BetterHelp

Senior Security Engineer, Applications

BetterHelp$130K — $185K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in web application security
  • Strong experience with code review and security architecture
  • Experience in full-stack projects and discovering web vulnerabilities
  • Proficient with tools like Burp Suite for pentesting
  • Basic understanding of networking concepts
  • Able to articulate complex ideas to diverse audiences
  • Knowledge of OWASP Top 10 security risks

Responsibilities

  • Collaborate with a passionate and nimble security team
  • Conduct thorough vulnerability triage and implement fixes
  • Review code for secure coding practices
  • Evaluate new features for security design
  • Work across teams to ensure long-term security success
  • Develop preventative measures and generate security alerts
  • Investigate issues deeply to find root causes and solutions

Benefits

  • Remote work with company-sponsored in-person bonding activities
  • Holistic perks, including free therapy and wellness programs
  • Excellent health, dental, and vision coverage
  • 401k with employer matching contributions
  • Opportunity to create impactful products
  • Access to any tools or hardware for productivity
  • Supportive community of colleagues
Full Job Description
What are we looking for?

We are looking for a motivated Application Security Engineer who is looking to help build the maturity of our Application Security Team while growing their own security skill set. Our team prioritizes the full lifecycle of security triage: identifying vulnerabilities, reproducing exploits, meticulous code analysis, and crafting production-ready fixes. We are looking for an engineer with good attention to detail, the ability to learn quickly and pick up new skills independently, and a get-things-done attitude with eagerness to build something awesome!
What will you do?
  • Work with a nimble passionate security team, collaborating with development and product.
  • Conduct vulnerability triage: handle internal and external vulnerability reports, and more importantly: go beyond investigating and write fixes yourself.
  • Review code and help make decisions about secure coding decisions.
  • Review new product features to ensure they are designed with security in mind
  • Collaborate with other developers and teams for long term security success.
  • Code solutions for preventative measures and generating alerts.
  • Use your detective work to get to the AH-HA! moment when you find and replicate the root cause of an issue and figure out how to fix it.
  • You will care and be involved in our product, mission, and success - way beyond checking off tasks.
What will you NOT do?
  • You will NOT worry about "runway", "cash left", or "how much time we have until the next round". We have the startup DNA but we're fully backed and funded, all the way to success.
  • You will NOT be confined to your "job". You will get involved in product, marketing, business strategy, and almost everything we do.
  • You will NOT be bogged down by office politics, ego, or bad attitude. Only positive, pleasure-to-work-with people are allowed here!
  • You will NOT get yourself burned out. We work hard but we believe in maintaining a sustainable work/life balance. Really.
Can I work remotely?

Yes. We operate on PST and candidates in any time zone are welcome to apply. We ask employees to travel to our San Jose, CA office up to three times per year plus one company-wide offsite to collaborate in person and strengthen working relationships. Travel expenses are covered and reasonable accommodations are made for those under unique circumstances who cannot travel.
What technologies will you work with?

Our application uses a combination of well established and more recent technologies, always innovating, always experimenting. Our current tech stack is:
  • Backend: PHP/Laravel, MySQL, Docker, AWS (SQS, ElastiCache, RDS)
  • Frontend: React, Nextjs, Twig (php templates), Tailwind, jQuery, SCSS, HTML & CSS
  • Tools: Static analysis tools (Semgrep, phpstan), DASTs
Requirements
  • 5+ years of experience in web application security
  • Strong experience with code review, security reviews, security architecture, pentesting, and bug bounty programs
  • Experience working in full-stack projects
  • Experience with discovering and fixing common web security vulnerabilities
  • Experience using web application pentesting tools (e.g. Burp Suite)
  • Basic understanding of networking concepts (DNS, TCP/IP, VPNs)
  • Able to explain complex ideas either verbally or in writing to a mixture of audiences
  • Knowledge and understanding of the OWASP Top 10
  • Experience creating security automations with GitHub Actions or other methods

Bonus (Great to have, but not required)
  • Experience coding in PHP and working with React/Next.js
  • Experience using scripting, using regex, and writing bash scripts
  • Experience with applications deployed in AWS & Kubernetes
  • Awareness of AI and LLMs, and how they are used in consumer products
  • Experience using AI and LLMs in security research
  • Experience with threat modeling
Benefits
  • Remote work with regular in-person bonding experiences sponsored by the company
  • Competitive compensation
  • Holistic perks program (including free therapy, employee wellness, and more)
  • Excellent health, dental, and vision coverage
  • 401k benefits with employer matching contribution
  • The chance to build something that changes lives - and that people love
  • Any piece of hardware or software that will make you happy and productive
  • An awesome community of co-workers

The base salary range for this position is $130,000 - $185,000. In addition to the base salary, this position is eligible for a performance bonus and the extensive benefits listed here (subject to eligibility requirements): Teladoc Health Benefits 2026. Total compensation is based on several factors - including, but not limited to, type of position, location, education level, work experience, and certifications. This information is applicable to all full-time positions.

About BetterHelp

BetterHelp is an online counseling platform that provides access to licensed therapists through video, phone, and messaging. The company was founded in 2013 by Alon Matas and Danny Bragonier. BetterHelp offers a range of services including individual counseling, couples counseling, and teen counseling. The platform is available 24/7 and offers affordable pricing options. BetterHelp has been featured in various media outlets including The New York Times, The Wall Street Journal, and CNN.
Learn more about BetterHelp
Size
1,000 employees
Industry
Founded
2013

Similar Jobs

More Jobs at BetterHelp

More Information Technology Jobs

Find similar Senior Security Engineer, Applications jobs: