← Back to job listings
HE
Application Security Engineer
HeartFlow · San Francisco, United States
About The Role
Join HeartFlow, a pioneering company in the healthcare industry, as an Application Security Engineer. In this hybrid role, you will work closely with our engineering team to integrate security into our Software Development Lifecycle (SDLC). Your expertise in security and software development will help protect patients as we build AI-driven healthcare products. You will provide hands-on technical guidance to software developers, drive vulnerability identification, support vulnerability management, and build security awareness through training.
- Collaborer avec l'équipe d'ingénierie pour fournir des conseils techniques pratiques aux développeurs de logiciels tout au long du cycle de remédiation des vulnérabilités.
- Conduire l'identification des vulnérabilités en utilisant des outils SAST, DAST, SCA et en interne, et gérer les tests de pénétration externes.
- Promouvoir la sensibilisation à la sécurité grâce à des formations sur les pratiques de codage sécurisé, les normes de sécurité et les dernières menaces.
- Securing SDLC – Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management
- Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI
- AI Development Tools – Experience using AI code tools such as Claude Code and Github Copilot for development and security testing
- Programming Skills – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines
- Education & Experience – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role
- Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued
- Healthcare Experience – Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable
- Infrastructure as Code & Cloud – Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar)
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring