MyFitnessPal logo
MyFitnessPal
Posted 31 days agoVerified live 2d ago

Application Security Engineer

Brief overview

Remote
$90k–$130k/yrStated range
Application Security AssessmentVulnerability ManagementOWASP Top 10OWASP MASVSSecurity AutomationPythonKubernetesInfrastructure as CodeGitHub ActionsBug Bounty ProgramsIdentity and Access Management

About the company

MyFitnessPal logo
MyFitnessPalmyfitnesspal.com

A health and wellness technology company building tools for healthy living.

Job description

Summary

MyFitnessPal provides tools, resources, and support to help users achieve their health and fitness goals. The company is seeking a Security Engineer II focused on Application Security to manage vulnerability programs, partner with engineering teams on remediation, operate security tooling, and build automation that secures applications and development processes.

Responsibilities

  • Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets through our SVM process to resolution
  • Operate and grow our bug bounty program — scoping engagements, triaging researcher submissions, validating findings, and coordinating with vendors
  • Leverage AI and agentic tooling (for example, Claude Code and agentic pipelines) to accelerate security workflows — from vulnerability triage and enrichment to automated remediation support — and help ensure our AI-assisted development practices remain secure
  • Build and maintain security automation (for example, in our SOAR platform and with Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces the metrics and reporting that keep the program transparent
  • Partner with product engineering teams on remediation — joining triage and refinement discussions, answering questions, and representing security as a business enabler rather than a blocker
  • Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance
  • Advocate secure coding practices and contribute to developer-facing security documentation and training
  • Administer and tune application security tooling across the SDLC, and help evaluate and implement new security technology
  • Support identity and access management workflows and the automation behind them

Skills

  • • 2-4 years of experience in security engineering, application security, software engineering, or a closely related role
  • • Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
  • • Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
  • • Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
  • • Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
  • • Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code)
  • • Strong communication skills, enabling collaboration across cross-functional teams, and the judgment to raise a security finding and land it as a shared problem to solve, not a fight to win
  • • Ability to create documentation that describes technical details clearly, including for non-technical audiences
  • • Ability & desire to learn new product lines and technologies quickly & efficiently
  • • Education and/or certifications equivalent to BS in Computer Science or IS related field; GIAC (e.g., GWEB, GCIH), OSCP, CSSLP, Security+, or vendor-specific certifications are a plus
  • • Experience automating security processes (e.g., Python, SOAR platforms, workflow automation) is strongly preferred
  • • Experience with security scanning in CI/CD pipelines and orchestration tools (e.g., GitHub Actions) is a plus
  • • Experience operating or triaging for a bug bounty program is a plus

Qualifications

Must Haves

  • • 2-4 years of experience in security engineering, application security, software engineering, or a closely related role
  • • Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
  • • Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
  • • Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
  • • Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
  • • Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code)
  • • Strong communication skills, enabling collaboration across cross-functional teams, and the judgment to raise a security finding and land it as a shared problem to solve, not a fight to win
  • • Ability to create documentation that describes technical details clearly, including for non-technical audiences
  • • Ability & desire to learn new product lines and technologies quickly & efficiently
  • • Education and/or certifications equivalent to BS in Computer Science or IS related field; GIAC (e.g., GWEB, GCIH), OSCP, CSSLP, Security+, or vendor-specific certifications are a plus

Nice to Haves

  • • Experience automating security processes (e.g., Python, SOAR platforms, workflow automation) is strongly preferred
  • • Experience with security scanning in CI/CD pipelines and orchestration tools (e.g., GitHub Actions) is a plus
  • • Experience operating or triaging for a bug bounty program is a plus

Benefits

  • Healthcare
  • Parental planning
  • Mental health benefits
  • Annual performance bonus
  • A 401(k) plan and match
  • Responsible time off
  • Monthly wellness and technology allowances
  • Opportunities to meet and connect with team members in person; all of MyFitnessPal gathers annually
  • A flexible time-off policy with the Responsible Time Off benefit
  • 2 volunteer days off per calendar year for each full-time teammate
  • An optional mentorship program with a matched teammate
  • Paid maternity and paternity leave
  • Best-in-class comprehensive assistance for fertility-related matters
  • A monthly Wellness Allowance, including dedicated mental health days
  • A reward and recognition platform for peer acknowledgment and rewards
  • Access to MyFitnessPal Premium
  • Access to a virtual learning and development library and training opportunities
  • A dedicated DEI Committee that fosters a diverse and inclusive workplace
  • Medical, dental, and vision benefits
  • A retirement savings program with a competitive employer match

More jobs like this