Heartflow

Heartflow

Application Security Engineer

San Francisco, California

Sponsorship not specified$145k-$180kDetected 8 days ago
PythonC++Code ReviewGitAWSDockerKubernetesTerraformAnsibleCI/CDGitHub ActionsMachine LearningCybersecurityComplianceHIPAAMedical DevicesCommunication

About the role

  • Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease, the #1 cause of death worldwide, using cutting-edge technology.
  • Our pipeline of products is growing and so is our team; join us in helping to revolutionize precision heartcare.

Responsibilities

  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle.
  • Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.

Requirements

  • Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences.
  • Experience leading training, speaking internally/externally about security projects valued.
  • Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python).
  • Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Knowledge of Modern AI Security Threats.
  • Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
  • If you enjoy working with talented engineers to solve complex technical challenges and want to see your work make a direct difference in patient outcomes, we encourage you to apply.
  • Security Communication - Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills - Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools - Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experience - BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC - Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats - Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
  • What Helps You Stand Out:
  • Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
  • Infrastructure as Code & Cloud - Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
  • A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1

Compensation

  • A reasonable estimate of the base salary compensation range is $145,000 to $180,000 per year, bonus, and equity. #LI-IB1

Benefits

  • Healthcare Experience - Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment.
  • Experience with Software as a Medical Device (SaMD) is especially valuable.
  • In this role, you'll have the chance to use your security and software development background to protect patients as we build products that leverage AI to improve healthcare.

Company info

  • We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC).

This listing is sourced directly from Heartflow's careers page and normalized into a canonical job model.