Heartflow
Application Security Engineer
San Francisco, California
Sponsorship not specified$145k-$180kDetected 8 days ago
PythonC++Code ReviewGitAWSDockerKubernetesTerraformAnsibleCI/CDGitHub ActionsMachine LearningCybersecurityComplianceHIPAAMedical DevicesCommunication
About the role
- Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease, the #1 cause of death worldwide, using cutting-edge technology.
- Our pipeline of products is growing and so is our team; join us in helping to revolutionize precision heartcare.
Responsibilities
- Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle.
- Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
- Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
- Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
- Build security awareness through training on secure coding practices, security standards and latest security threats.
Requirements
- Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences.
- Experience leading training, speaking internally/externally about security projects valued.
- Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python).
- Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
- 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
- Knowledge of Modern AI Security Threats.
- Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
- If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply.
- Security Communication - Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
- Programming Skills - Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
- AI Development Tools - Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
- Education & Experience - BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
- Securing SDLC - Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
- Knowledge of Modern AI Security Threats - Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
- What Helps You Stand Out:
- Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
- Infrastructure as Code & Cloud - Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
- A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1
Compensation
- A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1
Benefits
- Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment.
- Experience with Software as a Medical Device (SaMD) is especially valuable.
- In this role, you'll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare.
Company info
- We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC).
Apply directly at Heartflow →Create a free account for alerts like thisView Heartflow immigration profile
This listing is sourced directly from Heartflow's careers page and normalized into a canonical job model.