远程工作雷达

高级应用安全工程师 II

Senior Application Security Engineer II

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Spring Health
薪资$180,000 - $205,500/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-07-15
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

### **我们的使命:消除心理健康的所有障碍**

Spring Health 是一家全球性的心理健康公司,致力于消除所有心理健康障碍。我们正在打造一个世界,在这个世界中,获得支持变得简单、个性化,并以个人为中心,从而让护理能够贯穿每一个工作、每一次搬迁、每一份健康计划和每一个生命阶段。

我们的 AI 原生平台帮助我们通过自助工具、辅导、治疗、药物管理以及专科护理提供个性化的支持。我们的成果已通过 JAMA Network Open 和 Validation Institute 独立验证,目前通过领先的雇主、健康计划和合作伙伴,Spring Health 已覆盖全球超过 1.7 亿人。

作为一家 AI 原生公司,我们认为技术应该扩大护理的覆盖面、质量和人性化。每位 Spring Health 团队成员都应有意识地使用 AI 工具,对 AI 的输出应用人类判断,并以支持其角色和我们使命的方式持续提升 AI 熟练度。

Spring Health 正在寻找一名高级应用安全工程师 II 加入我们不断壮大的应用安全团队。你将向应用安全经理汇报,将在成熟和扩展我们的应用安全(AppSec)项目方面发挥关键作用——包括现有的 SAST、SCA 和 DAST 能力——同时参与塑造新的项目,例如安全 AI 开发生命周期(ADLC)。你将与一群已经打下坚实基础的工程师一起工作,利用你的经验帮助这些项目更上一层楼。

这是一个全职、完全远程的职位,面向居住在美国的候选人。偶尔可能需要前往纽约总部。

**你将负责:**

- 参与团队的 S-SDLC 计划,推动安全设计实践的发展,包括参与架构评审、设计咨询以及在整个开发周期中的安全指导。
- 指导工程师进行安全编码实践、应用安全基础知识和职业发展,营造一个协作的环境,使团队共同成长。
- 推动 AI 辅助威胁建模计划的开发,涵盖风险识别、安全架构和主动计划成熟度,使组织能够规模化威胁建模能力。
- 通过规则调优、覆盖率改进以及识别加强安全控制的机会,推动团队现有 SAST、SCA 和 DAST 计划的成熟。

查看英文原文

### **Our mission: e** liminating every barrier to mental health.

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage.

Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.

As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established SAST, SCA, and DAST capabilities — while helping shape new initiatives such as a Secure AI Development Lifecycle (ADLC). You will work alongside a team of engineers who have laid a strong foundation, bringing your experience to help take these programs to the next level.

This is a full-time, fully remote position open to candidates residing within the United States. Occasional travel to our NYC headquarters may be required.

**What you’ll do:**

- Contribute to the advancement of secure-by-design practices within the team’s S-SDLC program, including participation in architecture reviews, design consultations, and security guidance across the development lifecycle.
- Mentor engineers on secure coding practices, AppSec fundamentals, and career growth, fostering a collaborative environment where the team grows stronger together.
- Facilitate the development of an AI-assisted threat modeling program, spanning risk identification, security architecture, and proactive program maturity, enabling the ability to scale threat modeling across the organization.
- Contribute to maturing the team’s established SAST, SCA, and DAST programs through rule tuning, coverage improvements, and identifying opportunities to strengthen security controls as the organization scales.
- Perform security-focused code reviews of internal and open-source libraries, prioritizing findings by exploitability and business impact.
- Support vulnerability remediation efforts by assessing impact, proposing solutions, and validating fixes in accordance with the team’s established remediation workflows.
- Identify and implement process improvements and security automation using languages such as Go, Python, JavaScript, or Ruby, including the integration of AI tooling to improve team workflows and program efficiency.
- Contribute to security assessments of AI-integrated product features, including LLM APIs, vector databases, and RAG pipelines, with a focus on risks such as prompt injection, data leakage, and model supply-chain vulnerabilities.
- Contribute to the research, design, and development of a Secure AI Development Lifecycle (ADLC) in accordance with the OWASP Top 10 for LLM Applications and emerging adversarial ML guidance.
- Evaluate and recommend AI-assisted security tooling, including AI-augmented SAST and LLM-powered code review, to improve program coverage and team efficiency.

**What success looks like:**

- Demonstrated improvements to the team’s SAST, SCA, and DAST programs through rule tuning, noise reduction, and coverage expansion within the first 90 days.
- Delivery of a documented AI-assisted threat modeling program and foundational ADLC framework, including defined processes, tooling recommendations, and adoption milestones.
- Consistent adherence to team SLAs for vulnerability triage and remediation, with measurable contributions to reducing time-to-remediation for high and critical findings.
- Delivered security automation and AI tooling integrations that produce measurable improvements to program efficiency or engineering team experience.
- Completed security assessments of AI-integrated product features with documented findings, risk ratings, and remediation guidance delivered to engineering teams.

**What you’ll bring:**

- 7+ years of professional experience in application security or a closely related security engineering discipline, including experience working on complex, ambiguous problem areas independently.
- Hands-on experience with DAST, SAST, and SCA tools, and manual testing techniques (OWASP, SANS Top 25).
- Demonstrated experience securing CI/CD pipelines with commercial and custom-built tooling.
- Experience with IaaS cloud infrastructure (AWS, Azure, or GCP), container technologies, and service-oriented architectures.
- Security automation experience in at least one of: Go, Python, JavaScript, or Ruby.
- Familiarity with AI/ML security concepts — prompt injection, adversarial inputs, model supply-chain risks, and the OWASP LLM Top 10.
- Working knowledge of AI and LLM tooling (e.g., OpenAI, Anthropic, LangChain, or equivalent) sufficient to assess security risk and integrate into automated workflows.
- Experience implementing controls aligned to NIST CSF, HIPAA, HITRUST, ISO-27001, or SOC-2.
- Strong cross-functional collaboration skills, with experience working alongside engineering, product, and leadership stakeholders to define and advance security priorities and plans.
- Bachelor’s degree in Computer Science, Engineering, MIS, IT, or equivalent work experience.

**Nice to have:**

- 3+ years of demonstrated experience in security architecture, including designing and reviewing security controls across cloud-based, distributed, or service-oriented systems.
- Experience leading or contributing to the development of a formal threat modeling program, including tooling selection, methodology design, and adoption across engineering teams.
- Hands-on experience evaluating or implementing AI security tooling, including AI-augmented testing, LLM security assessments, or automated risk analysis.
- Experience managing a bug bounty or vulnerability disclosure program.
- Experience in digital health, healthcare technology, or other HIPAA-regulated environments.

The target base salary range for this position is **$180,000 - $205,500** _, and is part of a competitive total rewards package including stock options and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using [**Radford Global Compensation Database**](https://springhealth.link/jd-2022-09-radfordcomp) at minimum to ensure competitive and fair pay._

#### **Benefits provided by Spring Health:**

**Note**: We have even more benefits than listed [here](https://www.springhealth.com/careers#:~:text=Our%20perks%20%26%20benefits) and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.

- Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to [**One Medical**](https://www.onemedical.com/membership/) accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer sponsored 401(k) match of up to 2% for retirement planning
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- We offer competitive paid time off policies including vacation, sick leave and company holidays.
- At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to [**Noom**](https://www.noom.com/) **,** a weight management program—based in psychology, that’s tailored to your unique needs and goals.
- Access to fertility care support through [**Carrot**](https://springhealth.link/jd-2023-07-carrotbenefit), in addition to $4,000 reimbursement for related fertility expenses.
- Access to [**Wellhub**](https://springhealth.link/jd-2023-07-gympassbenefit),  which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
- Access to [**BrightHorizons**](https://www.brighthorizons.com/), which provides sponsored child care, back-up care, and elder care
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.

**Not sure if you meet every requirement?** . If this role excites you, we encourage you to apply.

**_Our privacy policy:_** [**_https://springhealth.com/privacy-policy/_**](https://springhealth.com/privacy-policy/)

_Spring Health is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, pregnancy, or other applicable legally protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements. Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you have a disability or special need that requires accommodation, please let us know._

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级数据分析师 I,医学事务

Spring HealthUnited States$125,000 - $142,000/年permanent今天
其他限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

运营经理

Spring HealthUnited Statespermanent5 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

资深商业法律顾问

Spring HealthUnited States$184,000 - $211,500/年permanent5 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

管理咨询团队负责人

Spring HealthUnited States$90,000 - $100,000/年permanent6 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位