About the role:
We are seeking an Application Security Analyst to build security into how we ship software, and to help our small but growing Information Security team with day-to-day work. This is a hands-on role. You will secure code, fix pipelines, manage security tools and requests and also help us stay ready for audits like PCI, HIPAA, and HITRUST.
You will work closely with engineering teams to embed security into development pipelines, implement testing and runtime protections, and ensure that AI/ML components are resilient against emerging threats.
This is a great fit for someone who likes both building and securing things, and who doesn't mind wearing more than one hat on a small team.
Key responsibilities:
Perform application security assessments using SCA, SAST, Secrets management, and interactive testing tools
Identify, triage, and prioritize vulnerabilities
Integrate security testing into CI/CD pipelines (DevSecOps)
Assess security risks in AI/ML-enabled applications, including model exposure and inference endpoints
Secure AI APIs, plugins, and third-party integrations
Tune security controls across technologies such as WAF, EDR, MDM, and cloud
Conduct threat modeling and secure design reviews for applications and AI use cases
Assess and harden identity and access flows ensuring least privilege
Automate repetitive security tasks so the team can focus on higher-value work
Partner with developers to remediate vulnerabilities and improve secure coding practices
Monitor and respond to security incidents as part of an on-call rotation
What you'll need:
Minimum of 2+ years of experience in Application Security or Product Security
Hands-on experience with secure code scanning tools such as SCA and SAST
Strong knowledge of OWASP Top 10 vulnerabilities
Experience securing APIs and microservices
Familiarity with CI/CD pipelines
Basic understanding of AI/ML systems
Cloud security experience
Scripting skills (Python, Bash)
Good communication skills — you'll work with engineers, and sometimes explain things to non-technical people
A security mindset: you think about how things can break, not just how to make them work
Preferred Qualifications:
Experience with ML frameworks is a plus
Familiarity with AI threat models
Experience with WAF or API security solutions
Strong coding skills in at least one language (Python, Bash, or similar)
Experience in ecommerce, healthcare or another highly regulated industry
Note for Current Employees:
Please use the internal job board in Greenhouse to apply. Applications submitted through this external link will not be tagged as internal.
Compensation, Benefits, & Additional Details:
Health-E Commerce's compensation philosophy is grounded in market data and internal equity to ensure fairness and consistency across the team. Individuals new to the company should generally expect offers to fall between the entry point and midpoint of the salary range. Our goal is to provide an offer that supports growth potential within the role and allows for future salary progression.
Compensation: $75,000 - 95,000
Discretionary Annual Bonus Eligibility: Up to 10%
Medical, Dental, Vision, and 401K with a company match
Dependent Care, FSA & HSA accounts
Paid Parental & Bonding Leave
Flexible PTO & office closure on all major holidays
Monthly wellness & internet reimbursements
Professional development including certification support & leadership coaching
Mental Health resources
100% remote within the United States
Must be able to work EST hours
Candidate Privacy Notice
Health-E Commerce operates FSAstore and HSAstore, two ecommerce platforms specializing in flexible spending account (FSA) and health savings account (HSA) eligible products. The company focuses on providing personalized shopping experiences and optimizing customer journeys across their storefronts to drive revenue growth and customer engagement. Their business centers on the health and wellness retail sector, serving consumers seeking tax-advantaged purchasing options for eligible health products.