4+ years in application, product, or software security as an individual contributor or transitioning from software engineering
Strong knowledge of OWASP Top 10 and API security vulnerabilities
Experience with manual security testing of web applications and APIs
Ability to assess application architecture and source code for security issues
Skills in integrating security tools into CI/CD workflows
Familiarity with security testing methods like static and dynamic analysis
Expertise in cloud technologies (AWS, GCP, Azure) and modern programming languages
Responsibilities
Lead the development of application security protocols in the SDLC
Collaborate with engineering teams to embed security in the development process
Conduct hands-on security assessments of web applications and cloud services
Enhance automated security testing within CI/CD practices
Assess application security tool effectiveness and reduce false positives
Craft secure coding standards with developer-focused documentation
Contribute to vulnerability management and post-incident reviews
Benefits
Opportunity for autonomy in defining security solutions
Work in a lean and collaborative team environment covering multiple security domains
Engage with innovative technology in a highly regulated healthcare sector
Exposure to cutting-edge security tools and practices
Professional development in a mission-critical security role
Full Job Description
About the role:This is an opportunity to join K's critical InfoSec team as a Senior Security Engineer - AppSec and operate with foresight in protecting our infrastructure, applications, cloud security, and customer trust. As a lean team, we span across multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture, or planning and building out net new security solutions. You will have the autonomy to define and implement cutting-edge security solutions across our entire technical ecosystem, ensuring our innovative work remains robust and compliant against evolving global threats. This role is crucial for establishing and maintaining a world-class security posture, particularly within the sensitive and highly regulated healthcare technology space.
What you will do:
Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
Develop secure coding standards with developer-focused documentation
Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
Evaluate third party applications, libraries and APIs and integrations for security risk
Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.
What we're looking for:
4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
Experience performing manual security testing of modern web applications, APIs and distributed systems
Ability to review application architecture and source code for security weaknesses
Experience integrating application security tools into modern CI/CD workflows
Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.
Bonus: #LI-Hybrid
Exploring, partnering and implementing bleeding edge tech not readily available to others.
Experience with specific tools and tech K uses including but not limited to: Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma
Compensation:
$150,000-$200,000 USD
About K Health
K Health is a healthcare company that uses AI and machine learning to provide affordable and accessible primary care to patients. The company's app allows users to input their symptoms and receive a diagnosis and treatment plan from a licensed physician within minutes. K Health also offers virtual visits with doctors and prescription delivery services. The company was founded in 2016 and is headquartered in New York City.