We are seeking an Application Security Analyst to build security into how we ship software, and to help our small but growing Information Security team with day-to-day work. This is a hands-on role. You will secure code, fix pipelines, manage security tools and requests and also help us stay ready for audits like PCI, HIPAA, and HITRUST.You will work closely with engineering teams to embed security into development pipelines, implement testing and runtime protections, and ensure that AI/ML components are resilient against emerging threats.This is a great fit for someone who likes both building and securing things, and who doesn't mind wearing more than one hat on a small team.Key responsibilities:Perform application security assessments using SCA, SAST, Secrets management, and interactive testing toolsIdentify, triage, and prioritize vulnerabilitiesIntegrate security testing into CI/CD pipelines (DevSecOps)Assess security risks in AI/ML-enabled applications, including model exposure and inference endpointsSecure AI APIs, plugins, and third-party integrationsTune security controls across technologies such as WAF, EDR, MDM, and cloudConduct threat modeling and secure design reviews for applications and AI use casesAssess and harden identity and access flows ensuring least privilegeAutomate repetitive security tasks so the team can focus on higher-value workPartner with developers to remediate vulnerabilities and improve secure coding practicesMonitor and respond to security incidents as part of an on-call rotationWhat you'll need:Minimum of 2+ years of experience in Application Security or Product SecurityHands-on experience with secure code scanning tools such as SCA and SASTStrong knowledge of OWASP Top 10 vulnerabilitiesExperience securing APIs and microservicesFamiliarity with CI/CD pipelinesBasic understanding of AI/ML systemsCloud security experienceScripting skills (Python, Bash)Good communication skills — you'll work with engineers, and sometimes explain things to non-technical peopleA security mindset: you think about how things can break, not just how to make them workPreferred Qualifications:Experience with ML frameworks is a plusFamiliarity with AI threat modelsExperience with WAF or API security solutionsStrong coding skills in at least one language (Python, Bash, or similar)Experience in ecommerce, healthcare or another highly regulated industryCompensation, Benefits, & Additional Details:Health-E Commerce's compensation philosophy is grounded in market data and internal equity to ensure fairness and consistency across the team. Individuals new to the company should generally expect offers to fall between the entry point and midpoint of the salary range. Our goal is to provide an offer that supports growth potential within the role and allows for future salary progression.Compensation: $75,000 - 95,000Discretionary Annual Bonus Eligibility: Up to 10%Medical, Dental, Vision, and 401K with a company matchDependent Care, FSA & HSA accountsPaid Parental & Bonding LeaveFlexible PTO & office closure on all major holidaysMonthly wellness & internet reimbursementsProfessional development including certification support & leadership coachingMental Health resources100% remote within the United StatesMust be able to work EST hours