K Health Logo

K Health

Senior Security Engineer - Application Security

Posted 2 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
150K-200K Annually
Senior level
In-Office
New York, NY, USA
150K-200K Annually
Senior level
Lead AppSec across the SDLC: design and implement application security controls, perform hands-on testing of web apps/APIs/cloud services, integrate automated security tooling into CI/CD, reduce developer friction, review architecture and code, support vulnerability management and incident response, evaluate third-party risks, and ensure healthcare regulatory compliance (e.g., HIPAA, GDPR).
The summary above was generated by AI

About the role:
This is an opportunity to join K's critical InfoSec team as a Senior Security Engineer - AppSec and operate with foresight in protecting our infrastructure, applications, cloud security, and customer trust. As a lean team, we span across multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture, or planning and building out net new security solutions. You will have the autonomy to define and implement cutting-edge security solutions across our entire technical ecosystem, ensuring our innovative work remains robust and compliant against evolving global threats. This role is crucial for establishing and maintaining a world-class security posture, particularly within the sensitive and highly regulated healthcare technology space.

What you will do:

  • Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
  • Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
  • Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
  • Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
  • Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
  • Develop secure coding standards with developer-focused documentation
  • Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
  • Evaluate third party applications, libraries and APIs and integrations for security risk
  • Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.

What we're looking for:

  • 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
  • Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
  • Experience performing manual security testing of modern web applications, APIs and distributed systems
  • Ability to review application architecture and source code for security weaknesses
  • Experience integrating application security tools into modern CI/CD workflows
  • Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
  • Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
  • Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
  • Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.

Bonus:  #LI-Hybrid

  • Exploring, partnering and implementing bleeding edge tech not readily available to others.
  • Experience with specific tools and tech K uses including but not limited to: Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma
Compensation:
$150,000$200,000 USD

Who We Are: 

Behind every leading health system is K Health’s AI-powered virtual care engine. 

Esteemed health systems like Mayo Clinic, Cedars-Sinai, Mass General Brigham, Hackensack Meridian Health, and Hartford Healthcare partner with K Health to build and run modern primary virtual care clinics on their behalf. 

Our deeply integrated model modernizes the primary care loop by using AI to put humans first. For our patients, we offer clinical AI (i.e., PatientGPT) and unparalleled access to close care gaps around the clock. For our Providers, we deliver provider-serving agentic solutions (i.e., Perfect Note) to eliminate administrative overload and burnout. And for the health systems, we deploy our top-grade Virtualists in AI-powered virtual clinics 24/7 to capture the patients' care journeys at step one, retain the journey through the system for longitudinal care, and strengthen profitability.  

We’re founded in 2016, headquartered in New York City, and backed by nearly $400 million from leading investors including Valor Equity Partners, Claure Group, Mangrove Capital Partners, 14W, Notable Capital, Lerer Hippeau, Primary Venture Partners, Comcast Ventures, PICO Venture Partners, Max Ventures, and other strategic healthcare partners.

We offer competitive compensation packages based on industry benchmarks for function, level, and geographic location. Offer amounts are determined by multiple factors such as a candidate's experience and expertise.  

We are proud to be an Equal Opportunity Employer and consider applicants for employment regardless of race, ethnicity, religion, color, national origin, ancestry, disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, sexual orientation, pregnancy, childbirth and breastfeeding, age, citizenship, military or veteran status, or any other class protected by applicable federal, state, and local laws. We’re deeply committed to building teams as diverse as the patients we serve and strive to cultivate an environment where everyone can bring their most authentic self to work. We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our users.

We are committed to maintaining the integrity of our hiring process and ensuring a safe environment for all candidates. All communication for job offers from K Health will come from email addresses ending in @khealth.com. K Health will never ask you to provide financial information about yourself during the recruitment process. We will never use personal email accounts or other domains for official correspondence. Our official job postings are only listed on our official website and reputable job boards. Be cautious of job offers from sources other than these platforms.

HQ

K Health New York, New York, USA Office

298 5th Ave, 7th Floor, New York, NY, United States, 10001

Similar Jobs

12 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
140K-165K Annually
Senior level
140K-165K Annually
Senior level
Fintech • Financial Services
Own and evolve the application security program: embed secure SDLC practices, partner with engineering on design and code reviews, manage AppSec tooling (SAST/DAST/ASM/WAF/mobile), harden AWS deployments, integrate security into CI/CD, and lead vulnerability investigation and remediation efforts.
Top Skills: AppdomeAsmAWSCi/Cd PipelinesCloudflare WafCryptographic Key ManagementDastEcsGithub Advanced SecurityGoHadrianIamInvictiMobile Application Security ToolsPythonReact NativeRuby On RailsSastScaSecret ScanningSsl Certificates
5 Days Ago
Remote or Hybrid
USA
160K-250K Annually
Senior level
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead application security for products by performing threat modeling, manual secure code reviews, and penetration testing. Collaborate with engineers to remediate defects, build AppSec automation and tooling, secure cloud/containerized applications, and drive bug-bounty responses to harden platform security.
Top Skills: Ai TechnologiesApi SecurityAppsec ToolsAspmAWSAzureBug BountyChromeCspmDastDockerDspmElectronFirefoxGCPGo (Golang)JavaScriptKotlinKubernetesNode.jsPythonReactSastScalaStrideTypescriptWebassembly (Wasm)
2 Days Ago
In-Office
New York, NY, USA
Senior level
Senior level
Agency • HR Tech • Professional Services
Lead application security by performing risk analyses, vulnerability assessments, SAST/DAST and SCA testing, secure design and code review, threat simulations, cloud and WAF hardening, CI/CD security integration, and reporting to senior management while coordinating remediation with development and IT teams.
Top Skills: APIsAppsecAWSAzureBashBurp SuiteCi/CdDastEncryptionGCPIamMicroservicesMobile ApplicationsMonitoring ToolsOwasp Top 10PowershellPythonSastScaVeracodeWeb Application Firewall (Waf)

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account