About the role:
This is an opportunity to join K's critical InfoSec team as a Senior Security Engineer - AppSec and operate with foresight in protecting our infrastructure, applications, cloud security, and customer trust. As a lean team, we span across multiple areas such as AppSec, CloudSec, SecOps, ITSec, and Compliance and apply it towards reading and interpreting architecture, or planning and building out net new security solutions. You will have the autonomy to define and implement cutting-edge security solutions across our entire technical ecosystem, ensuring our innovative work remains robust and compliant against evolving global threats. This role is crucial for establishing and maintaining a world-class security posture, particularly within the sensitive and highly regulated healthcare technology space.
What you will do:
• Lead the development and implementation of robust application security protocols throughout the entire Software Development Lifecycle (SDLC).
• Partner with engineering teams to incorporate security into architecture, design, development, testing and deployment
• Perform hands-on security testing of web applications, APIs, cloud-native services and supporting infrastructure
• Build and improve automated security testing within CI/CI pipelines, including static analysis, dependency scanning, secrets detection, container scanning and dynamic testing
• Evaluate effectiveness of application security tools, improve tooling output quality and reduce unnecessary findings and developer friction
• Develop secure coding standards with developer-focused documentation
• Contribute application security expertise to vulnerability management, during security incidents/investigations and post-incident reviews
• Evaluate third party applications, libraries and APIs and integrations for security risk
• Ensure adherence to relevant healthcare regulatory and compliance requirements (e.g., HIPAA, GDPR, etc.) across all product lines and systems.
What we're looking for:
• 4+ years of professional experience in application, product or software security, operating as an individual contributor, OR as a software engineer that has pivoted into security
• Strong understanding of application security vulnerabilities and attach techniques, including OWASP Top 10 and API security risks
• Experience performing manual security testing of modern web applications, APIs and distributed systems
• Ability to review application architecture and source code for security weaknesses
• Experience integrating application security tools into modern CI/CD workflows
• Familiarity with static application security testing, dynamic testing, secrets detection, container security and infrastructure-as-code scanning
• Understanding of authentication, authorization, session management, cryptography, secrets management and secure API design
• Strong expertise in cloud technology (AWS, GCP, or Azure), modern programming languages, utilization of generative coding utilities, and the security implications of utilizing AI code development utilities.
• Demonstrated experience researching, establishing, and successfully rolling out enterprise-wide security policies and guidelines.
Bonus: #LI-Hybrid
• Exploring, partnering and implementing bleeding edge tech not readily available to others.
• Experience with specific tools and tech K uses including but not limited to: Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma
Compensation:
$150,000—$200,000 USD
Who We Are:
Behind every leading health system is K Health’s AI-powered virtual care engine.
Esteemed health systems like Mayo Clinic, Cedars-Sinai, Mass General Brigham, Hackensack Meridian Health, and Hartford Healthcare partner with K Health to build and run modern primary virtual care clinics on their behalf.
Our deeply integrated model modernizes the primary care loop by using AI to put humans first. For our patients, we offer clinical AI (i.e., PatientGPT) and unparalleled access to close care gaps around the clock. For our Providers, we deliver provider-serving agentic solutions (i.e., Perfect Note) to eliminate administrative overload and burnout. And for the health systems, we deploy our top-grade Virtualists in AI-powered virtual clinics 24/7 to capture the patients' care journeys at step one, retain the journey through the system for longitudinal care, and strengthen profitability.
We’re founded in 2016, headquartered in New York City, and backed by nearly $400 million from leading investors including Valor Equity Partners, Claure Group, Mangrove Capital Partners, 14W, Notable Capital, Lerer Hippeau, Primary Venture Partners, Comcast Ventures, PICO Venture Partners, Max Ventures, and other strategic healthcare partners.
We offer competitive compensation packages based on industry benchmarks for function, level, and geographic location. Offer amounts are determined by multiple factors such as a candidate's experience and expertise.
We are proud to be an Equal Opportunity Employer and consider applicants for employment regardless of race, ethnicity, religion, color, national origin, ancestry, disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, sexual orientation, pregnancy, childbirth and breastfeeding, age, citizenship, military or veteran status, or any other class protected by applicable federal, state, and local laws. We’re deeply committed to building teams as diverse as the patients we serve and strive to cultivate an environment where everyone can bring their most authentic self to work. We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our users.
We are committed to maintaining the integrity of our hiring process and ensuring a safe environment for all candidates. All communication for job offers from K Health will come from email addresses ending in @khealth.com. K Health will never ask you to provide financial information about yourself during the recruitment process. We will never use personal email accounts or other domains for official correspondence. Our official job postings are only listed on our official website and reputable job boards. Be cautious of job offers from sources other than these platforms.