Senior Application Security Engineer II
$180k - $205.5kSpring Health
Role Description
Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established SAST, SCA, and DAST capabilities — while helping shape new initiatives such as a Secure AI Development Lifecycle (ADLC). You will work alongside a team of engineers who have laid a strong foundation, bringing your experience to help take these programs to the next level.
This is a full-time, fully remote position open to candidates residing within the United States. Occasional travel to our NYC headquarters may be required.
What you’ll do:
- Contribute to the advancement of secure-by-design practices within the team’s S-SDLC program, including participation in architecture reviews, design consultations, and security guidance across the development lifecycle.
- Mentor engineers on secure coding practices, AppSec fundamentals, and career growth, fostering a collaborative environment where the team grows stronger together.
- Facilitate the development of an AI-assisted threat modeling program, spanning risk identification, security architecture, and proactive program maturity, enabling the ability to scale threat modeling across the organization.
- Contribute to maturing the team’s established SAST, SCA, and DAST programs through rule tuning, coverage improvements, and identifying opportunities to strengthen security controls as the organization scales.
- Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
- Support vulnerability remediation efforts by assessing impact, proposing solutions, and validating fixes in accordance with the team’s established remediation workflows.
- Identify and implement process improvements and security automation using languages such as Go, Python, JavaScript, or Ruby, including the integration of AI tooling to improve team workflows and program efficiency.
- Contribute to security assessments of AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, with a focus on risks such as prompt injection, data leakage, and model supply-chain vulnerabilities.
- Contribute to the research, design, and development of a Secure AI Development Lifecycle (ADLC) in accordance with the OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
- Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review, to improve program coverage and team efficiency.
What success looks like:
- Demonstrated improvements to the team’s SAST, SCA, and DAST programs through rule tuning, noise reduction, and coverage expansion within the first 90 days.
- Delivery of a documented AI-assisted threat modeling program and foundational ADLC framework, including defined processes, tooling recommendations, and adoption milestones.
- Consistent adherence to team SLAs for vulnerability triage and remediation, with measurable contributions to reducing time-to-remediation for high and critical findings.
- Delivered security automation and AI tooling integrations that produce measurable improvements to program efficiency or engineering team experience.
- Completed security assessments of AI-integrated product features with documented findings, risk ratings, and remediation guidance delivered to engineering teams.
Qualifications
- 7+ years of professional experience in application security or a closely related security engineering discipline, including experience working on complex, ambiguous problem areas independently.
- Hands-on experience with DAST, SAST, and SCA tools, and manual testing techniques (OWASP, SANS Top 25).
- Demonstrated experience securing CI/CD pipelines with commercial and custom-built tooling.
- Experience with IaaS cloud infrastructure (AWS, Azure, or GCP), container technologies, and service-oriented architectures.
- Security automation experience in at least one of: Go, Python, JavaScript, or Ruby.
- Familiarity with AI/ML security concepts — prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
- Working knowledge of AI and LLM tooling (e.g., OpenAI, Anthropic, LangChain, or equivalent) sufficient to assess security risk and integrate into automated workflows.
- Experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
- Strong cross-functional collaboration skills, with experience working alongside engineering, product, and leadership stakeholders to define and advance security priorities and plans.
- Bachelor’s degree in Computer Science, Engineering, MIS, IT, or equivalent work experience.
Nice to have:
- 3+ years of demonstrated experience in security architecture, including designing and reviewing security controls across cloud-based, distributed, or service-oriented systems.
- Experience leading or contributing to the development of a formal threat modeling program, including tooling selection, methodology design, and adoption across engineering teams.
- Hands-on experience evaluating or implementing AI security tooling, including AI-augmented testing, LLM security assessments, or automated risk analysis.
- Experience managing a bug bounty or vulnerability disclosure program.
- Experience in digital health, healthcare technology, or other HIPAA-regulated environments.
Benefits
- Health, Dental, Vision benefits start on your first day at Spring.
- Employer sponsored 401(k) match of up to 2% for retirement planning.
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- Competitive paid time off policies including vacation, sick leave and company holidays.
- At 6 months tenure with Spring, parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to Noom, a weight management program tailored to your unique needs and goals.
- Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses.
- Access to Wellhub, which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription.
- Access to BrightHorizons, which provides sponsored child care, back-up care, and elder care.
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.
$60 - $62 per hour
...experience — talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days...SeniorContract workH1bRemote work- ...Senior Application Security Engineer Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security...SeniorWork at officeRemote work
- ...ServiceNow's leading workflow automation with Moveworks' Reasoning Engine and natural language capabilities, we deliver the AI... ...everyone. The Role Are you interested in being part of Application Security efforts at Moveworks? Do you enjoy collaborating closely with...SeniorWork at officeRemote workFlexible hours
$150k - $196k
Description Senior AppSec Engineer Location: Remote, USA Employment Type: Full-Time Benefits Offered: Vision, Medical, Life... ..., job-related criteria. Summary The Senior Application Security Engineer joins the Information Security team and plays a...SeniorFull timeTemporary workRemote work$120k
...Job Posting Title: Senior Application Security Engineer ---- Hiring Department: Dell Medical School ---- Position Open To: All Applicants ---- Weekly Scheduled Hours: 40 ---- FLSA Status: Exempt from FLSA ---- Earliest Start...SeniorFor contractorsWork at officeImmediate start$111k - $144.4k
...Sr. Application Security Engineer The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying...SeniorTemporary workWork experience placementRemote work$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...SeniorFull timeFlexible hours$77.24k - $130.49k
...doing extraordinary things. As the Application Engineer, you will provides advanced technical application... ...SHOULD HAVE AS AN APPLICATION ENGINEER II ~3-5 years of relevant work... ...Health & Family Support Financial Security Learning & Development Rewards &...SeniorWork experience placementWork at officeWorldwide$145k - $162k
Role Description The Senior Application Engineer II is responsible for developing a wide range of Ignition applications and solutions. They will develop smaller applications and solutions independently, and contribute to larger team projects as well. The Senior Application...SeniorFull time$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management...SeniorFull timeWork experience placement$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...SeniorFull timeLocal areaImmediate start$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...SeniorFull timeTemporary work- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...SeniorFull timeFlexible hours
$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...code side by side at high velocity. As a Senior AI Application Security Engineer, you...SeniorFull timeRemote work- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...SeniorFull timeRemote work
$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...SeniorFull timeWork at officeRemote workWeekend work- ...Job Description Job Description Senior Application Security Engineer Canopy, South Jordan, UT About Us Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, powerful software for accounting firms. We're on a mission to help accountants...SeniorRemote work
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...SeniorFull timeFlexible hours- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...SeniorFull timeRemote workFlexible hours
$130k - $160k
...information at scale across 75+ health systems and millions of patient encounters. Security is not a layer we add at the end; it is built into how we work. As a Senior Application Security Engineer, you will own the application security practice at Fabric, partnering...SeniorFull time$150k - $196k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SeniorRemote jobFull timeTemporary work$180k - $210k
...transforms the home buying and selling experience into a simple, secure, and enjoyable process. Our SMB and Enterprise products... ...every year. WHAT YOU'LL WORK ON We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a...SeniorFull timeWork at officeRemote workFlexible hours$120k - $258.5k
...Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn... ...we build with AI. You’ll report to the Senior Manager of Application Security and partner closely with product engineering and DevOps, alongside our security peers...SeniorFull time- ...working with a healthcare technology organization seeking a Senior Application Support Engineer to support and maintain critical production systems that... ...systems built with C#/.NET, React, SQL Server/Azure SQL, IIS, and Azure services Perform advanced SQL troubleshooting,...SeniorPermanent employmentWork from home
$77.96k - $109.34k
...work location, balancing what your work requires. As an Application Engineer II at Trane Commercial Systems, you will be responsible for... ...factors. The actual compensation will depend on elements such as seniority, merit, geographic location, education, experience, travel...Hourly payWork experience placementLocal areaWork from home- ...AVL Test Systems Inc offers a job in the United States (US) as Application Engineer II AVL Test Systems Inc. is looking for an Application Engineer II to join the Plymouth, Michigan team. This position will support AVL’s testbed commissioning activities, including...Full timeContract workWork visa
$85k - $105k
...Application Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and...Full timeH1bLocal areaImmediate startRemote workVisa sponsorship$220k - $320k
Job Title: Lead Application Security Engineer Job Location: Remote in USA & Canada (offices in SF, NY, and Austin) Salary: $220K - $320K Visa... ...candidates with fast growth, impact, and lead role experience. Seniority Minimum of 6 years of experience as a security engineer...Hourly payPermanent employmentFull timeTemporary workWork experience placementH1bLocal areaRemote workVisa sponsorship$95.3k - $158.8k
...on site in the Raleigh N.C. office 2-3 days a week. Senior Security Engineer II - Compliance Automation & Controls About Us LexisNexis... ...or adjustment, please let us know by completing our Applicant Request Support Form or please contact (***) ***-****....SeniorWork at officeLocal areaRemote workFlexible hours2 days per week3 days per week- ...About the role As a Security Application Engineer, you will play a key role in embedding security, compliance, and reliability into our IoT cloud applications across their full lifecycle. You combine hands‑on security engineering with process ownership and regulatory awareness...Permanent employmentContract workWork from home2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer II. Be the first to apply!
- application support engineer Remote
- senior application security engineer Remote
- senior application support engineer Remote
- cnc applications engineer Remote
- application engineering manager Remote
- network applications engineer Remote
- application engineer Remote
- application security engineer Remote
- application performance engineer Remote
- field applications engineer Remote











