Salary
💰 $155,500 - $183,000 per year
Tech Stack
JavaScriptNode.jsReactTypeScript
About the role
- We believe that mental health is just as important as physical health and are dedicated to treating the whole person
- Aim to create a world where mental health is not stigmatized and is embraced as part of overall well-being
- Provide quality, evidence-based, compassionate care to empower individuals to manage mental health
- Security Team responsible for protecting patient data and underlying technology
- Partner closely with Engineering and Product and interface across the company to embed security in culture
- Enhance security of code and development practices and improve vulnerability management with engineering and external partners
- Work will directly support better outcomes for patients and continuous learning opportunities
Requirements
- 5+ years of experience in a security engineering or related role
- 3+ years of experience in an application security engineering role
- Experience with TypeScript, JavaScript, and/or Node.js
- Experience with OWASP Top 10 and the application of those to modern systems
- Proven success with common SAST and DAST tooling and best practices
- Experience reviewing and triaging externally reported security vulnerabilities (e.g. bug bounty)
- A functional understanding of HIPAA requirements and how they apply to application security practices
- Experience with leading threat modeling exercises to identify security risks in technical designs
- Familiarity with JS front-end libraries, preferably React
- Experience interfacing with 3rd party pentesters to validate findings and develop remediation plans