Full-Time

Senior Application Security Engineer

Posted on 10/31/2025

hims & hers

hims & hers

1,001-5,000 employees

Telehealth platform for personalized medical treatments

Compensation Overview

$145k - $165k/yr

Remote in USA

Remote

Category
IT & Security (1)
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
  • 5-8 years of experience in application security or a related security field
  • Hands-on coding experience and ability to review code in multiple languages
  • Professional experience with SAST tools (e.g., SonarQube, Checkmarx, Fortify)
  • Professional experience with DAST tools (e.g., Burp Suite, OWASP ZAP)
  • Professional experience with SCA tools (e.g., Snyk, Black Duck, WhiteSource)
  • Experience with GitHub Advanced Security features
  • Container security scanning and IaC security scanning tools experience
  • Strong understanding of OWASP Top 10 and secure coding practices
  • Experience with penetration testing methodologies
  • Knowledge of security frameworks: NIST CSF, NIST 800-53, SOC 2, PCI DSS
  • Excellent communication skills to articulate security findings to technical and non-technical stakeholders
Responsibilities
  • Conduct security assessments using SAST, DAST, and SCA tools to identify vulnerabilities in applications
  • Perform code reviews and provide secure coding guidance to development teams
  • Implement and maintain GitHub Advanced Security, including secret scanning and code scanning
  • Assess and improve security of Infrastructure as Code deployments using Terraform
  • Evaluate container security in our Docker and Kubernetes environments
  • Support CI/CD security integration and automation
  • Conduct penetration testing and red team/purple team exercises on applications
  • Review and secure API implementations, with focus on GraphQL security
  • Evaluate AI/ML model security and implement protections against prompt injection and other AI-specific threats
  • Collaborate with the Staff AppSec Engineer on CIAM and advanced AI security initiatives
  • Maintain security documentation and contribute to security awareness training

Hims & Hers is recognized for blending telehealth convenience with a wide range of personalized medical services, from sexual health to mental health. The employment environment is backed by a commitment to technical excellence and a progressive approach to healthcare, offering opportunities to work on cutting-edge treatments that address diverse patient needs. Its culture promotes innovation and patient-centric solutions, providing a motivating workspace for professionals looking to impact healthcare accessibility and quality.

Company Size

1,001-5,000

Company Stage

Post IPO Equity

Headquarters

San Francisco, California

Founded

2017

Benefits

Full healthcare - High-coverage medical, dental & vision coverage for individuals and families

Generous PTO

Retirement planning - Take advantage of our 401(k) plan including contribution matching

WFH stipend

Robust compensation

Employee discount

Utility stipend - An extra $75 each month to cover extra cell phone, internet, or data usage

Spending accounts - Options for additional HSA and FSA plans to help toward healthcare costs

Growth & Insights

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

1%
INACTIVE