Senior Security Engineer - Application Security at K Health
New York, NY
$150,000–$200,000
Aug 7, 2026
New York, NY
Sep 24, 2026
What this job asks for AI summary
A Senior Security Engineer focused on application security at a healthcare AI company, responsible for embedding security across the full SDLC — from architecture review and secure code standards to hands-on web/API penetration testing and automated security tooling in CI/CD pipelines. The role spans AppSec, CloudSec, and compliance (HIPAA, GDPR), requiring both deep technical execution and cross-team partnership with engineering.
Senior level · 4+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
Pay in the description: $150,000–$200,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 80 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 15–120
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 8, 2026. It is a model, not a headcount.
Why we read it this way (6)
The alt SOC (15-1252 Software Developers) is a genuine runner-up: the role requires hands-on security testing, CI/CD pipeline integration, and source-code review, giving it a strong engineering flavor — but the primary framing is security analysis and AppSec program ownership, so 15-1212 wins.
The posting is tagged '#LI-Hybrid', indicating a hybrid work arrangement at the NYC headquarters rather than fully remote.
The cloud requirement is stated as 'AWS, GCP, or Azure' — AWS is listed as the primary skill with GCP and Azure as named alternatives. GCP also appears separately in the bonus tools list.
The bonus tools section ('Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma') is explicitly framed as preferred/bonus; all items from that list are marked preferred. 'flare.io' and 'Entitle' were omitted as they are niche/obscure enough that their canonical product names could not be confirmed with confidence.
No formal degree requirement is stated anywhere in the posting.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): web application security testing, infrastructure-as-code scanning.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.