> Markdown version of [/jobs/ext/3041165-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3041165-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Counterpart Health Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $169,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Disaster Recovery, Reliability Engineering, Secure Coding, Software Engineering, Software Security, Vulnerability Analysis, Programming Languages - **Published:** September 23, 2026 - **Apply:** https://www.builtincolorado.com/job/senior-application-security-engineer/11309112?handler=ApplyRedirect ## About the Role * You have 8+ years in software engineering and 4+ years focused on application security, vulnerability research, and penetration testing. * You have demonstrated the ability to identify vulnerabilities with custom tooling you've built. * You have been using AI to find vulnerabilities continuously in your day to day work. You know a range of tools, agents, and frameworks to drive impact with AI. But you also know where the guardrails go. * You can write code anywhere throughout the stack. Comfortable with a number of different programming languages. * You balance security against what engineers, clinicians, and operators actually need, and you measure yourself on results rather than policies. * You have mentored engineers into better security practices and want to keep doing it. * You work on software that touches patient care changes how you think about risk. ## Description * Actively hunt for and close security vulnerabilities across our core product, Counterpart Assistant. You will use a variety of different tools and scripts you write yourself to map a real attack. * Harden the systems, services, and endpoints around the platform. Establish strong security monitoring of our services and stack. * Safeguard PHI and monitor deidentification practices. Find the paths where protected data could leak and close them. * Use AI as a force multiplier for finding gaps; using agents and frameworks that scale vulnerability discovery, with guardrails you set. You will also help the engineering org build safely as the threat landscape around AI keeps moving. * Raise the bar for others. Review critical pull requests across every team, run security training, and mentor engineers whose secure coding needs work. * Partner with site reliability engineering, engineering leadership, and corporate security teams to establish defensive strategies to safeguard our data. * Strengthen our resilience and ensure disaster recovery is strong., Leads application security engineering for enterprise systems, including SAST and DAST scanning, security control implementation, web application protection, and pipeline development. Uses Veracode, Burp tools, Linux, and programming or scripting languages to identify and remediate vulnerabilities. Applies OWASP, CVSS, CWE, federal compliance standards, and secure architecture practices while supporting scalable digital transformation initiatives. Requires Public Trust eligibility and U.S. citizenship. Top Skills: .NetBashBurp EnterpriseBurp ProfessionalBurp ProxyC#CvssCweDastEclipseFedrampFipsHackeroneIastJavaJdeveloperLinuxNist 800-53Owasp Top 10Owasp ZapPythonSans-25SastSeleniumVeracodeVisual StudioWasc What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [Spot, Squash, Secure: Fighting Security Bugs with GitHub Copilot](https://www.wearedevelopers.com/videos/100052-spot-squash-secure-fighting-security-bugs-with-github-copilot) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Will AI replace Software Engineers?](https://www.wearedevelopers.com/magazine/340-will-ai-replace-software-engineers) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)