Application Security Engineer

Counterpart Health Inc.
San Francisco, CA, United States
2 days ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$169,000.0 - $220,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software System Penetration Testing Disaster Recovery Reliability Engineering Secure Coding Software Engineering Software Security Vulnerability Analysis Programming Languages

Job description

  • Actively hunt for and close security vulnerabilities across our core product, Counterpart Assistant. You will use a variety of different tools and scripts you write yourself to map a real attack.
  • Harden the systems, services, and endpoints around the platform. Establish strong security monitoring of our services and stack.
  • Safeguard PHI and monitor deidentification practices. Find the paths where protected data could leak and close them.
  • Use AI as a force multiplier for finding gaps; using agents and frameworks that scale vulnerability discovery, with guardrails you set. You will also help the engineering org build safely as the threat landscape around AI keeps moving.
  • Raise the bar for others. Review critical pull requests across every team, run security training, and mentor engineers whose secure coding needs work.
  • Partner with site reliability engineering, engineering leadership, and corporate security teams to establish defensive strategies to safeguard our data.
  • Strengthen our resilience and ensure disaster recovery is strong., Leads application security engineering for enterprise systems, including SAST and DAST scanning, security control implementation, web application protection, and pipeline development. Uses Veracode, Burp tools, Linux, and programming or scripting languages to identify and remediate vulnerabilities. Applies OWASP, CVSS, CWE, federal compliance standards, and secure architecture practices while supporting scalable digital transformation initiatives. Requires Public Trust eligibility and U.S. citizenship. Top Skills: .NetBashBurp EnterpriseBurp ProfessionalBurp ProxyC#CvssCweDastEclipseFedrampFipsHackeroneIastJavaJdeveloperLinuxNist 800-53Owasp Top 10Owasp ZapPythonSans-25SastSeleniumVeracodeVisual StudioWasc

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Requirements

  • You have 8+ years in software engineering and 4+ years focused on application security, vulnerability research, and penetration testing.
  • You have demonstrated the ability to identify vulnerabilities with custom tooling you’ve built.
  • You have been using AI to find vulnerabilities continuously in your day to day work. You know a range of tools, agents, and frameworks to drive impact with AI. But you also know where the guardrails go.
  • You can write code anywhere throughout the stack. Comfortable with a number of different programming languages.
  • You balance security against what engineers, clinicians, and operators actually need, and you measure yourself on results rather than policies.
  • You have mentored engineers into better security practices and want to keep doing it.
  • You work on software that touches patient care changes how you think about risk.

Benefits & conditions

Hands-on application security engineer responsible for finding and remediating vulnerabilities across a healthcare platform. Duties include offensive security testing, custom tooling, system hardening, security monitoring, PHI protection, AI-assisted vulnerability discovery, secure code review, security training, mentoring, defensive strategy, and disaster recovery resilience. The summary above was generated by AI

At Counterpart Health, we are transforming healthcare and improving patient care with our innovative primary care tool, Counterpart Assistant. By supporting Primary Care Physicians (PCPs), we are able to deliver improved outcomes to our patients at a lower cost through early diagnosis and longitudinal care management of chronic conditions., * Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program, 401k matching, and regular compensation reviews to recognize and reward exceptional contributions.

  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by providing comprehensive medical, dental, and vision coverage. Your health matters to us, and we invest in ensuring you have access to quality healthcare.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, monthly company holidays, access to mental health resources, and a generous flexible time-off policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location.
  • Professional Development: Developing internal talent is a priority for Clover. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities
  • Reimbursement for office setup expenses
  • Monthly cell phone & internet stipend
  • Remote-first culture, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Counterpart Health: In 2018, Clover Health set out to do something unprecedented: build a clinically intuitive, AI-enabled solution that fits within physicians’ workflows to help support the earlier diagnosis and management of chronic conditions.

Years later, that vision is a reality, with thousands of practitioners using Counterpart Assistant during patient visits to improve disease management, reduce medical expenses, and drive success in value-based care.

With an exceptional team of value-based care and technology experts, Counterpart Health is driving value-based care at the speed of software.

Counterpart Health is a subsidiary of Clover Health. From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people’s lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone’s responsibility.

LI-Remote

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E-Verify company.

Final pay is based on several factors including but not limited to internal equity, market data, and the applicant’s education, work experience, certifications, etc. A reasonable estimate of the base salary range for this role is: $169,000-$220,000 USD, Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams. Top Skills: Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript Grow Therapy

Staff Engineer

One Month Ago Remote or Hybrid 182K-288K Annually Senior level 182K-288K Annually Senior level Healthtech * Social Impact * Software Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development. Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling Agile Defense, LLC

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross · World Congress 2026 Europe

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all