Senior Application Security Engineer
Spring HealthAbout the role
Our mission: to eliminate every barrier to mental health.
Spring Health is a comprehensive mental health solution for employers and health plans. Unlike any other solution, we use clinically validated technology called Precision Mental Healthcare to pinpoint and deliver exactly what will work for each person — whether that’s meditation, coaching, therapy, medication, and beyond.
Today, Spring Health equips over 800 companies, from start-ups to multinational Fortune 500 corporations, as a leading and preferred mental health service. Companies like J.P. Morgan Chase & Co., Microsoft, J.B. Hunt, Bumble, and Instacart use the Spring Health platform to provide mental health services to thousands of their team members globally. We have raised over $370 million from prominent investors including Kinnevik, Tiger Global, Northzone, RRE Ventures, and many more. Thanks to their partnership, our current valuation has reached $2.5 billion.
We are looking for a Senior Application Security Engineer to be part of our Security Operations & Engineering (SecOps) team. SecOps is committed to proactively detect, respond to, simulate, and identify breach attempts and threat actors. You will work with a team who oversee overall enterprise security systems implementation, lifecycle (S-SDLC), and support. You will help improve the company’s ability to respond to threats through technology selection, internal product development and implementations with a heavy emphasis on automation of manual tasks and processes. We’re looking for security engineers that can work collaboratively with our security, product, infrastructure architecture and engineering teams to implement secure solutions.
What You’ll Be Doing:
- Work closely with Engineering teams on Design Reviews for new features or major changes
- Utilize SAST and DAST tools to identify security flaws and best practices
- Perform Security Tests on new features and on the platform as a whole
- Develop, implement, and communicate vulnerability mitigation strategies to development teams
- Lead vulnerability assessments and penetration testing efforts
- Develop and maintain security incident response plans.
- Mentor and train junior security engineers.
- Help define security strategy and document solutions that align to multi-year security goals
- Participates in on call rotation, addressing most issues without assistance, and identifies when an escalation is needed
- Improve the security throughout the systems / solutions selection, implementation, operation, and full lifecycle of the service.
- Create detailed process management workflows to ensure security engineering activities are tracked, processes reviewed, policies are followed, and audit requirements are met.
- Assist peer teams in securing applications, business software and services, and infrastructure.
- Assist teams with mitigating findings including assessment of impacts, possible solutions, and efficacy of remedies.
- Assist with the secure integration of cloud applications and infrastructure.
- Develop and maintain technical support/knowledge base.
- Develops Service Level Agreements to set expectations and measure performance.
- Other duties as assigned. Management reserves the right to assign or reassign duties and responsibilities at any time.
What we expect from you:
- Expertise in security testing tools and techniques, such as vulnerability scanning, penetration testing, and secure code analysis.
- Experience in mobile device (Android and/or iOS) application security testing.
- Experience with threat modeling.
- Proficiency in at least one programming or scripting language,, such as Python, Java, C++, or Bash, to automate tasks, analyze data, and develop security tools.
- Proficiency with Infrastructure as Code (Terraform, Terragrunt, CloudFormation, etc)
- Advanced analytical and problem-solving skills, with the ability to identify and address complex security risks and develop innovative mitigation strategies.
- Experience in managing and leading security projects, including planning, execution, and monitoring, while effectively prioritizing based on risk and business impact.
- Experience in mentoring and coaching less experienced team members, contributing to their professional growth and fostering a collaborative team environment.
- You are a dedicated, highly organized and motivated person who is passionate about technology and security.
- You can work under deadlines in a fast-paced environment..
- Strong hands-on working knowledge about modern web application architecture and how to secure it (OWASP, SANS Top 25).
- Experience securing CI/CD pipelines enabling strong securit
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s