Full-Time

Staff Application Security Engineer

Posted on 10/31/2025

hims & hers

hims & hers

1,001-5,000 employees

Telehealth platform for personalized medical treatments

Compensation Overview

$175k - $200k/yr

Remote in USA

Remote

Category
IT & Security (2)
,
Required Skills
Kotlin
Python
JavaScript
React.js
Git
GraphQL
TypeScript
AWS
Go
Jenkins
Terraform
CircleCI
React Native
Requirements
  • 12+ years in software engineering, including at least 5 years focused on Application Security at a senior or staff level. Deep familiarity with modern web and mobile stacks (Node.js, React/React Native, Kotlin, npm) and Git-centric workflows.
  • Hands-on experience with SCA, SAST, DAST, and secret-scanning solutions (e.g., Tenable, Snyk, Oligo, CrowdStrike, GitHub Advanced Security).
  • Proven ability to automate security checks within Jenkins, CircleCI, and GitHub Actions pipelines, and to codify controls in Terraform.
  • Strong coding/scripting skills (JavaScript/TypeScript, Python, or Go) and experience building custom security automation.
  • Thorough understanding of the vulnerability lifecycle: triage, remediation, reporting, and trend analysis.
  • Experience securing workloads in AWS and building cloud-native guardrails.
  • Demonstrated background securing private AI/ML model deployments.
  • Expertise in API security, specifically GraphQL, and implementing protections like schema validation and rate limiting.
  • Hands-on experience architecting CIAM/IAM solutions (e.g., Auth0 or equivalent) and integrating bot-detection tools (e.g., reCAPTCHA).
  • Experience in healthcare or other highly regulated environments.
  • Excellent leadership, collaboration, and communication skills for high-visibility, cross-functional initiatives.
Responsibilities
  • Drive full-stack AppSec across web, mobile, and cloud: integrate SCA, SAST, DAST, and secret-scanning into CI/CD pipelines (Jenkins, CircleCI, GitHub Actions) and IaC workflows (Terraform), covering Node.js/React back-ends and React Native/Kotlin mobile clients.
  • Lead AI/Model Security: define and enforce security practices around private model hosting platforms (e.g., AWS model services) ensuring safe deployment and monitoring of in-house and third-party models.
  • Own API security: design and implement robust protections for REST and GraphQL endpoints, including schema validation, rate limiting, and automated vulnerability scanning.
  • Drive vulnerability management: design and tune scan configurations, interpret results, partner with developers to remediate findings, and maintain dashboards to track trends and SLAs.
  • Drive offensive security programs: perform threat modeling, internal pentests, and red-team exercises; produce detailed reports, track remediation workflows, and continuously improve tactics.
  • Lead CIAM & IAM: architect and audit customer identity and access management solutions (e.g., Auth0 or similar), integrate bot and fraud defenses (e.g., reCAPTCHA), and ensure least-privilege access throughout our user-facing and internal systems.
  • Develop policy & guidance: author secure-coding standards, CI/CD security playbooks, secret-management procedures, and comprehensive AppSec/ProductSec documentation to ensure repeatable, compliant practices.
  • Mentor & evangelize: conduct secure code reviews, deliver workshops, and cultivate a security-first mindset across engineering teams.
Desired Qualifications
  • Prior staff-level or lead role in AppSec, Product Security, or DevSecOps organizations.
  • Experience standing up or managing a red team and conducting adversary simulation exercises.
  • Knowledge of AI/ML security principles and securing machine-learning pipelines.
  • Recognized security certifications—for example, CISSP, GIAC GWAPT, OSWE, LPT.
  • Contributions to open-source security tools or thought leadership (talks, blog posts, publications).
  • Advanced degree in Computer Science, Security, or related field.

Hims & Hers is recognized for blending telehealth convenience with a wide range of personalized medical services, from sexual health to mental health. The employment environment is backed by a commitment to technical excellence and a progressive approach to healthcare, offering opportunities to work on cutting-edge treatments that address diverse patient needs. Its culture promotes innovation and patient-centric solutions, providing a motivating workspace for professionals looking to impact healthcare accessibility and quality.

Company Size

1,001-5,000

Company Stage

Post IPO Equity

Headquarters

San Francisco, California

Founded

2017

Benefits

Full healthcare - High-coverage medical, dental & vision coverage for individuals and families

Generous PTO

Retirement planning - Take advantage of our 401(k) plan including contribution matching

WFH stipend

Robust compensation

Employee discount

Utility stipend - An extra $75 each month to cover extra cell phone, internet, or data usage

Spending accounts - Options for additional HSA and FSA plans to help toward healthcare costs

Growth & Insights

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

1%
INACTIVE