Associate Application Security Engineer

Elation Health

Elation Health

USD 80k-100k / year

Posted on Jun 2, 2026
Elation Health is a clinical-first technology company dedicated to strengthening primary care.
We build tools that help physicians and clinicians deliver exceptional, high-quality care. Our
platform powers physician practices, health systems, and other care organizations that manage
sensitive data and depend on Elation as a critical part of their clinical workflow.

As we continue to grow, we are investing in application security to help keep our web
applications, APIs, and patient-facing experiences secure by design.

If you're excited about securing tools that help doctors and patients — and you enjoy making the
secure path the easiest path for engineers — we want to hear from you, even if you don't check
every box below!

What you'll do in your first 60 days:

  • Assist with secure design and implementation reviews for new and existing features across web applications, APIs, and backend services.
  • Monitor, triage, and help remediate findings from security tooling.
  • Get familiar with our security technologies and processes
  • Work with feature teams to understand exploitability, prioritize fixes, and track closure of vulnerabilities in alignment with internal SLAs.
  • Implement an enterprise security control and configure it for long-term observability.

Success at 6-12 months looks like:

  • You're assisting in applying key application security processes
  • You're helping shape technical direction for secure, AI-native, product-critical services handling sensitive data
  • You're supporting evidence collection for compliance audits
  • You've built strong partnerships with product, support, infrastructure, and IT to help identify and triage vulnerabilities and quickly resolve issues
  • The security improvements you've implemented are measurably reducing risk
  • You’re independently reviewing and triaging security alerts
How we work: As a member of the team, you'll contribute to the development of secure patterns
and tooling by identifying, triaging, and tracking vulnerabilities, while also independently
reviewing security alerts and supporting our incident response process to ensure security events
are resolved quickly and safely.

WHAT WE'RE LOOKING FOR

Essential:

  • Experience securing web applications and APIs, including a strong grasp of common vulnerabilities (e.g., OWASP Top 10) and practical mitigations
  • Hands-on experience with application security tooling (e.g., SAST, SCA, DAST, IaC/container scanning) and/or observability for security-relevant signals
  • Ability to communicate complex security and technical problems clearly to both technical and non-technical audiences
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Track record of delivering high-quality, pragmatic security outcomes in collaboration with product and engineering teams
  • Enthusiasm and interest in technology in general and securing systems

Valued but not required:

  • Exposure to building or securing systems with AI/LLMs (e.g., OpenAI, Anthropic)
  • Familiarity with OAuth2/OIDC, SSO, secure API design, and multi-tenant SaaS architectures.
  • Experience with coding languages such as Python and JavaScript
  • Hands-on experience with security monitoring tooling (e.g., SIEM, IPS, WAF, SASE, Network Vulnerability Scanning) and/or observability for security-relevant signals
  • Exposure with secure SDLC practices such as threat modeling, security-focused design reviews, and vulnerability management
  • Knowledge of US healthcare industry, PHI/PII protection, and health tech
EVERYONE IS WELCOME

We're committed to building a diverse and inclusive engineering and security team. Please don't
see everything in this post as a “must have” — if you're excited about this role but don't check
every box, we still want to hear from you.

We especially encourage applications from women, people of color, the LGBTQ+ community,
people with disabilities, neurodivergent people, parents, carers and people from lower socio-
economic backgrounds. If you have any requirements or accommodations that would help you
interview or work comfortably, please let us know.

Our engineering team is fully remote and brings diverse backgrounds and experiences. This role
is open to candidates in the US, Canada, and New Zealand.
Salary: $80,000 - 100,000k/yr USD

Elation welcomes individuals from all backgrounds and walks of life. Elation is proud to be an Equal Opportunity Employer and is dedicated to creating and maintaining a diverse and inclusive work environment.

We are committed to equal opportunity for all employees and applicants, and value individuals with diverse perspectives including, but not limited to: race, color, religion, sex, sexual orientation, socioeconomic status, age, gender identity or gender expression, national origin, disability or veteran status.

Elation also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. We firmly believe a strong culture that supports a diverse and inclusive workforce allows us to achieve Elation’s mission of helping independent primary care thrive.