Senior Application Security Engineer

Published on April 02, 2023

Our team is dedicated to revolutionizing the mental health industry. At Spring Health, we stand by our values and are advocates for our members and employees. Together, we build with urgency and intention. We find strength in the diversity of cultural backgrounds, ideas, and experiences. United, we are open, honest, and ready to make a difference.

Our mission: to eliminate every barrier to mental health. 

Spring Health is a comprehensive mental health solution for employers and health plans. Unlike any other solution, we use clinically validated technology called Precision Mental Healthcare to pinpoint and deliver exactly what will work for each person  — whether that’s meditation, coaching, therapy, medication, and beyond. 
Today, Spring Health equips over 800 companies, from start-ups to multinational Fortune 500 corporations, as a leading and preferred mental health service. Companies like General Mills, Guardian, Bain, and Instacart use the Spring Health platform to provide mental health services to thousands of their team members globally. We have raised over $300 million from prominent investors including Kinnevik, Tiger Global, Northzone, RRE Ventures, Rethink Impact, Work-Bench, William K Warren Foundation, SemperVirens, Able Partners, True Capital Ventures, and a strategic investor, Guardian Life Insurance. Thanks to their partnership, our current valuation has reached $2 billion.
We are looking for an Application Security Engineer to be part of our Security Operations & Engineering (SecOps) team. SecOps is committed to proactively detect, respond to, simulate, and identify breach attempts and threat actors. 
You will work with a team who oversee overall enterprise security systems implementation, lifecycle (S-SDLC), and support. You will help improve the company’s ability to respond to threats through technology selection, internal product development and implementations with a heavy emphasis on automation of manual tasks and processes. We’re looking for security engineers that can work collaboratively with our security, product, infrastructure architecture and engineering teams to implement secure solutions.
What You’ll Be Doing: 
  • Improve the security throughout the systems / solutions selection, implementation, operation, and full lifecycle of the service.
  • Create detailed process management workflows to ensure security engineering activities are tracked, processes reviewed, policies are followed, and audit requirements are met.  
  • Assist peer teams in securing applications, business software and services, and infrastructure.
  • Participate in new solution requirements gathering and design development.
  • Assist with development, review, and execution of test plans to ensure effectiveness of security controls.
  • Assist teams with mitigating findings including assessment of impacts, possible solutions, and efficacy of remedies.
  • Assist with the secure integration of cloud applications and infrastructure.
  • Develop and maintain technical support/knowledge base. 
  • Develops Service Level Agreements to set expectations and measure performance. 
  • Be a member of the Incident Response Team.
  • Other duties as assigned. Management reserves the right to assign or reassign duties and responsibilities at any time.
What we expect from you:
  • You are a dedicated, highly organized and motivated person who is passionate about technology and security.
  • You are inquisitive, have a can-do attitude and a remarkable positive track record for figuring things out and getting things done.
  • You work well within a team but also individually and with little direction.
  • You can communicate effectively in both written and oral forms to technical and non-technical audiences.
  • You can work under deadlines in a fast-paced environment..
  • Experience implementing controls against various Frameworks such as NIST CSF, HIPAA, HITRUST, ISO-27001 and SOC-2
  • Strong hands-on working knowledge about modern web application architecture and how to secure it (OWASP, SANS Top 25).
  • Experience securing CI/CD pipelines enabling strong security controls through the implementation of commercial and custom built tooling.
  • Experience performing code audits on internal and open source libraries for inclusion in our products.
  • Experience with DAST, SAST, as well as manual testing techniques.
  • Experience with IaaS cloud infrastructure, container technologies, and software-oriented architecture.
  • Experience building security tools and automation in languages such as Go, JavaScript, Python, or Ruby.
  • Bachelor’s degree in Computer Science, Engineering, MIS, IT.  Or related coursework and/or equivalent work experience.
  • Minimum of 5 years of professional or technical experience in IT with a strong background in all aspects of security tools administration and incident response.
  • Must have certification, training, or educational equivalent in at least one of the following: security fundamentals, incident response, ethical hacking, or cloud security.
  • Within 18 months of hire, expected to acquire additional certifications or training as necessary (company-sponsored).
What we’d love to see as a bonus (but not required):
  • Experience with managing bug bounty programs.
  • PenTesting focused certifications.
  • 4+ years of demonstrated hands-on years experience configuring and implementing multiple cloud based security tools (e.g. SIEMs, EDR, UBA, PAM, IAM, MFA, DLP, etc.).
  • 4+ years of demonstrated hand-on experience developing, implementing, and supporting application security services consumed by product teams across cloud-based infrastructure (AWS, Azure, Google Cloud).
The target salary range for this position is $125,000 - $145,850, and is part of a competitive total rewards package including stock options, benefits, and incentive pay for eligible roles. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually at minimum to ensure competitive and fair pay.
Don’t meet every requirement? Studies have shown that women, communities of color and historically underrepresented talent are less likely to apply to jobs unless they meet every single qualification. At Spring Health we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we strongly encourage you to apply. You may be just the right candidate for this or other roles!
Ready to do the most impactful work of your life? Learn more about our values, how we work, and how hypergrowth meets impact at Spring Health: Our Values

Hypergrowth meets impact

What to expect working here:
  • You will be held accountable to an exceptionally high bar and impact
  • This may be the fastest work environment you will ever experience in terms of growth, decision-making, and time to impact
  • You will be challenged to set and protect your own boundaries
  • You will create processes & products that have never existed before
  • You will have very direct conversations and receive continuous feedback to push you to become the highest performer you can be
  • Change is a constant here: your role, team, responsibilities, and success metrics will shift as the company grows
  • You get to be surrounded by some of the brightest minds in the field  
  • You get to learn and grow at an extremely accelerated pace
  • You will experience transparency, integrity, &  humility from leadership 
  • You will be empowered to constantly challenge the status quo
  • You get the space to experiment & innovate
  • You get to make a transformational impact for the company, mental health, and for real human lives — and you will see that impact quickly
  • You will become more resourceful and resilient
  • You get to be part of a winning team that opens doors in the future

Benefits provided by Spring Health:

Focus on total health including:
  • Generous medical, dental, vision coverage available day 1 + access to One Medical
  • 20 total yearly no-cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents
  • Flexible paid time off in addition to 12 paid holidays throughout the year
  • $500 per year Wellness Reimbursement
  • Spring Health provides access to QuitGenius, a platform with technology-tailored, personalized addiction treatment plans for substance use (*QG is available to benefit-enrolled employees, spouses, and dependents age 18+)
Supporting you and your family:
  • 4-4.5 months of fully paid parental leave
  • Spring Health provides team members and their families with sponsored access to Bright Horizons® child care, back-up care, and elder care.
  • Access to Joshin is provided by Spring Health. Joshin is a comprehensive support system for disabilities and neurodivergence in the workplace. This benefit supports employees, their families, and our teams through personalized navigation and disability education and training along with a network of screened in-home caregivers with disability and neurodivergent experience. 
Supporting you financially through:
  • Our People team benchmarks all salaries using the Radford Global Compensation Database for technology and life sciences industries. Radford benchmarks salaries with 3,589 global firms, 6.5 million employees, and 98 countries across the globe. We do this to ensure all of our team members are paid equally and competitively.
  • On top of competitive and benchmarked salary, Spring Health offers incentive pay (based on role), and equity that begins vesting as we celebrate your first year with the company!
  • Employer sponsored 401(k) match of up to 2% after 90 days of employment
Creating a culture you can thrive in:
  • Flexible work arrangements: 60% of Spring Health team members work fully remote while 40% work in a hybrid model from our New York City offices
  • Calm Fridays: no meetings, no distractions, just time for you to get work done.
  • Up to $1,000 Professional Development Reimbursement per calendar year. Any requests over $250 must be requested for pre-approval prior to enrollment by sending an email to the People Team. 
  • $200 per year donation matching to support your favorite causes
Spring Health is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements. Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you have a disability or special need that requires accommodation, please let us know.