FlexHired LogoFlexHired
Logo of Rula

Rula

Sr. Application Security Engineer (Remote)

Job Summary

This role is focused on application security within a mental healthcare platform, working closely with engineering and product teams to enhance security measures and vulnerability management. The candidate should have over four years of experience in application security, familiarity with modern programming languages, and knowledge of security best practices like OWASP Top 10 and threat modeling. The position offers a fully remote work environment with comprehensive health benefits, generous time-off policies, and various employee support programs. The team values diversity, inclusion, and fostering a culture of safety and belonging.

Required Skills

React
Vulnerability Management
Security Testing
Threat Modeling
Application Security
SAST
DAST
OWASP Top 10
Bug Bounty
HIPAA

Benefits

Health Insurance
Paid Time Off
Remote Work
Parental Leave
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Employee Assistance Program
Wellness Events
401(k)
Home Office Stipend
FSA/HSA
Team Stipend
Community and Employee Resource Groups

Job Description

We believe that mental health is just as important as physical health. We recognize that mental health issues can be complex and multifaceted, and we are dedicated to treating the whole person, not just the symptoms.

We aim to create a world where mental health is no longer stigmatized or marginalized, but rather is embraced as an integral part of one's overall well-being.

We believe that by providing quality care that is both evidence-based and compassionate, we can empower individuals to take charge of their mental health and achieve their full potential. We are passionate about making a positive impact on the lives of those struggling with mental health issues and we strive to be a force for positive change in the field of mental healthcare.

About the Role

The Security Team at Rula is responsible for ensuring the protection of patient data and all of the technology behind our platform. We maintain close partnerships with Engineering and Product teams, but interface with everyone across the company to ensure that security is a core component of Rula’s culture. In this role, you’ll have the opportunity to enhance the security of our code and development practices, and enhance our vulnerability management program with Engineering and external partners. Overall, you’ll encounter endless learning opportunities and pursue projects that will leverage and refine your skills. More importantly, the work you do will help ensure the best outcomes for patients as we strive to make mental healthcare work for everyone.

Required Qualifications

  • 4+ years of experience as an application security engineer

  • Experience with JavaScript, TypeScript, Node.js, and/or Ruby

  • Demonstrated success applying OWASP Top 10 recommendations to modern application stacks

  • Experience with common SAST and DAST tooling and best practices

Preferred Qualifications

  • Experience launching and/or managing a bug bounty program

  • An understanding of HIPAA requirements and how they apply to application security

  • Established success leading threat modeling exercises to identify security risks in technical designs

  • Experience with JS front-end libraries, preferably React

  • Experience interfacing with 3rd party pentesters to validate findings and develop remediation plans

We're serious about your well-being! As part of our team, full-time employees receive:

  • 100% remote work environment (US-based only):Working hours to support a healthy work-life balance, ensuring you can meet both professional and personal commitments

  • Attractive pay and benefits: Full transparency of pay ranges regardless of where you live in the United States

  • Comprehensive health benefits: Medical, dental, vision, life, disability, and FSA/HSA

  • 401(k) plan access: Start saving for your future

  • Generous time-off policies: Including 2 company-wide shutdown weeks each year for self-care (for most employees)

  • Paid parental leave: Available for all parents, including birthing, non-birthing, adopting, and fostering

  • Employee Assistance Program (EAP): Support for your mental and physical health

  • New hire home office stipend: Set up your workspace for success

  • Quarterly department stipend: Fund team-building activities or in-person gatherings

  • Wellness events and lunch & learns: Explore a variety of engaging topics

  • Community and employee resource groups: Participate in groups that celebrate employee identity and lived experiences, fostering a sense of community and belonging for all

Our team

We believe that diversity, equity, and inclusion are fundamental to our mission of making mental healthcare work for everyone. We are dedicated to having a culture of inclusion that will support our employees in feeling safe, seen, heard, and valued.

Interested in this job?

Application deadline: Open until filled

Logo of Rula

Rula

Affordable online therapy where you are, on your schedule. Easily find a therapist covered by your insurance.

See more jobs
Date PostedMarch 28th, 2025
Job TypeFull Time
LocationRemote - United States
Salary$162,900 - $191,600
Exciting remote opportunity (requires residency in United States) for a Sr. Application Security Engineer (Remote) at Rula. Offering $162,900 - $191,600 (full time). Explore more remote jobs on FlexHired!

Safe Remote Job Search Tips

Verify Employer Thoroughly

Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.

Never Pay to Get a Job

Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.

Safeguard Your Personal Information

Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.

Scrutinize Communication & Interviews

Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.

Beware of Unrealistic Offers

If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.

Insist on a Formal Contract

Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.

Related Jobs

Full Time
$168,000 - $180,000
Remote - United States
Full Time
$164,200 - $229,900
Remote - United States
Full Time
$140,400 - $224,250
Remote - United States
Full Time
$140,400 - $224,250
Remote - United States
Full Time
$140,400 - $224,250
Remote - United States

Subscribe Newsletter

Never miss a remote job opportunity. Subscribe to our newsletter today and receive exclusive job alerts, career advice, and industry insights delivered straight to your inbox.