About the Role
Join K's critical InfoSec team as a Senior Security Engineer - AppSec to protect our infrastructure, applications, cloud security, and customer trust. You will define and implement cutting-edge security solutions across our technical ecosystem, ensuring robustness and compliance within the healthcare technology space.
Responsibilities
- Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
- Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment.
- Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure.
- Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing.
- Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction.
- Develop secure coding standards with developer-focused documentation.
- Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews.
- Evaluate third party applications, libraries and APIs and integrations for security risk.
- Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.
Requirements
- 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security.
- Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks.
- Experience performing manual security testing of modern web applications, APIs and distributed systems.
- Ability to review application architecture and source code for security weaknesses.
- Experience integrating application security tools into modern CI/CD workflows.
- Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning.
- Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design.
- Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
- Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.
Skills
- Application Security
- Cloud Security
- Security Operations
- Information Security
- Compliance
- Architecture Review
- Security Solution Implementation
- Software Development Lifecycle (SDLC)
- API Security
- Cloud-Native Services Security
- Infrastructure Security
- CI/CD Security Integration
- Static Analysis
- Dependency Scanning
- Secrets Detection
- Container Scanning
- Dynamic Testing
- Secure Coding Standards
- Vulnerability Management
- Incident Response
- Post-Incident Review
- Third-Party Risk Assessment
- HIPAA
- GDPR
- OWASP Top 10
- AWS
- GCP
- Azure
- Modern Programming Languages
- Generative Coding Utilities
- AI Code Development Utilities
- Enterprise Security Policies
- Datadog
- Sumologic
- Torq
- flare.io
- Entitle
- Okta
- Orca
- GitLab
- Prisma
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- Senior
Salary/Compensations
- $150,000—$200,000 USD
About the Company
- K Health's AI-powered virtual care engine partners with esteemed health systems to build and run modern primary virtual care clinics.
- Our integrated model modernizes the primary care loop using AI to put humans first, offering clinical AI and access for patients, provider-serving agentic solutions to eliminate administrative overload for providers, and deploying Virtualists in AI-powered virtual clinics for health systems.
- Founded in 2016, headquartered in New York City, and backed by nearly $400 million from leading investors.
- We offer competitive compensation packages based on industry benchmarks for function, level, and geographic location. Offer amounts are determined by multiple factors such as a candidate's experience and expertise.
Equal Opportunity
- We are proud to be an Equal Opportunity Employer and consider applicants for employment regardless of race, ethnicity, religion, color, national origin, ancestry, disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, sexual orientation, pregnancy, childbirth and breastfeeding, age, citizenship, military or veteran status, or any other class protected by applicable federal, state, and local laws.
- We’re deeply committed to building teams as diverse as the patients we serve and strive to cultivate an environment where everyone can bring their most authentic self to work.
- We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our users.
- We are committed to maintaining the integrity of our hiring process and ensuring a safe environment for all candidates. All communication for job offers from K Health will come from email addresses ending in @khealth.com. K Health will never ask you to provide financial information about yourself during the recruitment process. We will never use personal email accounts or other domains for official correspondence. Our official job postings are only listed on our official website and reputable job boards. Be cautious of job offers from sources other than these platforms.
