Senior Application Security Engineer

Spring Health

Spring Health

Posted on Thursday, August 17, 2023

Our mission: to eliminate every barrier to mental health.

Spring Health is a comprehensive mental health solution for employers and health plans. Unlike any other solution, we use clinically validated technology called Precision Mental Healthcare to pinpoint and deliver exactly what will work for each person — whether that’s meditation, coaching, therapy, medication, and beyond.

Today, Spring Health equips over 800 companies, from start-ups to multinational Fortune 500 corporations, as a leading and preferred mental health service. Companies like J.P. Morgan Chase & Co., Microsoft, J.B. Hunt, Bumble, and Instacart use the Spring Health platform to provide mental health services to thousands of their team members globally. We have raised over $370 million from prominent investors including Kinnevik, Tiger Global, Northzone, RRE Ventures, and many more. Thanks to their partnership, our current valuation has reached $2.5 billion.

We are looking for a Senior Application Security Engineer to be part of our Security Operations & Engineering (SecOps) team. SecOps is committed to proactively detect, respond to, simulate, and identify breach attempts and threat actors. You will work with a team who oversee overall enterprise security systems implementation, lifecycle (S-SDLC), and support. You will help improve the company’s ability to respond to threats through technology selection, internal product development and implementations with a heavy emphasis on automation of manual tasks and processes. We’re looking for security engineers that can work collaboratively with our security, product, infrastructure architecture and engineering teams to implement secure solutions.

What You’ll Be Doing:

  • Work closely with Engineering teams on Design Reviews for new features or major changes
  • Utilize SAST and DAST tools to identify security flaws and best practices
  • Perform Security Tests on new features and on the platform as a whole
  • Develop, implement, and communicate vulnerability mitigation strategies to development teams
  • Lead vulnerability assessments and penetration testing efforts
  • Develop and maintain security incident response plans.
  • Mentor and train junior security engineers.
  • Help define security strategy and document solutions that align to multi-year security goals
  • Participates in on call rotation, addressing most issues without assistance, and identifies when an escalation is needed
  • Improve the security throughout the systems / solutions selection, implementation, operation, and full lifecycle of the service.
  • Create detailed process management workflows to ensure security engineering activities are tracked, processes reviewed, policies are followed, and audit requirements are met.
  • Assist peer teams in securing applications, business software and services, and infrastructure.
  • Assist teams with mitigating findings including assessment of impacts, possible solutions, and efficacy of remedies.
  • Assist with the secure integration of cloud applications and infrastructure.
  • Develop and maintain technical support/knowledge base.
  • Develops Service Level Agreements to set expectations and measure performance.
  • Other duties as assigned. Management reserves the right to assign or reassign duties and responsibilities at any time.

What we expect from you:

  • Expertise in security testing tools and techniques, such as vulnerability scanning, penetration testing, and secure code analysis.
  • Experience in mobile device (Android and/or iOS) application security testing.
  • Experience with threat modeling.
  • Proficiency in at least one programming or scripting language,, such as Python, Java, C++, or Bash, to automate tasks, analyze data, and develop security tools.
  • Proficiency with Infrastructure as Code (Terraform, Terragrunt, CloudFormation, etc)
  • Advanced analytical and problem-solving skills, with the ability to identify and address complex security risks and develop innovative mitigation strategies.
  • Experience in managing and leading security projects, including planning, execution, and monitoring, while effectively prioritizing based on risk and business impact.
  • Experience in mentoring and coaching less experienced team members, contributing to their professional growth and fostering a collaborative team environment.
  • You are a dedicated, highly organized and motivated person who is passionate about technology and security.
  • You can work under deadlines in a fast-paced environment..
  • Strong hands-on working knowledge about modern web application architecture and how to secure it (OWASP, SANS Top 25).
  • Experience securing CI/CD pipelines enabling strong security controls through the implementation of commercial and custom built tooling.
  • Minimum of 6 years of professional or technical experience with a strong background in all aspects of security tools administration and incident response.

What we’d love to see as a bonus (but not required):

  • Experience with managing bug bounty programs.
  • PenTesting focused certifications.
  • 4+ years of demonstrated hand-on experience developing, implementing, and supporting application security services consumed by product teams across cloud-based infrastructure (AWS, Azure, Google Cloud).

The target salary range for this position is $159,100 - $194,150, and is part of a competitive total rewards package including stock options, benefits, and incentive pay for eligible roles. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually at minimum to ensure competitive and fair pay.

Don’t meet every requirement? Studies have shown that women, communities of color and historically underrepresented talent are less likely to apply to jobs unless they meet every single qualification. At Spring Health we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we strongly encourage you to apply. You may be just the right candidate for this or other roles!

Ready to do the most impactful work of your life? Learn more about our values, how we work, and how hypergrowth meets impact at Spring Health: Our Values

Hypergrowth meets impact

What to expect working here:

  • You will be held accountable to an exceptionally high bar and impact
  • This may be the fastest work environment you will ever experience in terms of growth, decision-making, and time to impact
  • You will be challenged to set and protect your own boundaries
  • You will create processes & products that have never existed before
  • You will have very direct conversations and receive continuous feedback to push you to become the highest performer you can be
  • Change is a constant here: your role, team, responsibilities, and success metrics will shift as the company grows


  • You get to be surrounded by some of the brightest minds in the field
  • You get to learn and grow at an extremely accelerated pace
  • You will experience transparency, integrity, & humility from leadership
  • You will be empowered to constantly challenge the status quo
  • You get the space to experiment & innovate
  • You get to make a transformational impact for the company, mental health, and for real human lives — and you will see that impact quickly
  • You will become more resourceful and resilient
  • You get to be part of a winning team that opens doors in the future

Benefits provided by Spring Health:

Your Total Health:

  • Generous medical, dental, vision coverage available day 1 + access to One Medical
  • 20 total yearly no-cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents
  • Flexible paid time off in addition to 12 paid holidays throughout the year
  • $500 per year Wellness Reimbursement
  • Access to Gympass, an on-demand virtual benefit that provides wellbeing coaching, and budget management.
  • Spring Health provides access to QuitGenius, a platform with technology-tailored, personalized addiction treatment plans for substance use (*QG is available to benefit-enrolled employees, spouses, and dependents age 18+)
  • Sabbatical Leave: When you’re a Team Member at Spring Health and hit your four-year Springaversary, you’ll be awarded a four week, fully paid, sabbatical leave.

You And Your family:

  • 4-4.5 months of fully paid parental leave
  • Spring Health provides team members and their families with sponsored access to Bright Horizons® child care, back-up care, and elder care.
  • Access to Joshin is provided by Spring Health. Joshin is a comprehensive support system for disabilities and neurodivergence in the workplace. This benefit supports employees, their families, and our teams through personalized navigation and disability education and training along with a network of screened in-home caregivers with disability and neurodivergent experience.
  • Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses

Supporting you financially through:

  • Our People team benchmarks all salaries using the Radford Global Compensation Database for technology and life sciences industries. Radford benchmarks salaries with 3,589 global firms, 6.5 million employees, and 98 countries across the globe. We do this to ensure all of our team members are paid equally and competitively.
  • On top of competitive and benchmarked salary, Spring Health offers incentive pay (based on role), and equity that begins vesting as we celebrate your first year with the company!
  • Employer sponsored 401(k) match of up to 2% after 90 days of employment

Creating a culture you can thrive in:

  • Flexible work arrangements: 60% of Spring Health team members work fully remote while 40% work in a hybrid model from our New York City offices
  • Focus Fridays: no meetings, no distractions, just time for you to get work done.
  • Focus Weeks: In Spring 2023, we held our first ever Focus Week, we canceled all non-essential meetings, minimized distractions, and you, our team members, to dive into the key work that gets chopped up or deprioritized during the regular day-to-day. We saw a 36% jump in the average energized score after those five days of flow state work and are finalizing a plan for quarterly Focus Weeks for team members.
  • Up to $1,000 Professional Development Reimbursement per calendar year.
  • $200 per year donation matching to support your favorite causes

Our privacy policy: https://springhealth.com/privacy-policy/

Spring Health is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements. Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you have a disability or special need that requires accommodation, please let us know.