Associate Application Security Engineer

elationhealth· Information Security
Apply Now ↗
🌍 Remote📍 US- Remote

About this role

 
Elation Health is a clinical-first technology company dedicated to strengthening primary care.
We build tools that help physicians and clinicians deliver exceptional, high-quality care. Our
platform powers physician practices, health systems, and other care organizations that manage
sensitive data and depend on Elation as a critical part of their clinical workflow.

As we continue to grow, we are investing in application security to help keep our web
applications, APIs, and patient-facing experiences secure by design.

If you're excited about securing tools that help doctors and patients — and you enjoy making the
secure path the easiest path for engineers — we want to hear from you, even if you don't check
every box below!

What you'll do in your first 60 days:

  • Assist with secure design and implementation reviews for new and existing features across web applications, APIs, and backend services.
  • Monitor, triage, and help remediate findings from security tooling.
  • Get familiar with our security technologies and processes
  • Work with feature teams to understand exploitability, prioritize fixes, and track closure of vulnerabilities in alignment with internal SLAs.
  • Implement an enterprise security control and configure it for long-term observability.

Success at 6-12 months looks like:

  • You're assisting in applying key application security processes
  • You're helping shape technical direction for secure, AI-native, product-critical services handling sensitive data
  • You're supporting evidence collection for compliance audits
  • You've built strong partnerships with product, support, infrastructure, and IT to help identify and triage vulnerabilities and quickly resolve issues
  • The security improvements you've implemented are measurably reducing risk
  • You’re independently reviewing and triaging security alerts
How we work: As a member of the team, you'll contribute to the development of secure patterns
and tooling by identifying, triaging, and tracking vulnerabilities, while also independently
reviewing security alerts and supporting our incident response process to ensure security events
are resolved quickly and safely.

WHAT WE'RE LOOKING FOR

Essential:

  • Experience securing web applications and APIs, including a strong grasp of common vulnerabilities (e.g., OWASP Top 10) and practical mitigations
  • Hands-on experience with application security tooling (e.g., SAST, SCA, DAST, IaC/container scanning) and/or observability for security-relevant signals
  • Ability to communicate complex security and technical problems clearly to both technical and non-technical audiences
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Track record of delivering high-quality, pragmatic security outcomes in collaboration with product and engineering teams
  • Enthusiasm and interest in technology in general and securing systems

Valued but not required:

  • Exposure to building or securing systems with AI/LLMs (e.g., OpenAI, Anthropic)
  • Familiarity with OAuth2/OIDC, SSO, secure API design, and multi-tenant SaaS architectures.
  • Experience with coding languages such as Python and JavaScript
  • Hands-on experience with security monitoring tooling (e.g., SIEM, IPS, WAF, SASE, Network Vulnerability Scanning) and/or observability for security-relevant signals
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Knowledge of US healthcare industry, PHI/PII protection, and health tech
EVERYONE IS WELCOME

We're committed to building a diverse and inclusive engineering and security team. Please don't
see everything in this post as a “must have” — if you're excited about this role but don't check
every box, we still want to hear from you.

We especially encourage applications from women, people of color, the LGBTQ+ community,
people with disabilities, neurodivergent people, parents, carers and people from lower socio-
economic backgrounds. If you have any requirements or accommodations that would help you
interview or work comfortably, please let us know.

Our engineering team is fully remote and brings diverse backgrounds and experiences. This role
is open to candidates in the US, Canada, and New Zealand.
 
Salary: $80,000 - 100,000k/yr USD
 

Elation welcomes individuals from all backgrounds and walks of life. Elation is proud to be an Equal Opportunity Employer and is dedicated to creating and maintaining a diverse and inclusive work environment.

We are committed to equal opportunity for all employees and applicants, and value individuals with diverse perspectives including, but not limited to: race, color, religion, sex, sexual orientation, socioeconomic status, age, gender identity or gender expression, national origin, disability or veteran status.

Elation also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. We firmly believe a strong culture that supports a diverse and inclusive workforce allows us to achieve Elation’s mission of helping independent primary care thrive.

Frequently Asked Questions

Is the salary disclosed for the Associate Application Security Engineer position at elationhealth?
The salary for this Associate Application Security Engineer role at elationhealth is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Associate Application Security Engineer job at elationhealth remote?
Yes, this Associate Application Security Engineer position at elationhealth is remote, with team members based in US- Remote. You can work from home or anywhere in the supported regions.
Which team or department does the Associate Application Security Engineer at elationhealth belong to?
This Associate Application Security Engineer position is part of the Information Security department at elationhealth. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Associate Application Security Engineer position at elationhealth?
Click the "Apply Now" button on this page. You will be redirected to elationhealth's official application portal hosted on greenhouse where you can submit your application directly.
When was the Associate Application Security Engineer job at elationhealth posted?
This Associate Application Security Engineer position at elationhealth was posted on Jun 1, 2026. Apply as soon as possible — early applications are often reviewed first.
Associate Application Security Engineer
elationhealth
Apply for this role ↗

You'll be redirected to elationhealth's official application page on Greenhouse.