Clover Health Logo

Clover Health

Senior Application Security Engineer

Posted One Month Ago
Remote
Hiring Remotely in USA
169K-220K Annually
Senior level
Remote
Hiring Remotely in USA
169K-220K Annually
Senior level
Lead offensive application security work across the core product: hunt and remediate vulnerabilities, harden systems, safeguard PHI, scale AI-driven vulnerability discovery, mentor engineers, and partner with SRE and security teams to improve resilience and disaster recovery.
The summary above was generated by AI

At Counterpart Health, we are transforming healthcare and improving patient care with our innovative primary care tool, Counterpart Assistant. By supporting Primary Care Physicians (PCPs), we are able to deliver improved outcomes to our patients at a lower cost through early diagnosis and longitudinal care management of chronic conditions.

We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team, the group responsible for foundational work across the platform. You will hunt for vulnerabilities in software that thousands of practitioners use during live patient visits, close the gaps you find, and raise the security floor of every engineer around you. 

As a Senior Application Security Engineer, you will: 

  • Actively hunt for and close security vulnerabilities across our core product, Counterpart Assistant. You will use a variety of different tools and scripts you write yourself to map a real attack. 
  • Harden the systems, services, and endpoints around the platform.  Establish strong security monitoring of our services and stack.
  • Safeguard PHI and monitor deidentification practices. Find the paths where protected data could leak and close them.
  • Use AI as a force multiplier for finding gaps; using agents and frameworks that scale vulnerability discovery, with guardrails you set. You will also help the engineering org build safely as the threat landscape around AI keeps moving.
  • Raise the bar for others. Review critical pull requests across every team, run security training, and mentor engineers whose secure coding needs work.
  • Partner with site reliability engineering, engineering leadership, and corporate security teams to establish defensive strategies to safeguard our data. 
  • Strengthen our resilience and ensure disaster recovery is strong.

You should get in touch if:

  • You have 8+ years in software engineering and 4+ years focused on application security, vulnerability research, and penetration testing.
  • You have demonstrated the ability to identify vulnerabilities with custom tooling you’ve built. 
  • You have been using AI to find vulnerabilities continuously in your day to day work. You know a range of tools, agents, and frameworks to drive impact with AI.  But you also know  where the guardrails go.
  • You can write code anywhere throughout the stack.  Comfortable with a number of different programming languages.
  • You balance security against what engineers, clinicians, and operators actually need, and you measure yourself on results rather than policies.
  • You have mentored engineers into better security practices and want to keep doing it.
  • You work on software that touches patient care changes how you think about risk.

Benefits Overview

  • Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program, 401k matching, and regular compensation reviews to recognize and reward exceptional contributions.
  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by providing comprehensive medical, dental, and vision coverage. Your health matters to us, and we invest in ensuring you have access to quality healthcare.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, monthly company holidays, access to mental health resources, and a generous flexible time-off policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location. 
  • Professional Development: Developing internal talent is a priority for Clover. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities
  • Reimbursement for office setup expenses
  • Monthly cell phone & internet stipend
  • Remote-first culture, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Counterpart Health: In 2018, Clover Health set out to do something unprecedented: build a clinically intuitive, AI-enabled solution that fits within physicians' workflows to help support the earlier diagnosis and management of chronic conditions.

Years later, that vision is a reality, with thousands of practitioners using Counterpart Assistant during patient visits to improve disease management, reduce medical expenses, and drive success in value-based care.

With an exceptional team of value-based care and technology experts, Counterpart Health is driving value-based care at the speed of software.

Counterpart Health is a subsidiary of Clover Health. From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.

#LI-Remote

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E-Verify company.


Final pay is based on several factors including but not limited to internal equity, market data, and the applicant’s education, work experience, certifications, etc.

A reasonable estimate of the base salary range for this role is:
$169,000$220,000 USD

Similar Jobs

15 Days Ago
Remote
United States
145K-183K Annually
Senior level
145K-183K Annually
Senior level
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills: Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
25 Days Ago
Remote or Hybrid
San Francisco, CA, USA
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
5 Days Ago
Remote
United States
112K-140K Annually
Senior level
112K-140K Annually
Senior level
Software
Own and implement application security across the software development lifecycle for multiple product lines. Define security controls, validation gates, standards, and guardrails; conduct architecture reviews; enhance CI/CD security; triage SAST, SCA, and penetration-testing findings; support incident response; maintain FedRAMP and CJIS compliance; and represent security practices in audits and customer engagements.
Top Skills: Aws CodepipelineAws GovcloudAws LambdaAzure GovernmentGitlab CiJavaJenkinsNexusPastaSastSbomScaSonarqubeStrideTenableTypescript

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account