SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 200,000 / annual
K Health is seeking a Senior Security Engineer for Application Security to join its InfoSec team. This role operates at the intersection of security architecture and hands-on implementation, protecting K Health's AI-powered virtual care platform used by leading health systems including Mayo Clinic, Cedars-Sinai, and Mass General Brigham.
You will lead the development and implementation of robust application security protocols throughout the Software Development Lifecycle (SDLC). Key responsibilities include partnering with engineering teams to embed security into architecture, design, development, testing, and deployment phases. You'll perform hands-on security testing of web applications, APIs, cloud-native services, and supporting infrastructure.
You will build and improve automated security testing within CI/CD pipelines, including static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing. You'll evaluate the effectiveness of application security tools, improve tooling output quality, and reduce developer friction. Additionally, you'll develop secure coding standards with developer-focused documentation and contribute expertise to vulnerability management, security incidents, and post-incident reviews.
A critical aspect of this role is ensuring adherence to healthcare regulatory and compliance requirements (HIPAA, GDPR, etc.) across all product lines and systems. You'll evaluate third-party applications, libraries, APIs, and integrations for security risk.
Required qualifications include 4+ years of professional experience in application, product, or software security as an individual contributor, or as a software engineer who has pivoted into security. You need strong understanding of application security vulnerabilities and attack techniques (OWASP Top 10, API security risks), experience performing manual security testing of modern web applications and distributed systems, and ability to review application architecture and source code for security weaknesses.
You should have experience integrating application security tools into modern CI/CD workflows, familiarity with SAST, DAST, secrets detection, container security, and IaC scanning. Understanding of authentication, authorization, session management, cryptography, secrets management, and secure API design is essential. Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, and awareness of security implications of AI code development utilities is required. Demonstrated experience researching, establishing, and rolling out enterprise-wide security policies and guidelines is expected.
Bonus experience includes familiarity with tools K Health uses: Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, and Prisma.