Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer II

$180k - $205.5k

SpringHealth Behavioral Health & Integrated Care

Senior Application Security Engineer II

Remote

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established SAST, SCA, and DAST capabilities — while helping shape new initiatives such as a Secure AI Development Lifecycle (ADLC). You will work alongside a team of engineers who have laid a strong foundation, bringing your experience to help take these programs to the next level. This is a full-time, fully remote position open to candidates residing within the United States. Occasional travel to our NYC headquarters may be required.

What You'll Do:

  • Contribute to the advancement of secure-by-design practices within the team's S-SDLC program, including participation in architecture reviews, design consultations, and security guidance across the development lifecycle.
  • Mentor engineers on secure coding practices, AppSec fundamentals, and career growth, fostering a collaborative environment where the team grows stronger together.
  • Facilitate the development of an AI-assisted threat modeling program, spanning risk identification, security architecture, and proactive program maturity, enabling the ability to scale threat modeling across the organization.
  • Contribute to maturing the team's established SAST, SCA, and DAST programs through rule tuning, coverage improvements, and identifying opportunities to strengthen security controls as the organization scales.
  • Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
  • Support vulnerability remediation efforts by assessing impact, proposing solutions, and validating fixes in accordance with the team's established remediation workflows.
  • Identify and implement process improvements and security automation using languages such as Go, Python, JavaScript, or Ruby, including the integration of AI tooling to improve team workflows and program efficiency.
  • Contribute to security assessments of AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, with a focus on risks such as prompt injection, data leakage, and model supply-chain vulnerabilities.
  • Contribute to the research, design, and development of a Secure AI Development Lifecycle (ADLC) in accordance with the OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
  • Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review, to improve program coverage and team efficiency.

What Success Looks Like:

  • Demonstrated improvements to the team's SAST, SCA, and DAST programs through rule tuning, noise reduction, and coverage expansion within the first 90 days.
  • Delivery of a documented AI-assisted threat modeling program and foundational ADLC framework, including defined processes, tooling recommendations, and adoption milestones.
  • Consistent adherence to team SLAs for vulnerability triage and remediation, with measurable contributions to reducing time-to-remediation for high and critical findings.
  • Delivered security automation and AI tooling integrations that produce measurable improvements to program efficiency or engineering team experience.
  • Completed security assessments of AI-integrated product features with documented findings, risk ratings, and remediation guidance delivered to engineering teams.

What You'll Bring:

  • 7+ years of professional experience in application security or a closely related security engineering discipline, including experience working on complex, ambiguous problem areas independently.
  • Hands-on experience with DAST, SAST, and SCA tools, and manual testing techniques (OWASP, SANS Top 25).
  • Demonstrated experience securing CI/CD pipelines with commercial and custom-built tooling.
  • Experience with IaaS cloud infrastructure (AWS, Azure, or GCP), container technologies, and service-oriented architectures.
  • Security automation experience in at least one of: Go, Python, JavaScript, or Ruby.
  • Familiarity with AI/ML security concepts — prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
  • Working knowledge of AI and LLM tooling (e.g., OpenAI, Anthropic, LangChain, or equivalent) sufficient to assess security risk and integrate into automated workflows.
  • Experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
  • Strong cross-functional collaboration skills, with experience working alongside engineering, product, and leadership stakeholders to define and advance security priorities and plans.
  • Bachelor's degree in Computer Science, Engineering, MIS, IT, or equivalent work experience.

Nice To Have:

  • 3+ years of demonstrated experience in security architecture, including designing and reviewing security controls across cloud-based, distributed, or service-oriented systems.
  • Experience leading or contributing to the development of a formal threat modeling program, including tooling selection, methodology design, and adoption across engineering teams.
  • Hands-on experience evaluating or implementing AI security tooling, including AI-augmented testing, LLM security assessments, or automated risk analysis.
  • Experience managing a bug bounty or vulnerability disclosure program.
  • Experience in digital health, healthcare technology, or other HIPAA-regulated environments.

The target base salary range for this position is $180,000 - $205,500, and is part of a competitive total rewards package including stock options and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.

Benefits provided by Spring Health:

Note: We have even more benefits than listed here and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.

  • Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to One Medical accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
  • Employer sponsored 401(k) match of up to 2% for retirement planning
  • A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
  • We offer competitive paid time off policies including vacation, sick leave and company holidays.
  • At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
  • Access to Noom, a weight management program—based in psychology, that's tailored to your unique needs and goals.
  • Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses.
  • Access to Wellhub, which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
  • Access to BrightHorizons, which provides sponsored child care, back-up care, and elder care
  • Up to $1,000 Professional Development Reimbursement a year.
  • $200 per year donation matching to support your favorite causes.

Not sure if you meet every requirement? Research shows that women and people from historically underrepresented communities often hesitate to apply for roles unless they meet every qualification compared to other similarly-qualified candidates. At Spring Health, we are committed to fostering a workplace where everyone feels valued, empowered, and supported to Thrive. If this role excite

Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer II in United States vacancy
  • $200k - $235k

     ...Senior Security Application EngineerSan Francisco, California, United StatesBitGo is the leading infrastructure...  ...seeking a Senior Application Security Engineer to lead the technical execution of our...  ...technical controls to meet SOC 2 Type II and GDPR compliance standards.Deep... 
    Senior
    Full time
    Work at office
    Worldwide

    BitGo, Inc.

    San Francisco, CA
    3 days ago
  • $157k - $216k

     ...the next generation of our Application Security capability, a continuous, AI...  ...defense program built for a SaaS engineering organization where AI agents...  ...side at high velocity. As a Senior AI Application Security...  ...familiarity with SOC 2 Type II, ISO 27001:2022, ISO 42001,... 
    Senior
    Contract work
    Local area
    Remote work

    AlphaSense, Inc.

    United States
    23 hours ago
  •  ...States Government Space Technology Export Regulations, the applicant must be a U.S. citizen, lawful permanent resident of the...  ...to join our team.We are looking to add several Senior Applications Engineer II to our rapidly growing customer-facing team. In this position... 
    Senior
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Local area

    CesiumAstro

    Austin, TX
    2 days ago
  • $117.6k - $176.4k

    Sr. Application Engineer II“The Protection, Controls & Automation (PCA) group of Digital power is the engineering entity of Schneider Electric...  ...team:Care for Yourself and Your Family. We ensure you feel secure with benefits that help you and your family thrive: medical... 
    Senior
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    Schneider Electric

    Nashville, TN
    2 days ago
  • Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends... 
    Senior
    Full time
    Flexible hours

    Apollo.io

    Remote
    a month ago
  • $130.1k - $187k

    Role Description Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform against threats like prompt injection at production scale. This is an individual contributor role that blends deep application... 
    Full time

    Abnormal

    Remote
    24 days ago
  • $115k - $150k

    A technology company in defense and space is seeking a Senior Applications Engineer II in Denver. This role requires at least 7 years of technical product experience, guiding customers in using advanced RF and embedded software solutions. Stellar communication skills are... 
    Senior

    CesiumAstro

    Denver, CO
    3 days ago
  •  ...against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed...  ..., or disability. Envision yourself at BarracudaAs a Senior Application Security Engineer, you’ll help shape the future of our AppSec program.... 
    Senior
    Worldwide
    Flexible hours

    Barracuda

    Alpharetta, GA
    23 hours ago
  •  ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web... 
    Senior
    Full time

    Tempus

    Chicago, IL
    2 days ago
  • Job DescriptionSenior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate... 
    Senior

    Infosys Technologies

    Wisconsin
    1 day ago
  • $90k - $180k

     ...operational health of ASPM, SSPM, and related security platforms.Partner with Application Security teams to align Product Security tooling...  ...positions may also include : - StockSummaryAs a Senior Application Security Engineer at Walmart, you will provide critical security... 
    Senior
    Full time
    Temporary work
    Part time

    Walmart

    Bentonville, AR
    2 days ago
  •  ...Written Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Senior
    Full time
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Insurance Company

    Farmington Hills, MI
    2 days ago
  • $175k - $215k

     ...enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives....  ...intelligence. Learn more at starburst.ai.About the roleAs our Senior Application Security Engineer, you'll be the technical owner of application and... 
    Senior
    Local area
    Flexible hours
    Shift work

    Starburst Data

    Boston, MA
    2 days ago
  • Phoenix, Arizona100% RemoteFull Time$160k - $225kA GPU Cloud company startup is looking to bring on a hands on a Senior to Staff Application Security Engineer to build out their application security program from the ground up. You'll work on their core platform, finding... 
    Senior
    Full time

    Motion Recruitment

    Phoenix, AZ
    2 days ago
  • $160.3k - $240.5k

     ...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top...  ...millions of creators and their users.We are seeking a Senior Application Security Engineer with profound expertise in application security. In this... 
    Senior
    Full time
    Work at office
    Remote work
    Worldwide

    Unity Technologies

    Texas
    2 days ago
  •  ...an organization, both internally and externallyAbility to travel as required by business and on-call availabilityThe Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the... 
    Senior

    CBIZ

    Independence, OH
    4 days ago
  • $111k - $144.4k

    Remote - US / Reno, NVAdministration - Enterprise Information Security /Full-Time /RemoteThe Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    23 hours ago
  • $170k - $235k

     ...with the ultimate goal of enabling human life on Mars.SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets...  ..., applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (... 
    Senior
    Permanent employment
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours
    Weekend work

    SpaceX

    Redmond, WA
    2 days ago
  •  ...Western Governors University seeks an Application Security Engineer to strengthen security across applications and systems. You will review code, guide remediation, and shape security policies throughout the software lifecycle. You will build and maintain security tooling... 
    Senior

    Western Governors University

    Salt Lake City, UT
    1 day ago
  • Job Title The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may...
    Senior
    Remote work

    PegaSys Protocol Engineering

    United States
    1 day ago
  • $125k - $160k

     ...0.00 - $160,000.00 / Year Other Compensation Annual Performance Bonus Eligible Job Category Cybersecurity, Application Security, Security Engineering Relocation Expense Covered No Employee Type FT Exempt Travel 5% Manage Others No Contact Information... 
    Senior
    Remote work
    Relocation

    BOLD PENGUIN

    United States
    3 days ago
  •  ...~6-8+ years of experience in Application Security, Product Security, or DevOps with a strong security focus. ~ Extensive hands-on experience with SAST, SCA, DAST , IaC scanning, and integrating security tools into modern CI/CD pipelines. ~ Proven ability to... 
    Senior
    Remote work

    Saxon Global

    United States
    4 days ago
  •  ...To enhance application security practices, the full-time Senior Application Security Engineer will design, implement, and support application security capabilities within the Software Development Lifecycles (SDLCs) while working remotely in the US. Key responsibilities... 
    Senior
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...our customers’ business challenges, Take2 will work as a partner to best resolve client needs. Take2 is hiring a Senior Application Security Engineer. This is a fully remote role. Job Description ~6+ years of Information Technology experience ~3+ years of experience... 
    Senior
    Full time
    Remote work

    Take2 Consulting LLC

    McLean, VA
    2 days ago
  •  ...Senior Application Security Engineer Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation... 
    Senior
    Remote work

    InterSources

    United States
    1 day ago
  •  ...Senior Application Security Engineer Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across... 
    Senior
    Work at office
    Remote work
    Work from home
    Weekend work

    Monarch Money

    United States
    4 days ago
  •  ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global... 
    Senior
    Permanent employment
    Contract work
    Remote work
    Worldwide
    Flexible hours

    TripAdvisor

    United States
    1 day ago
  •  ...Senior Application Security Engineer Intapp is growing our application security team and is looking for a Senior Application Security Engineer. You'll focus on a subset of our products to understand them deeply and help development teams build products that are secure... 
    Senior
    Local area
    Remote work
    Home office

    Intapp

    United States
    23 hours ago
  • $169k - $220k

     ...Senior Application Security Engineer Remote - USA At Counterpart Health, we are transforming healthcare and improving patient care with our innovative primary care tool, Counterpart Assistant. By supporting Primary Care Physicians (PCPs), we are able to deliver... 
    Senior
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Clover Health

    United States
    4 days ago
  • $325k - $405k

    A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience... 
    Senior
    Remote job

    Jobleads-US

    San Francisco, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer II. Be the first to apply!