Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
HeartFlow, Inc

Application Security Engineer

HeartFlow, Inc

Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on ef…

Posted 7/14/2026Verified active Jul 25, 2026, 12:36 AMfull-timeSan Francisco • California • 🇺🇸 United States💰 $180,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Emphasize expertise in secure software development lifecycle (SDLC) practices, including secure code reviews, vulnerability management, and risk assessment. Highlight experience in programming, particularly in C++ and Python, along with familiarity with AI development tools and modern security threats.

Highest-signal resume keywords
Secure Software Development Lifecycle (SDLC)Vulnerability ManagementRisk AssessmentSecure Code ReviewsAI Development Tools

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
C++PythonSASTDASTSCA
Soft Skills
Security CommunicationTrainingCoachingRisk ReasoningStakeholder Engagement
Tools & Technologies
AI Code ToolsGithub CopilotCI/CD PipelinesTesting FrameworksIn-House AI Tooling
Certifications & Qualifications
BS in Computer ScienceRelevant Certifications
Industry Keywords
Application SecurityVulnerability RemediationThreat ModelingSecurity StandardsAI Security Threats

Tech Stack

Tools & technologies
AnsibleAwsChefCloudDockerKubernetesPythonSdlcTerraform

About the role

Key responsibilities & impact
  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.

Requirements

What you’ll need
  • Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools – Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experience – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC – Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI.