logo inner

Senior Application Security Engineer

HeartFlowOnsite

Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease, the #1 cause of death worldwide, using cutting-edge technology. The flagship product—an AI-driven, non-invasive cardiac test supported by the ACC/AHA Chest Pain Guidelines called the Heartflow FFR
CT Analysis—provides a color-coded, 3D model of a patient’s coronary arteries indicating the impact blockages have on blood flow to the heart. Heartflow is the first AI-driven non-invasive integrated heart care solution across the CCTA pathway that helps clinicians identify stenoses in the coronary arteries (RoadMap™Analysis), assess coronary blood flow (FFRCT Analysis), and characterize and quantify coronary atherosclerosis (Plaque Analysis). Our pipeline of products is growing and so is our team; join us in helping to revolutionize precision heartcare.Heartflow is a VC-backed company that has received international recognition for exceptional strides in healthcare innovation, is supported by medical societies around the world, cleared for use in the US, UK, Europe, Japan and Canada, and has been used for more than 400,000 patients worldwide.  We are looking for a Senior Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC).

In this role, you’ll have the chance to use your security background to protect patients as we build products that leverage AI to improve healthcare. If you enjoying working with talented engineers to solve complex technical challenges and want to want to see your work make a direct difference in patient outcomes, we encourage you to apply. #LI-Remote; #LI-IB1

What You’ll Do:


  • Partner with the engineering team to define secure coding practices, threat model our products and carry out essential parts of a secure SDLC.
  • Collaborate with DevOps on identifying and implementing developer tools that support security best practices and identify security risks and vulnerabilities.
  • Drive vulnerability identification using SAST, DAST and SCA tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation and improving identification of vulnerabilities.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.
  • Translate security and privacy compliance requirements into technical requirements and support information security team through

What You Bring:


  • Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Securing SDLC – Experience building or improving secure SDLC activities, including threat modeling, code review, security testing and vulnerability management. 
  • Programming Skills  – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • Infrastructure as Code & Cloud – Familiarity with AWS (or equivalent cloud providers) and configuration tools (Terraform, Chef, Ansible). Experience with containerization (Docker, Kubernetes) and orchestration (GitHub Actions or similar).
  • Education & Experience  – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 4+ years experience working in Application Security.
  • Regulated Environment Readiness – Understanding of—or willingness to learn—compliance, documentation, and quality requirements in medical or similarly regulated fields.

What Helps You Stand Out:


  • Healthcare Experience – Current knowledge of HIPAA, HITRUST and the complexities of working in a regulated environment. Experience with Software as a Medical Device (SaMD) is especially valuable.
  • Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI.

A reasonable estimate of the base salary compensation range is $125,000 to $185,000 (for locations outside of San Francisco Bay Area) and $146,000 to $210,000 (for San Francisco Bay Area) per year, cash bonus, and stock options.Heartflow is an Equal Opportunity Employer. We are committed to a work environment that supports, inspires, and respects all individuals and do not discriminate against any employee or applicant because of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.

This policy applies to every aspect of employment at Heartflow, including recruitment, hiring, training, relocation, promotion, and termination.Positions posted for Heartflow are not intended for or open to third party recruiters / agencies. Submission of any unsolicited resumes for these positions will be considered to be free referrals.

Life at HeartFlow

HeartFlow is a medical technology company transforming the way cardiovascular disease is diagnosed and treated. With our HeartFlow Analysis, a non-invasive personalized cardiac test, physicians are able to make better care decisions for their patients with suspected coronary artery disease--the number one killer of men and women worldwide. HeartFlow is backed by decades of scientific research and development and leverages the latest advancements in technology to help set a new standard of care for diagnosing cardiovascular care worldwide. Cleared for use in the United States, Canada, Europe and Japan and with offices in Redwood City, Austin, London and Japan, HeartFlow's footprint is growing rapidly. HeartFlow has received more than $240 million dollars in funding in a recent Series E financing round, is pre-IPO and leverages the latest technology including deep learning and computational fluid dynamics. We try to embody the best of both technology and healthcare companies and hire people who are passionate about living our mission to save lives, improve the patient experience and reduce the overall cost of care. For more information, visit www.heartflow.com.
Thrive Here & What We Value1. Committed to diversity and inclusion2. Non-discrimination policy (race, color, religion, etc.)3. Equal Opportunity Employer4. Mature start-up pre-IPO marketplace leader in healthcare innovation5. Comprehensive employee benefits and programs6. International recognition for CAD diagnostics7. Supported by medical societies worldwide8. Clearance for use in multiple countries9. All-in-one solution for suspected CAD patients10. Revolutionizing precision heartcare

Related Sub

This job belongs to these sub. Explore related roles here:
Machine learning jobs
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2025