Avatar for K Health
K Health
Actively Hiring
The first medical app that uses AI to deliver primary care better, faster, and cheaper
  • Top 10% of responders
    K Health is in the top 10% of companies in terms of response time to applications
  • Responds within a week
    Based on past data, K Health usually responds to incoming applications within a week

Senior Security Engineer - Application Security

Posted: 2 days ago• Recruiter recently active
Job Location
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Shannon Curtis
Employee
image

About the job

About the role:

This is an opportunity to join K's critical InfoSec team as a Senior Security Engineer - AppSec and operate with foresight in protecting our infrastructure, applications, cloud security, and customer trust. As a lean team, we span across multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture, or planning and building out net new security solutions. You will have the autonomy to define and implement cutting-edge security solutions across our entire technical ecosystem, ensuring our innovative work remains robust and compliant against evolving global threats. This role is crucial for establishing and maintaining a world-class security posture, particularly within the sensitive and highly regulated healthcare technology space.

What you will do:

  • Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
  • Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
  • Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
  • Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
  • Develop secure coding standards with developer-focused documentation
  • Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
  • Evaluate third party applications, libraries and APIs and integrations for security risk
  • Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.

What we're looking for:

  • 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
  • Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
  • Experience performing manual security testing of modern web applications, APIs and distributed systems
  • Ability to review application architecture and source code for security weaknesses
  • Experience integrating application security tools into modern CI/CD workflows
  • Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
  • Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
  • Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
  • Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.

Bonus: #LI-Hybrid

  • Exploring, partnering and implementing bleeding edge tech not readily available to others.
  • Experience with specific tools and tech K uses including but not limited to: Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma

About the company

K Health company logo

K Health

Actively Hiring
The first medical app that uses AI to deliver primary care better, faster, and cheaper201-500 Employees
Company Size
201-500
Company Type
Startup
Company Type
Healthcare Technology
Company Type
Mobile App
Company Industries
Artificial Intelligence / Machine Learning
  • Top 10% of responders
    K Health is in the top 10% of companies in terms of response time to applications
  • Responds within a week
    Based on past data, K Health usually responds to incoming applications within a week
Learn more about K Health image

Funding

AMOUNT RAISED
$273M
FUNDED OVER
1 round
Round
E
$273000000
Series E - Jan 2021

Perks

Healthcare benefits
Retirement benefits
Parental leave
Equity benefits
Generous vacation
Company meals
Wellness benefits

Similar Jobs

Enigma Technologies company logo
Enigma Technologies
Enigma provides trusted business data built on unparalleled entity resolution
Shef company logo
Shef
Authentic dishes. Homemade. Delivered. Explore who's cooking in your neighborhood
Vise company logo
Vise
Technology-Powered Asset Manager for customized, intelligent investing
Kick Health company logo
Kick Health
The Online Performance Medicine Clinic for Energizing Sleep and Confident Presentations
Enigma Technologies company logo
Enigma Technologies
Enigma provides trusted business data built on unparalleled entity resolution
Brellium company logo
Brellium
Clinical teams use Brellium to ensure patient visits meet payor & clinical standards