New York, NY

Salary
$150,000–$200,000
Posted
Aug 7, 2026
Location
New York, NY
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A Senior Security Engineer focused on application security at a healthcare AI company, responsible for embedding security across the full SDLC — from architecture review and secure code standards to hands-on web/API penetration testing and automated security tooling in CI/CD pipelines. The role spans AppSec, CloudSec, and compliance (HIPAA, GDPR), requiring both deep technical execution and cross-team partnership with engineering.

Senior level · 4+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time

Pay in the description: $150,000–$200,000

Must have (10)
OWASP Top 10API security testingCI/CDSASTDASTsecrets detectioncontainer securityAWS, GCP or AzureHIPAAGDPR
Nice to have (7)
DatadogSumo LogicTorqOktaOrcaGitLabPrisma Cloud

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 80 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 15–120

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
GDPR12%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 8, 2026. It is a model, not a headcount.

Why we read it this way (6)

The alt SOC (15-1252 Software Developers) is a genuine runner-up: the role requires hands-on security testing, CI/CD pipeline integration, and source-code review, giving it a strong engineering flavor — but the primary framing is security analysis and AppSec program ownership, so 15-1212 wins.

The posting is tagged '#LI-Hybrid', indicating a hybrid work arrangement at the NYC headquarters rather than fully remote.

The cloud requirement is stated as 'AWS, GCP, or Azure' — AWS is listed as the primary skill with GCP and Azure as named alternatives. GCP also appears separately in the bonus tools list.

The bonus tools section ('Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma') is explicitly framed as preferred/bonus; all items from that list are marked preferred. 'flare.io' and 'Entitle' were omitted as they are niche/obscure enough that their canonical product names could not be confirmed with confidence.

No formal degree requirement is stated anywhere in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): web application security testing, infrastructure-as-code scanning.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗