Heartflow
Application Security Engineer
About this role
Heartflow seeks an Application Security Engineer to integrate security throughout the software development lifecycle for an AI-driven medical device platform. You'll conduct code reviews, manage vulnerability identification tools, guide developers on remediation, and build security awareness within the engineering organization.
What you'll do
- Perform secure code reviews and provide hands-on technical guidance to developers on vulnerability remediation
- Drive vulnerability identification using SAST, DAST, SCA tools and manage external penetration testing
- Threat model products and implement secure SDLC practices
- Support vulnerability management including risk assessment, remediation tracking, and technical requirement translation
- Deliver security training on secure coding practices and emerging threats
- Validate false positive determinations and coach developers on effective remediation strategies
What they're looking for
- Application security and secure code review
- C++ and Python programming languages
- SAST, DAST, and SCA tools expertise
- Threat modeling and risk assessment
- CI/CD pipelines and testing frameworks
- AI development tools (Claude Code, GitHub Copilot)
- HIPAA, HITRUST, and Software as a Medical Device (SaMD) regulations
- AWS, infrastructure-as-code, Docker, and Kubernetes
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Heartflow
Heartflow develops AI-driven cardiac diagnostic software that processes medical imaging data through cloud-based algorithmic pipelines and interactive 3D visualization tools. The company is hiring software engineers to build and refine these diagnostic systems while ensuring compliance with FDA and ISO medical device standards.
View all jobs at HeartflowLikely interview questions
- Describe your experience conducting secure code reviews and how you've guided developers through vulnerability remediation in a team setting.
- Walk us through your experience with SAST, DAST, and SCA tools—which have you used most and how did you reduce false positives?