Application Security Engineer
Heartflow · San Francisco, CA
$145,000–$180,000from the description
Jul 14, 2026
San Francisco, CA
Jul 21, 2026
What this job asks for AI summary
An application security engineer role embedded within a software engineering team, focused on securing the full development lifecycle for AI-powered medical imaging products. Day-to-day work spans secure code review, threat modeling, vulnerability management using SAST/DAST/SCA tooling, and coaching developers on remediation. Suited to someone with a software development background who has moved into application security and is comfortable working in a regulated, healthcare-adjacent environment.
Mid level · 5+ years · San Francisco-Oakland-Berkeley, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 8 people in the San Francisco-Oakland-Berkeley, CA area plausibly meet what this posting asks for (information security analysts). range 5–15
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $165,879 (middle half $117,529–$206,125). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The role sits at the intersection of application security and software development — the JD explicitly values a 'software development background' and requires coding proficiency alongside AppSec duties. 15-1212 (Information Security Analysts) was chosen as primary because the core mandate is securing the SDLC, not shipping product features; 15-1252 is a credible runner-up given the hands-on coding and CI/CD expectations.
Seniority is assessed as Mid despite 5+ years total experience: only 1 year of dedicated AppSec is required, the scope is individual-contributor within an engineering team, and no org-wide or cross-team technical authority is described. The title carries no level modifier.
Python and C++ are listed as the languages Heartflow uses in a parenthetical under the programming requirement; they are treated as a single interchangeable gate (at least one modern language required) with Python as primary and C++ as the alternative.
AI code tools (Claude Code, GitHub Copilot) appear under the 'What You Bring' required section and are treated as a single interchangeable gate.
Cloud/IaC/containerization skills (AWS, Terraform, Docker, Kubernetes, GitHub Actions) and healthcare compliance knowledge (HIPAA, HITRUST, SaMD) all appear under 'What Helps You Stand Out' — the preferred/nice-to-have section.
The degree requirement is None: the JD explicitly accepts 'relevant certifications and equivalent experience' as an alternative to a BS in Computer Science.
Compensation includes bonus and equity in addition to the stated base salary range.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.