springhealth66

Senior Application Security Engineer II

Apply Now

At a Glance

Location
Remote
Work Regime
remote
Experience
7+ years
Compensation
ry range for this position is $180,000 - $205,500 , and is part of a competitiv
Posted
2026-07-15T18:55:02-04:00

Key Requirements

Required Skills

AWSAzureCI/CDGCPJavaScriptPythonRuby

Domain Knowledge

  • Automation
  • Cloud
  • Engineering
  • Healthcare

Requirements

7+ years of professional experience in application security or a closely related security engineering discipline, including experience working on complex, ambiguous problem areas independently.

Hands-on experience with DAST, SAST, and SCA tools, and manual testing techniques (OWASP, SANS Top 25).

Demonstrated experience securing CI/CD pipelines with commercial and custom-built tooling.

Experience with IaaS cloud infrastructure (AWS, Azure, or GCP), container technologies, and service-oriented architectures.

Security automation experience in at least one of: Go, Python, JavaScript, or Ruby.

Familiarity with AI/ML security concepts — prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.

Compensation & Benefits

Note

: We have even more benefits than listed

here

and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.

Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to

One Medical

Responsibilities

Contribute to the advancement of secure-by-design practices within the team’s S-SDLC program, including participation in architecture reviews, design consultations, and security guidance across the development lifecycle.

Facilitate the development of an AI-assisted threat modeling program, spanning risk identification, security architecture, and proactive program maturity, enabling the ability to scale threat modeling across the organization.

Contribute to maturing the team’s established SAST, SCA, and DAST programs through rule tuning, coverage improvements, and identifying opportunities to strengthen security controls as the organization scales.

Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.

Support vulnerability remediation efforts by assessing impact, proposing solutions, and validating fixes in accordance with the team’s established remediation workflows.

Identify and implement process improvements and security automation using languages such as Go, Python, JavaScript, or Ruby, including the integration of AI tooling to improve team workflows and program efficiency.