Jobs and Careers
AK

Sr. Application Security Engineer

AKASA
South San Francisco, United Statesfull_timeVerifiedPosted 19 Mar 2026
💰 $275,000/yr($205,000/yr$275,000/yr)

About the role

About AKASA

At AKASA, our mission is to build the future of healthcare with AI. As the leading provider of generative AI solutions for the healthcare revenue cycle, we help health systems comprehensively capture and communicate the full patient clinical journey. By empowering health systems to streamline their operations, they can focus on what matters most - delivering quality patient care. We have raised over $205M in funding from investors such as Andreessen Horowitz, BOND, and Costanoa Ventures.

This is the most exciting time to join AKASA. Revenue bookings for our new AI-native product suite have grown over 20x since launching in 2024. In this time, we have broken our record for the largest deal in company history three times consecutively. This growth is driven by the massive improvement we are generating for our customers across clinical quality and documentation accuracy, both top priority areas for health system leaders.

Our deployments have been recognized nationally as "one of the most comprehensive real-world uses of GenAI in healthcare finance to date" (link). Our customer base represents more than $120B+ in net patient revenue and includes the most innovative health systems in the country, like Cleveland Clinic, Duke, Stanford, and Johns Hopkins.

Some of our recent recognitions include being named one of America's Top Startup Employers 2026 by Forbes, #1 most promising healthcare RCM startup of 2025 by Black Book Market Research, and one of the fastest-growing GenAI startups to watch by AIM Research. Our CEO was ranked among the “Top 50 Healthcare Technology CEOs” by the Healthcare Technology Report, and we have been certified as a “Great Place to Work” for the past 6 years in a row.

We’re building on this momentum to redefine what’s possible in healthcare. We’re looking for exceptional people to help us accelerate that reality.

The opportunity

We're looking for a seasoned Application Security Engineer who brings the credibility of a software engineering background and the mindset of a security practitioner. You'll be embedded with our engineering teams, helping us build secure systems from the ground up — not bolted on after the fact. You'll own our application security program, work closely with developers, and be a key voice in shaping how we think about risk across our product and infrastructure.

What you’ll do

  • Own and evolve our application security program, including threat modeling, secure code review, SAST/DAST tooling, and penetration testing coordination.

  • Partner closely with engineering squads throughout the SDLC to identify and remediate vulnerabilities early — acting as a security champion, not a gatekeeper.

  • Lead security design reviews for new features and architecture changes, ensuring security requirements are well-understood and actionable.

  • Develop and maintain a vulnerability management program, prioritizing findings based on risk and driving remediation to closure.

  • Build and deliver security training and awareness programs tailored to developers — leveraging your engineering background to make guidance practical and relevant.

  • Evaluate and implement security tooling across the CI/CD pipeline (SAST, SCA, secret scanning, container scanning, etc.).

  • Support third-party penetration tests and bug bounty programs, including triage, validation, and remediation tracking.

  • Contribute to compliance efforts related to HIPAA, SOC 2, and other relevant frameworks, particularly as they relate to application and data security.

  • Monitor the threat landscape and proactively surface emerging risks relevant to our technology stack and industry.

  • Develop applications that run securely in cloud and containerized environments.

Must-haves

  • 10+ years of experience in software engineering, application security, or a combination of both.

  • A strong software engineering foundation — you've written production code and understand how applications are built, not just how they break.

  • Meaningful experience in application security, whether that came from transitioning out of a development role or through dedicated AppSec positions.

  • Hands-on experience with common vulnerability classes (OWASP Top 10, injection attacks, authentication flaws, insecure deserialization, etc.) and how to fix them.

  • Experience conducting or coordinating threat modeling, security architecture reviews, and secure code reviews.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AKASA

View company profile →