Security Applications Engineer (Quinte West)

Security Applications Engineer (Quinte West)

03 Oct
|
Strive Health
|
Quinte West

03 Oct

Strive Health

Quinte West

At Strive Health, patients come first. We’re on a mission to transform chronic conditions by identifying risk earlier, coordinating thoughtful care, and supporting people through every stage of their health journey. Our work reduces emergency visits, improves outcomes, and helps patients live fuller lives.

If you’re looking for meaningful work where your contributions truly matter, you’ll feel right at home at Strive! Hybrid-Remote Flexibility – Work from home while fulfilling in-person needs at the office, clinic, or patient home visits.

Comprehensive

Benefits – Medical, dental, and vision insurance, employee assistance programs, employer-paid and voluntary life and disability insurance, plus health and flexible spending accounts. Financial & Retirement Support – Competitive compensation with a performance-based bonus program, 401k with employer match, and financial wellness resources. Time Off & Leave – Paid holidays, vacation time, sick time, and paid birthgiving, bonding, sabbatical, and living donor leaves.

The Application Security

Engineer is responsible for embedding application security directly into Strive’s product development lifecycle, specifically supporting the deployment of Canvas Medical, patient-facing experiences, and future mobile applications. You will serve as the primary security partner for Product and Engineering, ensuring that applications are built securely from the design phase through to production. Rather than treating security as a late-stage penetration test, you will establish the requirements, review gates, testing frameworks, and remediation operating rhythms necessary to support a secure and compliant development pipeline.





Security Discovery and Threat Modeling: Perform threat modeling and establish a security baseline for internal environments, patient portals, mobile applications, and integration services. Maintain data-flow and trust-boundary diagrams, assessing identity, operational, and PHI data classifications. Collaborate with engineering teams to embed security acceptance criteria into PRDs, technical plans, and Jira stories.

Application Security Testing Framework: Design, deploy, and operate application security testing tools including SAST, DAST, Software Composition Analysis (SCA), and container/IaC scanning. Perform authenticated testing of browser workflows and APIs (e.g., Conduct manual testing for complex vulnerabilities such as privilege escalation, SSRF, and business-logic abuse. Manage the vulnerability intake pipeline, assign severities, and track remediation aligned with internal SLAs.

Lead recurring vulnerability review sessions with Security, Product, and Engineering stakeholders. Coordinate external penetration tests, including scoping, vendor selection, and tracking of remediation/retesting. Ensure all security requirements, threat models, testing evidence, and remediation documentation align with internal compliance needs (e.g., Bachelor’s degree in Computer Science, Information Security, or a related field. ~3+ years (Engineer)



to 5+ years (Senior) of experience in information security, with a robust focus on Application Security, DevSecOps, or software engineering. ~ Demonstrable experience integrating security tools into CI/CD pipelines (e.g., Experience leading or performing application threat modeling, architecture reviews, and manual security testing. ~ Ability to travel and be onsite to meet business needs.

Experience with testing and securing complex API integrations, mobile application releases, and web-based portals. Familiarity with enterprise dynamic testing tools (e.g., Burp Suite Enterprise) and automating security testing against deployed applications. Advanced certifications in application security or information security (e.g., Excellent problem-solving and analytical skills, able to assess complex application security issues and provide practical, developer-friendly solutions. capable of articulating technical risk to both technical and non-technical stakeholders.

Proactive and adaptable, comfortable embedding directly with engineering pods to shift security "left". This position is also eligible for a target annual bonus of 10% All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to talentacquisition@strivehealth.

📌 Security Applications Engineer (Quinte West)
🏢 Strive Health
📍 Quinte West

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security applications engineer (quinte west) / quinte west

Subscribe to this job alert:

Get the latest job offers by email for: security applications engineer (quinte west) / quinte west