Summary
Health-E Commerce is seeking an Application Security Analyst to enhance the security of their software development processes. The role involves performing security assessments, integrating security into CI/CD pipelines, and collaborating with engineering teams to ensure robust security practices, particularly in AI/ML applications.
Responsibilities
- Perform application security assessments using SCA, SAST, Secrets management, and interactive testing tools
- Identify, triage, and prioritize vulnerabilities
- Integrate security testing into CI/CD pipelines (DevSecOps)
- Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints
- Secure AI APIs, plugins, and third-party integrations
- Tune security controls across technologies such as WAF, EDR, MDM, and cloud
- Conduct threat modeling and secure design reviews for applications and AI use cases
- Assess and harden identity and access flows ensuring least privilege
- Automate repetitive security tasks so the team can focus on higher-value work
- Partner with developers to remediate vulnerabilities and improve secure coding practices
- Monitor and respond to security incidents as part of an on-call rotation
Skills
- Minimum of 2+ years of experience in Application Security or Product Security
- Hands-on experience with secure code scanning tools such as SCA and SAST
- Strong knowledge of OWASP Top 10 vulnerabilities
- Experience securing APIs and microservices
- Familiarity with CI/CD pipelines
- Basic understanding of AI/ML systems
- Cloud security experience
- Scripting skills (Python, Bash)
- Good communication skills — you'll work with engineers, and sometimes explain things to non-technical people
- A security mindset: you think about how things can break, not just how to make them work
- Experience with ML frameworks is a plus
- Familiarity with AI threat models
- Experience with WAF or API security solutions
- Strong coding skills in at least one language (Python, Bash, or similar)
- Experience in ecommerce, healthcare or another highly regulated industry
Qualifications
Must Haves
- Minimum of 2+ years of experience in Application Security or Product Security
- Hands-on experience with secure code scanning tools such as SCA and SAST
- Strong knowledge of OWASP Top 10 vulnerabilities
- Experience securing APIs and microservices
- Familiarity with CI/CD pipelines
- Basic understanding of AI/ML systems
- Cloud security experience
- Scripting skills (Python, Bash)
- Good communication skills — you'll work with engineers, and sometimes explain things to non-technical people
- A security mindset: you think about how things can break, not just how to make them work
Nice to Haves
- Experience with ML frameworks is a plus
- Familiarity with AI threat models
- Experience with WAF or API security solutions
- Strong coding skills in at least one language (Python, Bash, or similar)
- Experience in ecommerce, healthcare or another highly regulated industry
Benefits
- Discretionary Annual Bonus Eligibility: Up to 10%
- Medical, Dental, Vision, and 401K with a company match
- Dependent Care, FSA & HSA accounts
- Paid Parental & Bonding Leave
- Flexible PTO & office closure on all major holidays
- Monthly wellness & internet reimbursements
- Professional development including certification support & leadership coaching
- Mental Health resources
- 100% remote within the United States
- Must be able to work EST hours