SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 145,000 - 180,000 / annual
HeartFlow is a publicly traded medical technology company (HTFL) pioneering AI-driven solutions for coronary artery disease diagnosis and management. The company's flagship product, HeartFlow FFR_CT Analysis, uses cutting-edge AI to provide non-invasive cardiac assessment and has been used for over 500,000 patients worldwide across the US, UK, Europe, Japan, and Canada.
We seek an Application Security Engineer to embed security throughout our Software Development Lifecycle (SDLC). You'll partner closely with engineering teams to ensure security is integral to product development, protecting patients as we build AI-powered healthcare solutions.
Key responsibilities include:
- Provide hands-on technical guidance to developers during vulnerability remediation, performing secure code reviews, validating findings, and coaching on remediation strategies
- Conduct threat modeling and implement secure SDLC practices
- Drive vulnerability identification using SAST, DAST, SCA, and in-house AI tooling; manage external penetration testing
- Support vulnerability management including risk assessment, remediation tracking, and translation of security/privacy requirements into technical specifications
- Build security awareness through training on secure coding, security standards, and emerging threats
You bring 5+ years of total experience with at least 1 year in application security or security-focused development roles. You have a BS in Computer Science or equivalent certifications and relevant experience. You're proficient in modern programming languages (C++/Python preferred) and scripting, comfortable with testing frameworks and CI/CD pipelines, and experienced with AI development tools like Claude Code and GitHub Copilot.
You've contributed to secure SDLC activities including threat modeling, code review, security testing, and vulnerability management. You understand modern AI security threats for both machine learning and generative AI systems.
Standout candidates have healthcare experience (HIPAA, HITRUST, Software as a Medical Device), familiarity with AWS or equivalent cloud platforms, infrastructure-as-code tools (Terraform, Chef, Ansible), and containerization/orchestration technologies (Docker, Kubernetes, GitHub Actions).
This hybrid role requires three days per week in our San Francisco office. You'll work with talented engineers solving complex technical challenges with direct impact on patient outcomes.