Senior Application Security Engineer

Remote, USA Full-time
Hims & Hers is the leading health and wellness platform, on a mission to help the world feel great through the power of better health. We are redefining healthcare by putting the customer first and delivering access to care that is affordable, accessible, and personal, from diagnosis to treatment to delivery. No two people are the same, so we provide access to personalized care designed for results. By normalizing health & wellness challenges and innovating on their solutions, we’re making better health outcomes easier to achieve. Hims & Hers is a public company, traded on the NYSE under the ticker symbol “HIMS.” To learn more about the brand and offerings, you can visit hims.com/about and hims.com/how-it-works . For information on the company’s outstanding benefits, culture, and its talent-first flexible/remote work approach, see below and visit www.hims.com/careers-professionals . About the Role: We are seeking a Senior Application Security Engineer II to join our security team. This role will focus on ensuring the security of our applications throughout the development lifecycle, with an emphasis on modern security practices including AI/ML security considerations. You will work closely with development teams to implement secure coding practices and maintain our application security posture. You Will: Conduct security assessments using SAST, DAST, and SCA tools to identify vulnerabilities in applications Perform code reviews and provide secure coding guidance to development teams Implement and maintain GitHub Advanced Security, including secret scanning and code scanning Assess and improve security of Infrastructure as Code (IaC) deployments using Terraform Evaluate container security in our Docker and Kubernetes environments Support CI/CD security integration and automation Conduct penetration testing and red team/purple team exercises on applications Review and secure API implementations, with focus on GraphQL security Evaluate AI/ML model security and implement protections against prompt injection and other AI-specific threats Collaborate with the Staff AppSec Engineer on CIAM and advanced AI security initiatives Maintain security documentation and contribute to security awareness training You Have: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or related field 5-8 years of experience in application security or a related security field Hands-on coding experience and ability to review code in multiple languages Professional experience with SAST tools (e.g., SonarQube, Checkmarx, Fortify) Professional experience with DAST tools (e.g., Burp Suite, OWASP ZAP) Professional experience with SCA tools (e.g., Snyk, Black Duck, WhiteSource) Experience with GitHub Advanced Security features Container security scanning and IaC security scanning tools experience Strong understanding of OWASP Top 10 and secure coding practices Experience with penetration testing methodologies Knowledge of security frameworks: NIST CSF, NIST 800-53, SOC 2, PCI DSS Excellent communication skills to articulate security findings to technical and non-technical stakeholders Our Benefits (there are more but here are some highlights): Competitive salary & equity compensation for full-time roles Unlimited PTO, company holidays, and quarterly mental health days Comprehensive health benefits including medical, dental & vision, and parental leave Employee Stock Purchase Program (ESPP) 401k benefits with employer matching contribution Offsite team retreats We are committed to building a workforce that reflects diverse perspectives and prioritizes ethics, wellness, and a strong sense of belonging. If you’re excited about this role, we encourage you to apply—even if you’re not sure if your background or experience is a perfect match. Hims considers all qualified applicants for employment, including applicants with arrest or conviction records, in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, the California Fair Chance Act, and any similar state or local fair chance laws. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Hims & Hers is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please contact us at [email protected] and describe the needed accommodation. Your privacy is important to us, and any information you share will only be used for the legitimate purpose of considering your request for accommodation. Hims & Hers gives consideration to all qualified applicants without regard to any protected status, including disability. Please do not send resumes to this email address. To learn more about how we collect, use, retain, and disclose Personal Information, please visit our Global Candidate Privacy Statement .
Apply Now

Similar Jobs

Commercial Strategy & Category Manager

Remote, USA Full-time

Staff Software Engineer, Android – Telematics

Remote, USA Full-time

Full Stack Developer

Remote, USA Full-time

LLM Operations & Governance Specialist – Marketing

Remote, USA Full-time

Forward Deployed Engineer, GTM & AI – Marketing

Remote, USA Full-time

Senior Manager, Workforce Strategy

Remote, USA Full-time

Technical Sourcer, Engineering

Remote, USA Full-time

Customer Experience & Retention Specialist

Remote, USA Full-time

Java Developer

Remote, USA Full-time

Graphic Designer

Remote, USA Full-time

REMOTE Nurse Practitioner Openings - Nashville - Hendersonville - Full TIME / Weekly Compensation

Remote, USA Full-time

Experienced Part-Time Customer Service Representative – Remote Work from Home Opportunity with Teleperformance

Remote, USA Full-time

**Experienced Remote Customer Service Representative - American Express: Delivering Exceptional Customer Experiences in a Global Financial Services Leader**

Remote, USA Full-time

[Remote] America Is All In - Executive Director

Remote, USA Full-time

Experienced Movie and TV News Writer – Remote Freelance Opportunity for Passionate Entertainment Journalists

Remote, USA Full-time

Experienced Remote Chat Online Greeter – Delivering Exceptional Customer Support through Live Chat for a Leading Online Retailer at arenaflex

Remote, USA Full-time

Remote Claims Casualty Team Manager

Remote, USA Full-time

Experienced Remote Customer Service Representative - Delta Airlines' Youth Development Program

Remote, USA Full-time

Experienced Remote Customer Service Representative – Delivering Exceptional Support and Technical Expertise to Diverse Customer Base at blithequark

Remote, USA Full-time

Cybersecurity Analyst - Business Continuity

Remote, USA Full-time
Back to Home