Strive Health

Application Security Engineer

Strive Health$108K — $136K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 3+ years experience for Engineer or 5+ years for Senior in information security with Application Security focus.
  • Experience integrating security tools into CI/CD pipelines like SAST and DAST.
  • Proficient in application threat modeling and architecture reviews.
  • Familiar with securing cloud environments and cloud architecture.

Responsibilities

  • Perform threat modeling and establish security baselines for internal and external applications.
  • Collaborate with engineering teams to incorporate security criteria into product requirements and technical plans.
  • Conduct security architecture reviews with a focus on key vulnerabilities and prevention measures.
  • Design and implement application security testing frameworks using tools like SAST and DAST.
  • Manage the vulnerability intake pipeline and coordinate remediation efforts.

Benefits

  • Health, dental, and vision insurance
  • 401(k) plan with company match
  • Flexible work hours and remote work options
  • Professional development opportunities
  • Generous paid time off policy
Full Job Description
What You'll Do

The Application Security Engineer is responsible for embedding application security directly into Strive's product development lifecycle, specifically supporting the deployment of Canvas Medical, patient-facing experiences, and future mobile applications. You will serve as the primary security partner for Product and Engineering, ensuring that applications are built securely from the design phase through to production. Rather than treating security as a late-stage penetration test, you will establish the requirements, review gates, testing frameworks, and remediation operating rhythms necessary to support a secure and compliant development pipeline.

The Day to Day

Security Discovery and Threat Modeling:
  • Perform threat modeling and establish a security baseline for internal environments, patient portals, mobile applications, and integration services.
  • Maintain data-flow and trust-boundary diagrams, assessing identity, operational, and PHI data classifications.

Architecture & Secure Product Development:
  • Collaborate with engineering teams to embed security acceptance criteria into PRDs, technical plans, and Jira stories.
  • Conduct architecture reviews focusing on tenant boundaries, server-side authorization, prevention of IDOR (insecure direct object references), and lateral movement guardrails.
  • Develop and enforce merge request (MR) checklists covering authentication, input validation, secrets management, and cryptography.

Application Security Testing Framework:
  • Design, deploy, and operate application security testing tools including SAST, DAST, Software Composition Analysis (SCA), and container/IaC scanning.
  • Perform authenticated testing of browser workflows and APIs (e.g., using Burp Suite Enterprise).
  • Conduct manual testing for complex vulnerabilities such as privilege escalation, SSRF, and business-logic abuse.

Vulnerability Management & Remediation:
  • Manage the vulnerability intake pipeline, assign severities, and track remediation aligned with internal SLAs.
  • Lead recurring vulnerability review sessions with Security, Product, and Engineering stakeholders.
  • Coordinate external penetration tests, including scoping, vendor selection, and tracking of remediation/retesting.

Compliance & Audit Readiness:
  • Ensure all security requirements, threat models, testing evidence, and remediation documentation align with internal compliance needs (e.g., HITRUST, SOC 2).

Minimum Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 3+ years (Engineer) to 5+ years (Senior) of experience in information security, with a strong focus on Application Security, DevSecOps, or software engineering.
  • Demonstrable experience integrating security tools into CI/CD pipelines (e.g., SAST, DAST, SCA).
  • Experience leading or performing application threat modeling, architecture reviews, and manual security testing.
  • Familiarity with securing cloud environments (SaaS, IaaS, PaaS) and understanding of cloud architecture.
  • Internet Connectivity - Min Speeds: 3.8Mbps/3.0Mbps (up/down): Latency
  • Ability to travel and be onsite to meet business needs.

Preferred Qualifications
  • Experience within the healthcare sector, securing environments that manage PHI and complying with frameworks like HITRUST.
  • Deep expertise in identifying and exploiting vulnerabilities (OWASP Top 10, IDOR, SSRF, authentication bypass).
  • Experience with testing and securing complex API integrations, mobile application releases, and web-based portals.
  • Familiarity with enterprise dynamic testing tools (e.g., Burp Suite Enterprise) and automating security testing against deployed applications.
  • Advanced certifications in application security or information security (e.g., CSSLP, GWAPT, CISSP, CEH).

About You
  • Excellent problem-solving and analytical skills, able to assess complex application security issues and provide practical, developer-friendly solutions.
  • Strong communication and collaboration skills; capable of articulating technical risk to both technical and non-technical stakeholders.
  • Proactive and adaptable, comfortable embedding directly with engineering pods to shift security "left".


Annual Salary Range: $108,500 - $136,000. This position is also eligible for a target annual bonus of 10%

Final compensation will be determined based on location, experience, and qualifications.

About Strive Health

Strive Health is a healthcare company that provides chronic kidney disease (CKD) care and management services. The company offers a comprehensive care model that includes risk identification, early intervention, care coordination, and patient engagement. Strive Health's goal is to improve the quality of life for CKD patients and reduce the overall cost of care. The company was founded in 2018 and is headquartered in Emeryville, California.
Learn more about Strive Health
Size
1,000 employees
Industry
Net Income
-$20 million
Founded
2018
5 Year Trend
+50%
Revenue
$100 million

Similar Jobs

More Jobs at Strive Health

More Information Technology Jobs

Find similar Application Security Engineer jobs: