Clover Health Logo

Clover Health

Senior Application Security Engineer

Posted 4 Hours Ago
Remote
Hiring Remotely in USA
169K-220K Annually
Senior level
Remote
Hiring Remotely in USA
169K-220K Annually
Senior level
Lead offensive application security work across the core product: hunt and remediate vulnerabilities, harden systems, safeguard PHI, scale AI-driven vulnerability discovery, mentor engineers, and partner with SRE and security teams to improve resilience and disaster recovery.
The summary above was generated by AI

At Counterpart Health, we are transforming healthcare and improving patient care with our innovative primary care tool, Counterpart Assistant. By supporting Primary Care Physicians (PCPs), we are able to deliver improved outcomes to our patients at a lower cost through early diagnosis and longitudinal care management of chronic conditions.

We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team, the group responsible for foundational work across the platform. You will hunt for vulnerabilities in software that thousands of practitioners use during live patient visits, close the gaps you find, and raise the security floor of every engineer around you. 

As a Senior Application Security Engineer, you will: 

  • Actively hunt for and close security vulnerabilities across our core product, Counterpart Assistant. You will use a variety of different tools and scripts you write yourself to map a real attack. 
  • Harden the systems, services, and endpoints around the platform.  Establish strong security monitoring of our services and stack.
  • Safeguard PHI and monitor deidentification practices. Find the paths where protected data could leak and close them.
  • Use AI as a force multiplier for finding gaps; using agents and frameworks that scale vulnerability discovery, with guardrails you set. You will also help the engineering org build safely as the threat landscape around AI keeps moving.
  • Raise the bar for others. Review critical pull requests across every team, run security training, and mentor engineers whose secure coding needs work.
  • Partner with site reliability engineering, engineering leadership, and corporate security teams to establish defensive strategies to safeguard our data. 
  • Strengthen our resilience and ensure disaster recovery is strong.

You should get in touch if:

  • You have 8+ years in software engineering and 4+ years focused on application security, vulnerability research, and penetration testing.
  • You have demonstrated the ability to identify vulnerabilities with custom tooling you’ve built. 
  • You have been using AI to find vulnerabilities continuously in your day to day work. You know a range of tools, agents, and frameworks to drive impact with AI.  But you also know  where the guardrails go.
  • You can write code anywhere throughout the stack.  Comfortable with a number of different programming languages.
  • You balance security against what engineers, clinicians, and operators actually need, and you measure yourself on results rather than policies.
  • You have mentored engineers into better security practices and want to keep doing it.
  • You work on software that touches patient care changes how you think about risk.

Benefits Overview

  • Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program, 401k matching, and regular compensation reviews to recognize and reward exceptional contributions.
  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by providing comprehensive medical, dental, and vision coverage. Your health matters to us, and we invest in ensuring you have access to quality healthcare.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, monthly company holidays, access to mental health resources, and a generous flexible time-off policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location. 
  • Professional Development: Developing internal talent is a priority for Clover. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities
  • Reimbursement for office setup expenses
  • Monthly cell phone & internet stipend
  • Remote-first culture, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Counterpart Health: In 2018, Clover Health set out to do something unprecedented: build a clinically intuitive, AI-enabled solution that fits within physicians' workflows to help support the earlier diagnosis and management of chronic conditions.

Years later, that vision is a reality, with thousands of practitioners using Counterpart Assistant during patient visits to improve disease management, reduce medical expenses, and drive success in value-based care.

With an exceptional team of value-based care and technology experts, Counterpart Health is driving value-based care at the speed of software.

Counterpart Health is a subsidiary of Clover Health. From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.

#LI-Remote

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E-Verify company.


Final pay is based on several factors including but not limited to internal equity, market data, and the applicant’s education, work experience, certifications, etc.

A reasonable estimate of the base salary range for this role is:
$169,000$220,000 USD

Similar Jobs

3 Days Ago
Remote or Hybrid
USA
160K-250K Annually
Senior level
160K-250K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead application security for products by performing threat modeling, manual secure code reviews, and penetration testing. Collaborate with engineers to remediate defects, build AppSec automation and tooling, secure cloud/containerized applications, and drive bug-bounty responses to harden platform security.
Top Skills: Ai TechnologiesApi SecurityAppsec ToolsAspmAWSAzureBug BountyChromeCspmDastDockerDspmElectronFirefoxGCPGo (Golang)JavaScriptKotlinKubernetesNode.jsPythonReactSastScalaStrideTypescriptWebassembly (Wasm)
An Hour Ago
In-Office or Remote
180K-225K Annually
Senior level
180K-225K Annually
Senior level
Software
Lead application security across product, pipeline, and customer environments by partnering with engineering to integrate secure design, conduct threat modeling and risk assessments, manage code and supply-chain security (SAST/DAST), triage bug bounty findings, harden Kubernetes and multi-tenant architectures, and participate in on-call rotation.
Top Skills: Admission ControlAuthenticationBug BountyDastEncryptionGoKubernetesLlm Security (Owasp Top 10 For Llms)Penetration TestingPythonRbacSastSecure Communication ProtocolsSupply Chain Security
An Hour Ago
Remote
Michigan, USA
121K-191K Annually
Senior level
121K-191K Annually
Senior level
eCommerce • Retail • Sales
Lead application security initiatives across the SDLC: perform threat modeling, secure design reviews, remediation guidance, third-party pen test management, develop security tooling, advise leadership on risks, mentor teammates, and improve application security maturity and training.
Top Skills: C#C++Client-ServerCloud InfrastructureContainerizationDatabasesJavaMicroservicesNative MobileOwasp Top 10Penetration TestingSingle Page Applications

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account