SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer

HeartFlow - San Francisco, CA, United States - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 165,000 - 200,000 / annual

HeartFlow is a publicly traded medical technology company (HTFL) that develops AI-driven solutions for diagnosing and managing coronary artery disease. The flagship product, HeartFlow FFR_CT Analysis, is a non-invasive cardiac test that provides 3D models of coronary arteries to help clinicians assess blood flow blockages. The company has received international recognition, is cleared for use in the US, UK, Europe, Japan, and Canada, and has been used for over 750,000 patients worldwide. You will serve as a Senior Application Security Engineer, partnering with the engineering team to embed security throughout the Software Development Lifecycle (SDLC). This is a hands-on technical role requiring three days per week in the San Francisco office. Key responsibilities include: - Provide hands-on technical guidance to software developers during vulnerability remediation, performing secure code reviews, validating false positives, coaching on remediation strategies, threat modeling products, and executing essential SDLC security activities. - Drive vulnerability identification using SAST, DAST, SCA, and in-house AI tooling; manage external penetration testing. - Support the engineering team on vulnerability management, including risk assessment, remediation planning, and translating security/privacy requirements into technical specifications. - Build security awareness through training on secure coding practices, security standards, and emerging threats. You will work with a talented engineering team on complex technical challenges with direct impact on patient outcomes in a regulated healthcare environment. REQUIREMENTS: - BS in Computer Science or related degree, or relevant certifications with equivalent experience - 5+ years of total experience, with at least 1 year in Application Security or performing security tasks in a development role - Proficiency writing and maintaining code in at least one modern programming language (C++/Python preferred) and at least one scripting language - Comfortable with testing frameworks and CI/CD pipelines - Experience using AI code tools such as Claude Code and GitHub Copilot for development and security testing - Demonstrated contribution to secure SDLC activities including threat modeling, code review, security testing, and vulnerability management - Knowledge of modern AI security threats for both machine learning and generative AI - Ability to reason about risk in complex environments and communicate to technical and non-technical audiences - Experience leading training or speaking internally/externally about security projects valued DESIRABLE QUALIFICATIONS: - Current knowledge of HIPAA, HITRUST, and regulated environment complexities - Experience with Software as a Medical Device (SaMD) - Familiarity with AWS or equivalent cloud providers - Experience with infrastructure-as-code tools (Terraform, Chef, Ansible) - Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar)

Similar roles