H
Health-E Commerce
Posted 55 days agoVerified live 8h ago

Application Security Analyst

Brief overview

Remote
$75k–$95k/yrStated range
2+ yrsMinimum
2 H-1B approvalsDept. of Labor
Application SecurityProduct SecuritySecure Code ScanningSCASASTOWASP Top 10 VulnerabilitiesAPI SecurityMicroservices SecurityCI/CD PipelinesAI/ML Systems SecurityCloud SecurityPythonBashThreat ModelingSecure Design ReviewsWAFEDR

About the company

H
Health-E Commercehealth-ecommerce.com

Health-E Commerce is a family of brands that serve the 60+ million consumers with pre-tax health and wellness accounts.

Visa sponsorship history

2 years sponsoring, last filed FY2024H-1B dependent

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
2H-1B approved
100%approval rate
$108,306median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20231
20241
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20241
Top sponsored roles
Business Intelligence Anaylst

Job description

Summary

Health-E Commerce is seeking an Application Security Analyst to enhance the security of their software development processes. The role involves performing security assessments, integrating security into CI/CD pipelines, and collaborating with engineering teams to ensure robust security practices, particularly in AI/ML applications.

Responsibilities

  • Perform application security assessments using SCA, SAST, Secrets management, and interactive testing tools
  • Identify, triage, and prioritize vulnerabilities
  • Integrate security testing into CI/CD pipelines (DevSecOps)
  • Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints
  • Secure AI APIs, plugins, and third-party integrations
  • Tune security controls across technologies such as WAF, EDR, MDM, and cloud
  • Conduct threat modeling and secure design reviews for applications and AI use cases
  • Assess and harden identity and access flows ensuring least privilege
  • Automate repetitive security tasks so the team can focus on higher-value work
  • Partner with developers to remediate vulnerabilities and improve secure coding practices
  • Monitor and respond to security incidents as part of an on-call rotation

Skills

  • Minimum of 2+ years of experience in Application Security or Product Security
  • Hands-on experience with secure code scanning tools such as SCA and SAST
  • Strong knowledge of OWASP Top 10 vulnerabilities
  • Experience securing APIs and microservices
  • Familiarity with CI/CD pipelines
  • Basic understanding of AI/ML systems
  • Cloud security experience
  • Scripting skills (Python, Bash)
  • Good communication skills — you'll work with engineers, and sometimes explain things to non-technical people
  • A security mindset: you think about how things can break, not just how to make them work
  • Experience with ML frameworks is a plus
  • Familiarity with AI threat models
  • Experience with WAF or API security solutions
  • Strong coding skills in at least one language (Python, Bash, or similar)
  • Experience in ecommerce, healthcare or another highly regulated industry

Qualifications

Must Haves

  • Minimum of 2+ years of experience in Application Security or Product Security
  • Hands-on experience with secure code scanning tools such as SCA and SAST
  • Strong knowledge of OWASP Top 10 vulnerabilities
  • Experience securing APIs and microservices
  • Familiarity with CI/CD pipelines
  • Basic understanding of AI/ML systems
  • Cloud security experience
  • Scripting skills (Python, Bash)
  • Good communication skills — you'll work with engineers, and sometimes explain things to non-technical people
  • A security mindset: you think about how things can break, not just how to make them work

Nice to Haves

  • Experience with ML frameworks is a plus
  • Familiarity with AI threat models
  • Experience with WAF or API security solutions
  • Strong coding skills in at least one language (Python, Bash, or similar)
  • Experience in ecommerce, healthcare or another highly regulated industry

Benefits

  • Discretionary Annual Bonus Eligibility: Up to 10%
  • Medical, Dental, Vision, and 401K with a company match
  • Dependent Care, FSA & HSA accounts
  • Paid Parental & Bonding Leave
  • Flexible PTO & office closure on all major holidays
  • Monthly wellness & internet reimbursements
  • Professional development including certification support & leadership coaching
  • Mental Health resources
  • 100% remote within the United States
  • Must be able to work EST hours

More jobs like this