Senior Software Engineer, Information Security
Job description
Senior Software Engineer, Information Security at commure.
About the role
We are seeking an application security engineer to improve how we protect our AI-driven healthcare platform. You will work directly with our engineering teams to build automated defenses and fix systemic vulnerabilities within our codebase. This position focuses on proactive engineering and tool creation rather than traditional compliance auditing.
Key facts
What you'll do
- Analyze our engineering workflows and code to locate and resolve systemic security weaknesses.
- Develop and integrate security automation tools, such as custom static analysis and SCA pipelines.
- Perform security design reviews and code audits for our agentic AI systems and data infrastructure.
- Lead threat modeling sessions to provide actionable security guidance for product teams.
- Evaluate how AI-accelerated development impacts our risk profile and implement relevant security measures.
- Communicate our security posture to enterprise healthcare clients.
Requirements
- 5+ years of professional experience in software engineering or application security.
- Ability to read and debug complex codebases to identify root causes of security issues.
- Proficiency in core security concepts including threat modeling, secure code reviews, and OWASP standards.
- Capacity to work independently in a fast-paced environment.
- Ability to work from the Mountain View office 3 days per week.
- Strong communication skills for cross-functional collaboration.
Nice to have
- Experience with the security of LLMs or agentic AI systems.
- Background in building custom static analysis rules or SAST pipelines.
- Knowledge of healthcare regulations such as HIPAA and handling PHI.
- Offensive security experience, including bug bounties, pentesting, or CTFs.
- Experience interacting directly with enterprise customers.
Skills & tools
- SAST/SCA tools
- Threat modeling
- Secure code review
- AI/LLM security principles
Practical notes
All official correspondence will originate from an email address ending in @commure.com. Employees are required to adhere to all internal information security policies, including the protection of organizational assets and the reporting of potential security risks. Compliance with these policies must be attested to upon hiring and annually thereafter.