our careers site at
- ...some of the most cutting edge software/security solutions platforms in the world Why... ...Details RESPONSIBILITIES Perform application security assessments including manual... ...backed workflows with customer product and engineering teams. Integrate security tooling (...SuggestedLong term contractWork at officeLocal area
- ...Application Security Engineer The Application Security Engineer will be responsible for analyzing software code repositories, code designs, processes, and implementation from a security perspective, and work with software development and infrastructure teams to identify...Suggested
- ...Application Security Engineer At Opal, we're building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise...Suggested
$231.9k - $318.25k
...platform where they write and execute arbitrary code. The security surface that comes with that is large, nuanced, and... ...security program have grown with it. We're looking for an Application Security Engineer who combines deep security fundamentals with real engineering...SuggestedShift work$200k - $235k
...Senior Security Application Engineer San Francisco, California, United States BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage. Since...SuggestedFull timeWork at officeWorldwide- ...Responsibilities In this role, you'll build security into every phase of the software development lifecycle for Anthropic's AI systems... ...Create security policies, standards, and educational resources that enable all engineers to be security champions. #J-18808-Ljbffr
- ...Senior Application Security Engineer Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and highly motivated Senior Application Security Engineer to join our team as one of...Hourly payFull timeFlexible hours
$220k - $250k
...headquartered in New York City with offices around the world. To learn more, go to About the Role We’re seeking a Lead Application Security Engineer to help advance Zeta Global’s application and platform security posture through AI-native security practices,...$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...Remote job- ...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Anthropic's Application Security team secures the systems that build, serve, and increasingly are...Full time
- ...$225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A funding, and has...Full time
- ...Position Overview We are seeking a frontend-leaning engineer to help build and scale the user-facing web applications powering Knowtex’s AI-driven clinical... ...intuitive, and performant user interfaces Develop secure and performant APIs and supporting infrastructure...Full timeShift work
- ...Our First Product Security-Focused Engineer Takes high-level direction (e.g., "identify top five security-related gaps for AX") and drives to results. Success looks like a LanceDB platform that follows security-related best practices, and an ongoing partnership with...
- ...like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role We’re hiring a Product Security Engineer to build Collective’s application security program — with AI agents at the center of it from day one. This is not a legacy appsec role where you...Self employmentWork at officeRemote workFlexible hours
- ...next. About the team Airwallex's Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...related to the security of our networks, systems and applications. What you'll be doing Partner with other...Worldwide
$175k - $215k
...looking for someone to make sure it's built securely from the ground up. As part of the... ...ll be building it, working closely with engineering teams, shipping production code,... ...models ~ Production experience with application security tooling (SAST, DAST, SCA) and...Temporary work$208k - $312k
...About the Role: We are looking for a Product Security Engineer to join our security team to drive critical product security initiatives across Vercel’s products and platform. Your core focus will be on threat modeling, open-source software security, secure code review...Work at officeRemote workWork from homeMonday to FridayFlexible hours- ...Product Security Engineer BackOps AI transforms supply-chain operations with agentic AI that automates complex workflows, freeing teams... ...scanning in CI with a triage path engineers actually use. Run application vulnerability management end to end. Find it, prioritize it...Work at officeFlexible hours
- ...Security Research Engineer RunSybil is an AI security startup scaling offensive security services by automating hacker intuition. We're building Sybil: an AI-powered penetration testing product that finds vulnerabilities faster than human hackers. Backed by strong...
$208k - $312k
...Product Security Engineer Hybrid - San Francisco, New York City, London, Berlin About the Role: Traditional product security teams... ...or securing multi-tenant platforms where customer-built applications run on shared infrastructure. Have built systems that auto...Work at officeRemote workWork from homeMonday to FridayFlexible hours$122.9k - $216.3k
The Opportunity Adobe's Security Partnership Product Engineering (SPPE) team is hiring a mid-level engineer to build the AI-powered platforms that help... .... ~ Solid foundation in Secure SDLC practices, application security, and threat modeling. ~ Proficiency in Python...Temporary workLocal areaWorldwide- ...Product Security Engineer Persona is the configurable identity platform built for businesses in a digital-first world. Verifying individuals and organizations is harder — but more important — than ever, with AI enabling fraudsters to launch sophisticated accounts at...Full timeFor contractorsInternshipRelocation package
$188k - $282k
...getting started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you'll be a key technical contributor... ...Have ~5+ years of experience in product security, application security, offensive security, and/or security-focused software...Work experience placement$130k - $215k
...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers... ...and Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs,... ...responsible for building and securing our web applications and services. Your role will involve...Permanent employmentFlexible hours$125k - $160k
...your skills and experience — talk with your recruiter to learn more. Base pay range $125,000.00/yr - $160,000.00/yr Applications Engineer – Industrial Vision & AI Deployment ~50% Overnight Travel About the Opportunity A rapidly growing AI + computer‑vision...Night shift- ...LLM Application EngineerSoftware Guidance & Assistance, Inc., (SGA), is searching for an LLM Application Engineer for a remote full time assignment with one of our premier technology clients... ...into dependable, observable, and secure business processes.Integrate AI solutions...Full timeRemote work
$125k - $160k
...LLM Applications EngineerUncountable is seeking experienced engineers to lead the transformation of our platform into an AI-first R&D ecosystem. We are building the next generation of tools that empower scientists at Fortune 500 companies to accelerate discovery through...$125.64k
...Security Engineer We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder's... ...of a hands-on security team working across Infrastructure, Application, and Enterprise Security where responsibilities sometimes overlap...Full timeWork at officeLocal areaRemote workNight shift$170k - $200k
...Senior Application EngineerGibson Dunn is a leading global law firm, advising clients on significant... ...U.S. offices, the Senior Application Engineer will be responsible for the full... ...portfolio, ensuring reliability, performance, security, and continuous improvement. This role...Contract workWork at officeLocal areaFlexible hours- ...enable life-saving cures also lowers the barrier to creating engineered threats and AI-generated bioweapons. We believe these forces... ...ship on a weekly cadence. What You'll Do Develop the application surface for your area of ownership, including interactive...Live inLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- field applications engineer San Francisco, CA
- technical application engineer San Francisco, CA
- hydraulic application engineer San Francisco, CA
- application engineering manager San Francisco, CA
- junior application support engineer San Francisco, CA
- project application engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- application security engineer San Francisco, CA
- application operations engineer San Francisco, CA
- senior application support engineer San Francisco, CA



