SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 108,500 - 136,000 / annual
Strive Health is transforming chronic disease management by identifying risk earlier, coordinating care, and supporting patients through their health journey. The Application Security Engineer will embed security directly into Strive's product development lifecycle, serving as the primary security partner for Product and Engineering teams.
You will be responsible for establishing security requirements, review gates, testing frameworks, and remediation operating rhythms across the development pipeline. Your focus will be on Canvas Medical, patient-facing applications, and future mobile applications—ensuring they are built securely from design through production rather than treating security as a late-stage penetration test.
Day-to-day responsibilities include:
- Conducting threat modeling and security architecture reviews for new features and systems
- Developing and maintaining secure coding standards and guidelines tailored to Strive's tech stack
- Performing code reviews and security assessments, identifying vulnerabilities and recommending fixes
- Designing and implementing automated security testing within CI/CD pipelines (SAST, dependency scanning, etc.)
- Collaborating with engineering teams to remediate findings and track remediation progress
- Supporting compliance efforts (HIPAA, SOC 2) by ensuring applications meet regulatory requirements
- Staying current with application security trends, vulnerabilities, and best practices
- Mentoring engineers on secure development practices and shifting security left
You will work in a hybrid environment with flexibility to work from home while fulfilling in-person needs at the office. Strive offers comprehensive benefits including medical, dental, and vision insurance, 401(k) with employer match, paid time off, professional development stipend, and wellness programs.
REQUIREMENTS:
- 5+ years of application security experience, with demonstrated expertise in secure code review, threat modeling, and vulnerability assessment
- Strong understanding of OWASP Top 10, secure coding practices, and common application vulnerabilities
- Experience with security testing tools (SAST, DAST, dependency scanning) and CI/CD integration
- Proficiency in at least one modern programming language (Python, Java, JavaScript, Go, etc.)
- Knowledge of healthcare compliance requirements (HIPAA, HITRUST) is a plus
- Excellent problem-solving and analytical skills; able to assess complex security issues and provide practical, developer-friendly solutions
- Strong communication and collaboration skills; capable of articulating technical risk to both technical and non-technical stakeholders
- Proactive and adaptable; comfortable embedding directly with engineering teams to shift security left