Elation Health

Associate Application Security Engineer

Elation Health$80K — $100K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience securing web applications and APIs with knowledge of OWASP Top 10 vulnerabilities
  • Hands-on experience with various application security tools such as SAST, DAST, and IaC/container scanning
  • Strong communication skills for explaining security concepts to various audiences
  • Familiarity with secure SDLC practices like threat modeling and vulnerability management
  • Proven ability to collaborate with product and engineering teams to drive security efforts
  • Genuine enthusiasm for technology and system security

Responsibilities

  • Assist in security design and implementation reviews for web applications, APIs, and backend services
  • Monitor and remediate security findings from various tooling
  • Get acquainted with company security technologies and processes
  • Collaborate with feature teams to assess and resolve security vulnerabilities
  • Implement enterprise security controls for ongoing observability
  • Support compliance audits by collecting evidence
  • Review and triage security alerts independently

Benefits

  • Inclusive company culture that values diverse backgrounds
  • Remote work flexibility across the US, Canada, and New Zealand
  • Opportunities for personal and professional growth
  • Encouragement for applicants from underrepresented communities
  • Support for interview accommodations to promote comfort and accessibility
Full Job Description

As we continue to grow, we are investing in application security to help keep our web
applications, APIs, and patient-facing experiences secure by design.

If you're excited about securing tools that help doctors and patients - and you enjoy making the
secure path the easiest path for engineers - we want to hear from you, even if you don't check
every box below!

What you'll do in your first 60 days:
  • Assist with secure design and implementation reviews for new and existing features across web applications, APIs, and backend services.
  • Monitor, triage, and help remediate findings from security tooling.
  • Get familiar with our security technologies and processes
  • Work with feature teams to understand exploitability, prioritize fixes, and track closure of vulnerabilities in alignment with internal SLAs.
  • Implement an enterprise security control and configure it for long-term observability.

Success at 6-12 months looks like:
  • You're assisting in applying key application security processes
  • You're helping shape technical direction for secure, AI-native, product-critical services handling sensitive data
  • You're supporting evidence collection for compliance audits
  • You've built strong partnerships with product, support, infrastructure, and IT to help identify and triage vulnerabilities and quickly resolve issues
  • The security improvements you've implemented are measurably reducing risk
  • You're independently reviewing and triaging security alerts
How we work: As a member of the team, you'll contribute to the development of secure patterns
and tooling by identifying, triaging, and tracking vulnerabilities, while also independently
reviewing security alerts and supporting our incident response process to ensure security events
are resolved quickly and safely.

WHAT WE'RE LOOKING FOR

Essential:
  • Experience securing web applications and APIs, including a strong grasp of common vulnerabilities (e.g., OWASP Top 10) and practical mitigations
  • Hands-on experience with application security tooling (e.g., SAST, SCA, DAST, IaC/container scanning) and/or observability for security-relevant signals
  • Ability to communicate complex security and technical problems clearly to both technical and non-technical audiences
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Track record of delivering high-quality, pragmatic security outcomes in collaboration with product and engineering teams
  • Enthusiasm and interest in technology in general and securing systems

Valued but not required:
  • Exposure to building or securing systems with AI/LLMs (e.g., OpenAI, Anthropic)
  • Familiarity with OAuth2/OIDC, SSO, secure API design, and multi-tenant SaaS architectures.
  • Experience with coding languages such as Python and JavaScript
  • Hands-on experience with security monitoring tooling (e.g., SIEM, IPS, WAF, SASE, Network Vulnerability Scanning) and/or observability for security-relevant signals
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Knowledge of US healthcare industry, PHI/PII protection, and health tech
EVERYONE IS WELCOME

We're committed to building a diverse and inclusive engineering and security team. Please don't
see everything in this post as a "must have" - if you're excited about this role but don't check
every box, we still want to hear from you.

We especially encourage applications from women, people of color, the LGBTQ+ community,
people with disabilities, neurodivergent people, parents, carers and people from lower socio-
economic backgrounds. If you have any requirements or accommodations that would help you
interview or work comfortably, please let us know.

Our engineering team is fully remote and brings diverse backgrounds and experiences. This role
is open to candidates in the US, Canada, and New Zealand.

Salary: $80,000 - 100,000k/yr USD

About Elation Health

Elation Health is a healthcare technology company dedicated to improving the physician-patient relationship. The company provides a cloud-based electronic health record (EHR) platform for doctors and patients. The platform is designed to help physicians provide better care to their patients by streamlining workflows, reducing administrative tasks, and improving communication. Elation Health's platform is used by thousands of physicians across the United States. The company was founded in 2010 and is headquartered in San Francisco, California.
Learn more about Elation Health
Size
200 employees
Industry
Founded
2008

Similar Jobs

More Jobs at Elation Health

More Information Technology Jobs

Find similar Associate Application Security Engineer jobs: