Senior Application Security Engineer

Posted 3 Days Ago
Be an Early Applicant
Mountain View, CA, USA
Hybrid
160K-190K Annually
Senior level
Information Technology • Software
The Role
Work directly with engineering to identify systemic application security gaps, build SAST/SCA tooling and custom static analysis, perform secure code and design reviews, threat model new features (including agentic AI/LLM systems), and present security posture to enterprise healthcare customers.
Summary Generated by Built In

At Commure, we're building the AI Operating System for healthcare, the foundation that defines how care is delivered, documented, and financed. Our platform spans the full care journey: Ambient AI and Dictation eliminating documentation burden at the point of care, intelligent Agents automating patient and revenue workflows, and autonomous RCM processing billions in claims, all on a single AI-native platform integrated with 60+ EHRs.

Healthcare carries a $1 trillion administrative burden and we're at the center of transforming it. Today, 500,000+ clinicians across 500+ healthcare organizations nationwide trust Commure to handle $25B+ in annual claims and support over 200 million patient interactions. Our latest $70M raise at a $7B valuation reflects the confidence the market has placed in this mission. We've also been named to the Fortune Future 50 list and the 2026 AI Breakthrough Awards for “Overall NLP Company of the Year.”

Our team works directly alongside clinicians, not through layers of process, which means the gap between what you build and its impact on patient care is immediate. We move fast, deploy daily, and take full ownership from early thinking to production. If you're energized by hard problems, high stakes, and a team that holds itself to a high bar, you'll find your people here.

The future of healthcare is being built right now. Come deliver this transformation.

About the Role

Security patterns that worked 20 years ago don't hold up anymore, especially as AI changes how fast engineering teams ship code. We're looking for an Application Security Engineer who combines real engineering depth with security fundamentals — someone who gets into the code, spots systemic patterns, and builds the tooling and fixes that address them at scale, rather than flagging issues for someone else to resolve.

This isn't an audit-from-a-distance role. You'll work directly with engineering, with no interim layer needed, and you'll be equally comfortable owning a project end-to-end as you are looping in support when it counts.

Full Time position requires working 3 days a week in our Mountain View office (Hybrid)

What You'll Do
  • Identify systemic security gaps in our codebase and engineering workflows, and drive durable fixes with engineering, not just one-off patches

  • Build security tooling and automation, including SAST/SCA integration and custom checks, that catches issues earlier rather than after they ship

  • Conduct code reviews and security design reviews for major product initiatives, including agentic AI systems and data pipelines

  • Drive threat modeling for new features and translate requirements into guidance engineers actually use

  • Think through what AI-accelerated development means for how we find, prioritize, and fix risk, and use AI tooling where it genuinely helps

  • Present our security posture to enterprise customers, including healthcare and regulated-data conversations

What You Have
  • 5+ years of hands-on application security or software engineering experience, not mainly audit or compliance work

  • Genuine engineering depth: you can read and reason about code well enough to find real bugs and root causes

  • Strong AppSec fundamentals: threat modeling, secure code review, and OWASP-aligned vulnerability knowledge

  • Comfort operating independently with good judgment in a fast-moving environment

  • Clear communication that earns trust with engineers

Nice to Have
  • Experience securing agentic AI or LLM-powered systems

  • Experience building SAST pipelines or custom static analysis rules

  • Healthcare or other regulated-industry security experience (PHI, HIPAA)

  • Offensive security background (bug bounty, CTF, pentesting)

  • Direct enterprise customer experience

Please be aware that all official communication from us will come exclusively from email addresses ending in @commure.com. Any emails from other domains are not affiliated with our organization.


Employees will act in accordance with the organization’s information security policies, to include but not limited to protecting assets from unauthorized access, disclosure, modification, destruction or interference nor execute particular security processes or activities. Employees will report to the information security office any confirmed or potential events or other risks to the organization. Employees will be required to attest to these requirements upon hire and on an annual basis.

Skills Required

  • 5+ years hands-on application security or software engineering experience (not primarily audit/compliance)
  • Willingness to work hybrid: 3 days per week in Mountain View office
  • Ability to read and reason about code to find bugs and root causes (engineering depth)
  • Strong AppSec fundamentals: threat modeling, secure code review, OWASP-aligned vulnerability knowledge
  • Comfort operating independently with good judgment in a fast-moving environment
  • Clear communication that earns trust with engineering teams
  • Experience securing agentic AI or LLM-powered systems
  • Experience building SAST pipelines or custom static analysis rules
  • Healthcare or regulated-industry security experience (PHI, HIPAA)
  • Offensive security background (bug bounty, CTF, pentesting)
  • Direct enterprise customer experience (presenting security posture to customers)

Commure Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Commure and has not been reviewed or approved by Commure.

  • Fair & Transparent Compensation Pay is considered generally market‑aligned for many roles, with engineering and senior IC/manager ranges consistent with venture‑backed health tech and major metros. Sales packages also show competitive base and OTE structures for SDRs and AEs.
  • Healthcare Strength Core medical, dental, and vision coverage is offered, complemented by access to One Medical for convenient primary care. These elements position the health offering as robust for a mid‑size tech employer.
  • Leave & Time Off Breadth Flexible/unlimited PTO with sick time and company holidays is provided. Parental leave is included, expanding time‑off options for different life events.

Commure Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
159 Employees
Year Founded: 2017

What We Do

Healthcare modernization doesn’t require a silver bullet looking to disrupt, it needs 1,000+ innovative solutions working together. Commure is mending fragmentation by uniting innovators across the health ecosystem to transform care with consumer-centric, data-driven digital and physical health at scale. With our universal platform and common architecture, we’re on a path to enable a system of health assurance that keeps people well while bending costs. Join us, and replace disruption with hyper-connected innovation: visit www.commure.com/careers. Commure was hatched at General Catalyst, which has backed healthcare companies such as Livongo, Oscar, Mindstrong, and Color.

Similar Jobs

Beyond Finance Logo Beyond Finance

Application Security Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
140K-165K Annually

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
160K-250K Annually

Monolithic Power Systems Logo Monolithic Power Systems

Application Security Engineer

Automotive • Cloud • Software • Industrial • Manufacturing
In-Office
2 Locations
1120 Employees
120K-150K Annually

Satellogic Inc. Logo Satellogic Inc.

Application Security Engineer

Aerospace • Artificial Intelligence • Defense • Manufacturing
Remote or Hybrid
USA
570 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account