Application Security Engineer
Candidhealth · San Francisco (CA), Denver (CO), New York (NY)
About this role
## About Candid Health Candid Health is building the modern financial backbone for American healthcare. In the U.S., getting doctors paid by insurance companies is notoriously complicated—rules change constantly, claims require extensive paperwork, and mistakes can lead to rejected bills, unexpected patient charges, and major administrative waste. Candid Health’s autonomous Revenue Cycle Management (RCM) platform unifies clinical, billing, and insurance data into a single smart system. Powered by AI agents and a configurable rules engine, it helps submit complex medical claims accurately and efficiently—reducing administrative costs and improving cash flow for healthcare providers. Trusted by 200+ healthcare organizations and backed by top investors, Candid Health recently raised a $120M Series D to accelerate AI-driven transformation of healthcare payments. --- ## Role Overview We’re looking for a **Product Security Engineer** to be a security champion within our product engineering organization. You’ll partner with development squads to ensure our products are designed, developed, and maintained with security as a core pillar. --- ## Key Responsibilities - **Security by Design:** Lead threat modeling sessions during architectural design for new features to identify risks early. - **Secure Development Lifecycle (SDLC):** Drive “Shift Left” security practices by integrating security tooling (SAST, DAST, SCA) into developer workflows. - **Vulnerability Management:** Triage, prioritize, and partner with engineering teams to remediate vulnerabilities in code, third-party libraries, and cloud infrastructure. - **Security Tooling & Automation:** Build, maintain, and tune security automation to reduce developer friction while maintaining high security standards. - **Secure Coding Standards:** Create training, coding patterns, and security guardrails to help teams build resilient, secure-by-default products. - **Incident Response Support:** Help identify root causes of security incidents related to product features and contribute to post-incident remediation and architectural improvements. - **Supply Chain Security:** Build processes and automation to ensure the security of open-source dependencies. --- ## Required Qualifications - **Experience:** 5+ years in software engineering or security engineering, focused on product/application security. - **Technical Skills:** - Proficiency in one or more languages (e.g., Python, Go, Java, JavaScript) - Deep understanding of modern web/cloud architecture (APIs, microservices, Kubernetes, AWS/GCP/Azure) - Familiarity with OWASP Top 10 and common exploitation techniques - **Collaboration:** Ability to influence and collaborate with engineering teams without slowing delivery. - **Problem Solving:** Strong analytical skills to evaluate complex systems and design practical security solutions. --- ## Preferred Skills (Nice to Have) - Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation) - Cryptographic implementations and secure auth flows (OAuth, OIDC, JWT) - Compliance knowledge relevant to the industry (SOC2, ISO27001, HIPAA) --- ## Pay Transparency Estimated starting annual salary range: **$180,000 – $258,000 USD**. The range is a guideline from Pave (https://www.pave.com/). Actual base salary may vary based on job-related skills, experience/qualifications, interview performance, and market data. Total compensation may include equity, benefits, and (for sales roles) i
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.