Skip to content
NexHealthNexHealth

Senior Software Engineer, Security

Builds and secures backend systems for APIs, EHR integrations, and payments infrastructure. Leads threat modeling, vulnerability remediation, and security tooling integration in AWS/Google Cloud environments. Requires 5+ years engineering with security focus.

About the job

What You’ll Do

  • Design and build secure systems across our APIs, EHR integrations, payments infrastructure, and SaaS products
  • Lead threat modeling and security design reviews for new features — embedded in the development process, not bolted on at the end
  • Identify and remediate vulnerabilities in application code, dependencies, and infrastructure
  • Improve authentication, authorization, and access control systems across our platform (OAuth, RBAC, service-to-service auth)
  • Integrate and maintain security tooling in our CI/CD pipelines — SAST, DAST, dependency scanning
  • Contribute to secure coding standards, internal libraries, and developer-facing security frameworks
  • Support HIPAA and SOC 2 compliance through strong system design and documentation
  • Help raise the security bar across the engineering org through code reviews, education, and pairing with developers

What You’ll Bring

  • 5+ years of software engineering experience, with 1–3+ years focused on application or product security
  • Experience building and securing backend systems in Python, Go, Java, or similar languages
  • Solid understanding of common vulnerabilities and mitigations (OWASP Top 10 and beyond)
  • Hands-on experience securing APIs and implementing authentication/authorization systems (OAuth 2.0, JWT, RBAC)
  • Experience working in cloud environments — we run on AWS and Google Cloud
  • Familiarity with security tooling: SAST, DAST, dependency scanning
  • Bachelor's degree in Computer Science, Engineering, or equivalent practical experience

Compensation

Base salary: $165,000—$230,000 USD

Benefits:

  • Full Medical, Dental, and Vision (up to 100% covered)
  • 401K and commuter benefits
  • Flexible PTO

Skills

Python, Go, Java, Oauth 2.0, Jwt, RBAC, Owasp Top 10, AWS, GCP, SAST, DAST, CI/CD

Upstart

Upstart

United States

Senior Application Security Engineer
$167k+/yrRemote5+ YOESecurity Engineering

Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Censys

Censys

United States

Research Systems Analyst
$170k+/yrRemote6+ YOESecurity Engineering

Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.

Flex

Flex

United States

Senior Software Engineer, Security
$170k+/yrRemote5+ YOESecurity Engineering

Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.