Security Engineer – Application Security
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• Strong understanding of application security principles and OWASP Top 10. • Experience implementing secure coding practices and enabling developer security adoption. • Hands-on experience with SAST, DAST, and SCA tools. • Experience integrating security into CI/CD pipelines. • Familiarity with compliance frameworks such as ISO 27001, NIST CSF, and HIPAA. • Distributed and Remote First • Neko Health has nearly 100 full-time engineers working across Berlin, Chamonix, Hamburg, Lisbon, Marseille, Vilnius, and Stockholm, spanning disciplines such as Hardware Engineering, Firmware Development, Electrical Design, Algorithm Development, Machine Learning, Optronics Research, and Software Engineering. • Our technology stack includes React, TypeScript, C++, Python, and C# with ASP.NET Core. We use Azure Cosmos DB and Azure Active Directory for authentication. • We are a Remote-First company, though some hardware and firmware roles require occasional access to physical devices. Software engineers in Stockholm typically work from the office once every one to two weeks. Teams meet in person several times per year for collaboration and team connection. • Organization and Way of Working • Engineering teams are structured into small, cross-functional groups aligned to specific goals. Some teams are long-lived while others are formed for targeted initiatives. Teams aim to operate autonomously while collaborating across the organization when necessary. • Goals are tracked quarterly and annually, with bi-weekly organization-wide progress reviews. Most teams operate on a bi-weekly planning cadence, though each group has flexibility in how they work. • All teams present progress, learnings, and experiments during bi-weekly engineering demos, covering topics ranging from hardware and calibration challenges to infrastructure improvements, backend capabilities, and data innovations that enhance clinical productivity. • Neko Health supports a flexible workplace that prioritizes work-life balance. We are deeply committed to our mission while believing meaningful impact should not require sacrificing personal wellbeing. • We use a simplified internal title framework that prioritises clarity over hierarchy, so internal titles may differ from market‑facing role titles. Scope, impact and level of the role are fully aligned and will be clearly discussed throughout the process. • Candidates progress from application and structured screening through thoughtfully designed interviews culminating in a formal offer and final pre-employment checks before joining the team. • Equal Opportunity & Inclusion Statement • Neko Health is committed to inclusive hiring and member-first care. We welcome candidates from all backgrounds and encourage you to request reasonable adjustments to support your application.
Responsibilities
• Drive adoption and continuous improvement of Secure Software Development Lifecycle (SSDLC) practices. • Perform code reviews and vulnerability assessments for critical applications. • Integrate and manage SAST, DAST, and SCA tools within CI/CD pipelines. • Conduct threat modelling for new features, services, and products. • Collaborate with developers to remediate vulnerabilities and promote secure coding practices. • Maintain audit-ready security and compliance documentation.