Senior Application Security Engineer II
$180k - $205.5kSpringHealth Behavioral Health & Integrated Care
Senior Application Security Engineer II
Remote
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.
Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established SAST, SCA, and DAST capabilities — while helping shape new initiatives such as a Secure AI Development Lifecycle (ADLC). You will work alongside a team of engineers who have laid a strong foundation, bringing your experience to help take these programs to the next level. This is a full-time, fully remote position open to candidates residing within the United States. Occasional travel to our NYC headquarters may be required.
What You'll Do:
- Contribute to the advancement of secure-by-design practices within the team's S-SDLC program, including participation in architecture reviews, design consultations, and security guidance across the development lifecycle.
- Mentor engineers on secure coding practices, AppSec fundamentals, and career growth, fostering a collaborative environment where the team grows stronger together.
- Facilitate the development of an AI-assisted threat modeling program, spanning risk identification, security architecture, and proactive program maturity, enabling the ability to scale threat modeling across the organization.
- Contribute to maturing the team's established SAST, SCA, and DAST programs through rule tuning, coverage improvements, and identifying opportunities to strengthen security controls as the organization scales.
- Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
- Support vulnerability remediation efforts by assessing impact, proposing solutions, and validating fixes in accordance with the team's established remediation workflows.
- Identify and implement process improvements and security automation using languages such as Go, Python, JavaScript, or Ruby, including the integration of AI tooling to improve team workflows and program efficiency.
- Contribute to security assessments of AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, with a focus on risks such as prompt injection, data leakage, and model supply-chain vulnerabilities.
- Contribute to the research, design, and development of a Secure AI Development Lifecycle (ADLC) in accordance with the OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
- Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review, to improve program coverage and team efficiency.
What Success Looks Like:
- Demonstrated improvements to the team's SAST, SCA, and DAST programs through rule tuning, noise reduction, and coverage expansion within the first 90 days.
- Delivery of a documented AI-assisted threat modeling program and foundational ADLC framework, including defined processes, tooling recommendations, and adoption milestones.
- Consistent adherence to team SLAs for vulnerability triage and remediation, with measurable contributions to reducing time-to-remediation for high and critical findings.
- Delivered security automation and AI tooling integrations that produce measurable improvements to program efficiency or engineering team experience.
- Completed security assessments of AI-integrated product features with documented findings, risk ratings, and remediation guidance delivered to engineering teams.
What You'll Bring:
- 7+ years of professional experience in application security or a closely related security engineering discipline, including experience working on complex, ambiguous problem areas independently.
- Hands-on experience with DAST, SAST, and SCA tools, and manual testing techniques (OWASP, SANS Top 25).
- Demonstrated experience securing CI/CD pipelines with commercial and custom-built tooling.
- Experience with IaaS cloud infrastructure (AWS, Azure, or GCP), container technologies, and service-oriented architectures.
- Security automation experience in at least one of: Go, Python, JavaScript, or Ruby.
- Familiarity with AI/ML security concepts — prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
- Working knowledge of AI and LLM tooling (e.g., OpenAI, Anthropic, LangChain, or equivalent) sufficient to assess security risk and integrate into automated workflows.
- Experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
- Strong cross-functional collaboration skills, with experience working alongside engineering, product, and leadership stakeholders to define and advance security priorities and plans.
- Bachelor's degree in Computer Science, Engineering, MIS, IT, or equivalent work experience.
Nice To Have:
- 3+ years of demonstrated experience in security architecture, including designing and reviewing security controls across cloud-based, distributed, or service-oriented systems.
- Experience leading or contributing to the development of a formal threat modeling program, including tooling selection, methodology design, and adoption across engineering teams.
- Hands-on experience evaluating or implementing AI security tooling, including AI-augmented testing, LLM security assessments, or automated risk analysis.
- Experience managing a bug bounty or vulnerability disclosure program.
- Experience in digital health, healthcare technology, or other HIPAA-regulated environments.
The target base salary range for this position is $180,000 - $205,500, and is part of a competitive total rewards package including stock options and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.
Benefits provided by Spring Health:
Note: We have even more benefits than listed here and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.
- Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to One Medical accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer sponsored 401(k) match of up to 2% for retirement planning
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- We offer competitive paid time off policies including vacation, sick leave and company holidays.
- At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to Noom, a weight management program—based in psychology, that's tailored to your unique needs and goals.
- Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses.
- Access to Wellhub, which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
- Access to BrightHorizons, which provides sponsored child care, back-up care, and elder care
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.
Not sure if you meet every requirement? Research shows that women and people from historically underrepresented communities often hesitate to apply for roles unless they meet every qualification compared to other similarly-qualified candidates. At Spring Health, we are committed to fostering a workplace where everyone feels valued, empowered, and supported to Thrive. If this role excite
$200k - $235k
...focused on enabling our clients to securely navigate the digital asset space. With... ...-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our... ...technical controls to meet SOC 2 Type II and GDPR compliance standards. ~...SeniorFull timeWork at officeWorldwide$130.1k - $187k
...About the Role Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection...SuggestedFull time- ...Senior Application Security Engineer Location: Middletown, NJ (F2F Required, Onsite from Day Telecom Experience) Long Term Overview: We are looking for a Senior Application Security Engineer to join our growing team and play a hands-on role in strengthening security...Senior
- ...however, we are looking for someone with a stronger Application Security background. Certifications like DevSecOps and CISSP... .... Overall, the client is looking for a strong Senior Application Security Engineer with DevSecOps Team Lead-level experience . App Sec...Senior
- ...Leading Red Team engagements, the full-time Senior Application Security Engineer will shape an evolving offensive security practice by collaborating with Blue Team members to enhance detection and response, while also educating developers to prevent vulnerabilities and...SeniorFull timeRemote work
- ...Application Security Specialist The Application Security team is responsible for the solutions and processes that secure Vanguard applications... ...(containers, serverless, API, AI/ML). Provide hands-on engineering support for security incidents, threat events,...Senior
- ...Senior Application Security Engineer Tasks: • Perform comprehensive cybersecurity risk analysis, identifying and prioritizing risks specifically related to application security. • Develop, socialize, and implement security strategies to address vulnerabilities...SeniorFlexible hours
$75k
...through technology. Job Description The Application Security program defines, promotes, assures, and... ...secure-by-design software. As a senior technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead...SeniorFull timeWork at officeShift workNight shiftWeekend workAfternoon shift- ...7+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...to meet you! ABOUT THE ROLE We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across...SeniorWork at officeWork from homeVisa sponsorshipWork visa
- ...The Role We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters. This is a hands-on, in-the-weeds engineering role. You will execute the security strategy set by our Director of IT & Information Security and our CTO, with...SeniorWork at office
$192k - $240k
...support you need to grow your career. Engineering at Brex Engineering at Brex is... ...intention. Our teams span Software, Data, Security, and IT, and operate with high... ...become leaders. What you’ll do As a Senior Application Security Engineer, you will focus on finding...SeniorWork experience placementRemote work- ...Come deliver this transformation. About the Role Security patterns that worked 20 years ago don't hold up anymore, especially as AI changes how fast engineering teams ship code. We're looking for an Application Security Engineer who combines real engineering depth...SeniorFull timeInterim roleWork at officeImmediate start3 days per week
$100k - $150k
...Senior Application Security Engineer Credo is seeking a Senior Application Security Engineer to join our Security Team. This role will be responsible for advancing the organization's Secure Software Development Lifecycle (Secure SDLC), identifying and mitigating application...Senior$128k - $181.25k
...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life’s experiences unforgettable. We believe there is extraordinary power in the self-expression. That’s why our family of brands helps customers create products and capture moments...SeniorRemote work$169k - $220k
...lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core...SeniorWork experience placementWork at officeRemote workFlexible hours$150k - $180k
...their careers, contribute meaningfully, and thrive professionally. The Position We are seeking a highly skilled Senior Application Security Engineer to help establish and mature our secure software development and DevSecOps program. This role will serve as the...SeniorFull time$166.9k - $230.9k
...d love to hear from you. The Team: Upstart's Application Security team enables product and engineering teams to build secure products without slowing innovation... ...a positive developer experience. As a Senior Application Security Engineer at Upstart, you will...SeniorCurrently hiringLocal areaRemote workWork from home- ...our customers’ business challenges, Take2 will work as a partner to best resolve client needs. Take2 is hiring a Senior Application Security Engineer. This is a fully remote role. Job Description ~6+ years of Information Technology experience ~3+ years of experience...SeniorFull timeRemote work
$160.3k - $240.5k
...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top... ...of creators and their users. We are seeking a Senior Application Security Engineer with profound expertise in application security. In this...SeniorWork at officeRemote workWorldwide- ...Senior Application Security Engineer The Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Application Security function at CBIZ. As the first dedicated hire in this...Senior
- ...Senior Application Security Engineer Amerisure creates exceptional value for its partners, policyholders, and employees. As a property and casualty insurance company, Amerisure's promise to our partner agencies and policyholders begins with a comprehensive line of...SeniorLocal areaRemote workFlexible hoursShift work
- ...Senior Application Security Engineer Poland The Tripadvisor Group connects people to experiences worth sharing, and aims to be the world's most trusted source for travel and experiences. We leverage our brands, technology, and capabilities to connect our global...SeniorPermanent employmentContract workRemote workWorldwideFlexible hours
$118.65k - $166.1k
...Cyber Defense, Application Security Engineer III Location – Irvine, CA Company Overview Hyundai AutoEver America (HAEA) , the dynamic... ...automotive innovation. What You Will Be Doing The Senior Application Security Engineer plays a key role in...SeniorFull timeWork experience placementLocal area- ...Europe, Japan and Canada, and has been used for more than 750,000 patients worldwide. We are looking for a Senior Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC...SeniorWork at officeLocal areaWorldwideRelocation3 days per week
$109k - $156k
...providing a level of professionalism and service unsurpassed in the lending industry. Position Summary The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled...SeniorMinimum wageWork at officeLocal areaRemote workWork from homeMonday to FridayShift work- ...fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously... ..., together. The Role: Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of...SeniorWork at officeImmediate startRemote workWork from homeWeekend work
- ...through technology. Job Description The Application Security program defines, promotes, assures, and... ...secure-by-design software. As a senior technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead...SeniorFull timeWork at officeShift workNight shiftWeekend workAfternoon shift
- ...Senior Application Security Engineer Intapp is growing our application security team and is looking for a Senior Application Security Engineer. You'll focus on a subset of our products to understand them deeply and help development teams build products that are secure...SeniorLocal areaRemote workHome office
$190k - $237k
...and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and...SeniorRemote workWorldwideFlexible hours$109.5k
..., ( Facebook, Instagram ( , X ( and YouTube. ( Job Description Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software development...SeniorLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Application Security Engineer II. Be the first to apply!
- cnc applications engineer United States
- senior application support engineer United States
- technical application engineer United States
- application performance engineer United States
- project application engineer United States
- application system engineer United States
- application engineer United States
- hydraulic application engineer United States
- senior application security engineer United States
- application security engineer United States


