MyFitnessPal
Application Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 4 days ago · Added today
First listed 4 days ago and still open.
Salary
$90,000 to $120,000
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote - US"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
At MyFitnessPal, we believe good health starts with what you eat. We provide tools, resources and support to enable users to reach their health goals.
We are looking for a Security Engineer II with a focus on Application Security to join the MyFitnessPal Security team. Our users rely on MyFitnessPal to power their health and fitness journeys every day, and you will leverage your technical skills to secure the code, applications, and development processes that create the MyFitnessPal product experience. In addition to technical expertise, you'll find that your teammates value collaboration, mentorship, and inclusive environments.
About the team:
The Productivity Engineering: Automation & Self-Service (PEAS) team is responsible for the automation, CI/CD, and self-service platforms that product teams rely on to build, test, and ship features quickly and safely.
The PEAS team is part of the Technology Operations (TechOps) organization, which includes IT, Infrastructure, Security, Reliability, and DevOps/DevEx disciplines. TechOps seeks to enable MyFitnessPal to "ship with confidence" by delivering a secure, reliable, and low-friction runway to build and operate software at scale. Within TechOps, you'll represent the Security discipline — protecting the applications and development processes that keep our mobile and backend software safe for millions of users.
Essential Duties:
As a Security Engineer II, you will own the day-to-day operation of our application security vulnerability management program and act as a trusted security partner to product engineering teams. You'll triage what our tooling and researchers find, drive it to remediation, and build the automation that makes the whole program run with less manual effort. This is a hands-on technical position with real ownership and substantial opportunity for growth.
What you'll be doing:
Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets through our SVM process to resolution
Operate and grow our bug bounty program — scoping engagements, triaging researcher submissions, validating findings, and coordinating with vendors
Leverage AI and agentic tooling (for example, Claude Code and agentic pipelines) to accelerate security workflows — from vulnerability triage and enrichment to automated remediation support — and help ensure our AI-assisted development practices remain secure
Build and maintain security automation (for example, in our SOAR platform and with Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces the metrics and reporting that keep the program transparent
Partner with product engineering teams on remediation — joining triage and refinement discussions, answering questions, and representing security as a business enabler rather than a blocker
Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance
Advocate secure coding practices and contribute to developer-facing security documentation and training
Administer and tune application security tooling across the SDLC, and help evaluate and implement new security technology
Support identity and access management workflows and the automation behind them
Qualifications to be successful in this role:
2-4 years of experience in security engineering, application security, software engineering, or a closely related role
Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code)
Requirements
- ·2-4 years of experience in security engineering, application security, software engineering, or a closely related role
- ·Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
- ·Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
- ·Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
- ·Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
Benefits
- ·Flexibility At Its Best: Achieve the work-life balance you deserve. Enjoy a flexible time-off policy with our Responsible Time Off benefit.
- ·Give Back: Use your volunteer days off to support what matters most to you. Each full time teammate receives 2 days per calendar year to give back to their community through service.
- ·Mentorship Program: Take control of your career through our mentorship program where, if you’d like, you will be matched with a teammate who can help you scale your skills and propel your growth.
- ·Celebrate Greatness: Your hard work deserves recognition! Our reward and recognition platform empowers peers to acknowledge and reward each other for the exceptional contributions they make.
- ·Elevate Your Health & Fitness: Get access to MyFitnessPal Premium, allowing you to take your fitness, health and wellness journey to new heights.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at MyFitnessPal, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 20h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$90,000 to $120,000 · You'll be taken to the employer's careers page.