Senior Application Security Engineer at Clover Health
$134,600–$175,000
Aug 5, 2026
—
Sep 24, 2026
What this job asks for AI summary
A hands-on offensive security role at a healthcare technology company, focused on finding and closing vulnerabilities in a primary care AI platform used by thousands of practitioners. The engineer will conduct penetration testing, build custom security tooling, harden services, monitor for PHI exposure, review code across teams, and mentor engineers — with a particular emphasis on leveraging AI to scale vulnerability discovery.
Senior level · 8+ years · Remote · Full-time
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 560 people nationally plausibly meet what this posting asks for (information security analysts). range 120–850
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 7, 2026. It is a model, not a headcount.
Why we read it this way (6)
The role sits at the intersection of offensive security (penetration testing, vulnerability research) and software engineering (custom tooling, full-stack coding), making it a genuine hybrid between 15-1212 Information Security Analysts and 15-1252 Software Developers. The primary day-to-day framing is security analysis and offensive research, so 15-1212 was chosen, with 15-1252 as the runner-up.
The JD states 8+ years in software engineering overall and 4+ years focused on application security — the overall years minimum is set to 8 (the broader gate); the 4-year security-specific requirement is reflected on the relevant skills.
No compensation figures are disclosed despite a mention of 'competitive base salary and equity.'
The posting references the San Francisco Fair Chance Ordinance, suggesting SF/Bay Area as a legal anchor, though the role is explicitly remote-first.
The JD does not name specific programming languages, security frameworks (e.g., Burp Suite, OWASP), or cloud platforms — only generic categories ('a number of different programming languages', 'tools, agents, and frameworks'). No concrete named technologies beyond these categories were stated, so no additional skill entries were created to avoid inventing requirements the posting does not specify.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): site reliability engineering collaboration.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.