bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesArtera 2Senior Application Security Engineer, AI & Product Security

Senior Application Security Engineer, AI & Product Security

Artera 2 · Seattle, Washington · Hybrid · Active · $146,000–$175,000 / year · Lever

Job facts

FieldValue
CompanyArtera 2
TitleSenior Application Security Engineer, AI & Product Security
Normalized title-
Department / teamEngineering / Security
LocationSeattle, WA, United States
Work modelHybrid / Hybrid
Employment typeFull Time
Salary$146,000–$175,000 / year
Statusactive
ATS providerLever
Posted / first seen2026-05-15 / 2026-05-29
Changed / last seen2026-06-03 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Artera 2.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Seattle.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyArtera 2
Source194a4761-1929-47d8-9917-8118c4beaafb
ATS providerLever

Description

ABOUT ARTERA Our Mission: Make healthcare #1 in customer service. What We Deliver: Artera is an agentic company strengthening how healthcare providers communicate and care for patients. As an agentic partner, we bring over a decade of healthcare experience to address urgent workflows from day one and build custom solutions as healthcare providers’ needs evolve. Trusted by 1,000+ specialties, FQHCs, health systems, and federal agencies, Artera strengthens and protects and enhances patient relationships across every interaction - from intake and scheduling to referral management, post-visit care, and more. Hear from our CEO, Guillaume de Zwirek, about why we are standing at the edge of the biggest technological shift in healthcare’s history! Our award-winning culture: Our award-winning culture: Since founding in 2015, Artera has consistently been recognized for its innovative technology, business growth, and named a top place to work. Examples of these accolades include: Inc. 5000 Fastest Growing Private Companies (2020, 2021, 2022, 2023, 2024); Deloitte Technology Fast 500 (2021, 2022, 2023, 2024, 2025); Built In Best Companies to Work For (2021, 2022, 2023, 2024, 2025, 2026). Artera has also been recognized by Forbes as one of “America’s Best Startup Employers,” Newsweek as one of the “World’s Best Digital Health Companies,” and named one of the top “44 Startups to Bet your Career on in 2024” by Business Insider. Applicants must be currently authorized and have the ability to provide proof of full-time, long-term authorization to work in the United States. We are unable to provide visa sponsorship or support visa transfers now or in the future. ABOUT THE OPPORTUNITY Artera is seeking a hands-on Application Security Engineer to work alongside our AI builders and Systems Engineers to threat-model agentic and LLM-powered features, harden PHI/PII-handling workflows, and ship the "paved road" tooling (secure SDLC guardrails, prompt/agent-identity patterns, SAST/DAST/SCA in CI/CD) that keeps innovation fast and safe. This is a frontier role. You'll be operating where AI security is still being defined — translating policy into code, building guardrails for agent identity and prompt/output filtering, and giving our team the logging, scanning, and safe tool-use patterns. Artera Security finds the secure path and ships it with our AI Builders and System Engineers. This role is based in our Seattle, WA office. In-person collaboration is intentional – you'll be working shoulder-to-shoulder with our AI builders, Systems Engineers, and security leadership as we build Artera's Seattle tech hub. This role supports federal-facing systems and contributes to enterprise security functions. Candidates must meet eligibility for a government background check and follow strict data protection, access control, and incident response protocols. Familiarity with regulatory frameworks is expected. Ongoing compliance training and evidence-based documentation may be required. OUR APPROACH TO WORK LOCATION At Artera, we believe the best work happens when people are truly connected. Our AI services model has shown what’s possible when small, focused teams move fast together — the speed of collaboration, pace of career growth, and quality of what we build can become stronger when teams share space. As we grow, we want every new teammate to feel part of an in-person community from day one. That’s why we are focusing our U.S. hiring in three cities, where we are investing in offices and building strong local teams: Santa Barbara, CA (Our HQ) Seattle, WA Kansas City, KS/MO Unless a role’s posting states otherwise, new U.S. roles are based in one of these three cities, and candidates should reside in (or be willing to relocate to) one of these areas. Each location follows an in-person schedule that reflects how our local teams work best; we’ll walk you through what to expect for your specific role and city during the interview process. Focusing on offices and hiring in a few locations,  rather than spreading thin across many cities,  lets us invest deeply in each one so every team has real community, mentorship, and momentum in person. WORKING AT ARTERA Company benefits - Full health benefits (medical, dental, and vision), flexible spending accounts, company paid life insurance, company paid short-term & long-term disability, company equity, voluntary benefits, 401(k) and more! Career development - Manager development resources, employee development funds Generous time off - Company holidays, Winter & Summer break, and flexible time off Employee Resource Groups (ERGs) - We believe that everyone should belong at their workplace. Our ERGs are available for identifying employees or allies to join. EQUAL EMPLOYMENT OPPORTUNITY (EEO) STATEMENT Artera is an Equal Opportunity Employer and is committed to fair and equitable hiring practices. All hiring decisions at Artera are based on strategic business needs, job requirements, and individual qualifications. All candidates are considered without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, genetics, protected veteran status, or any other protected status. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire. Artera is committed to providing employees with a work environment free of discrimination and harassment; Artera will not tolerate discrimination or harassment of any kind. Artera provides reasonable accommodations for applicants and employees in compliance with state and federal laws. If you need an accommodation, please reach out to [email protected]. DATA PRIVACY Artera values your privacy. By submitting your application, you consent to the processing of your personal information provided in conjunction with your application. For more information please refer to our Privacy Policy. SECURITY REQUIREMENTS All employees are responsible for protecting the confidentiality, integrity, and availability of the organization’s systems and data, including safeguarding Artera’s sensitive information such as, Personal identifiable Information (PII) and Protected Health Information (PHI). Those with specific security or privacy responsibilities must ensure compliance with organizational policies, regulatory requirements, and applicable standards and frameworks by implementing safeguards, monitoring for threats, reporting incidents, and addressing data handling risks or breaches. Responsibilities AI Threat Modeling : Threat-model agentic and LLM-powered features end-to-end: data ingress/egress, agent identity, tool-use boundaries, and the unique risks that come with frontier AI work Paved Road Tooling : Build the secure SDLC paved road — secure SDLC guardrails, prompt/agent identity patterns, secrets management, PHI/PII redaction patterns Security Gates : Embed SAST, DAST, SCA, and infrastructure scanning into CI/CD so security gates are part of the pipeline, not an afterthought AI Monitoring Strategy : Identify and pilot an AI monitoring tool to fill the gap our current tooling (Zscaler) doesn't cover Policy -> Practice : Translate existing security policy into safe tool-use patterns for the Artera Primitives team, Systems Engineers, and other AI Builder squads Cross Functional Partnership : Partner cross-functionally with DevOps, Systems Engineering, and the AI builder teams — meeting AI Builders and engineers in the middle and finding the secure path forward, not the "no" path Security Ownership : Own AWS identity and access management patterns, secrets management, and security tooling decisions in our AWS environment. Collaborate with System Engineers / DevOps on implementation. Security Framework Application : Apply frameworks like MITRE ATT&CK, MITRE ATLAS, OWASP Top 10, and OWASP LLM Top 10 to architectural decisions. Requirements AppSec Tenure: 6–10 years in Application Security, with a hands-on engineering orientation LLM & Agent Security : Demonstrable experience with LLM and agent security — OWASP LLM Top 10, MITRE ATLAS, prompt/output filtering, agent identity, and tool-use risk Threat Modeling Expertise : You’ve built end-to-end threat models for production platforms and translated them into corrective controls Pipeline Scanning Tools : SAST, DAST, and infrastructure scanning tools in production CI/CD environments Shift-Left Security Experience : Taking policy, codifying it as infrastructure-as-code (Terraform), and gating CI/CD pipelines on security findings Cloud Depth : Significant AWS experience (GCP or Azure background acceptable; AWS is learnable, but cloud depth is required) Regulated Environment Experience : Background in regulated environments — healthcare (HIPAA/HITRUST), federal (FedRAMP), or fintech (PCI) Collaborative Communicator : Strong cross-functional communicator;able to partner with engineers and AI builders, find the secure path together. Bonus Agentic AI Modeling : Direct experience threat modeling agentic AI systems (rare — but if you have it, you're the cherry on top) Agentic Platform Exposure : AWS Agent Core, MCP, or similar agent-platform exposure Growth Stage AI Experience : Experience at a growth-stage company (~50–500 people) that has already adopted agentic AI Fintech to Agentic Path : Background in fintech transitioning into agentic systems (a common path into this kind of work today) AI Monitoring Tool Ownership : Past ownership of an AI monitoring tool rollout or evaluation

Full job record

Job IDfeebf14c11ae34d70b84028bd2048dd65c20d684
Org ID79b75c42-5334-4fe2-af4a-c4101c13eb8a
Source ID194a4761-1929-47d8-9917-8118c4beaafb
Board ID194a4761-1929-47d8-9917-8118c4beaafb
Providerlever
Provider Job Keyc77979d2-dd2a-49c3-9945-1083fc6a08a9
TitleSenior Application Security Engineer, AI & Product Security
Normalized Title
Statusactive
Activeyes
Location TextSeattle, Washington
DepartmentEngineering
TeamSecurity
Employment TypeFull Time
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionWA
CitySeattle
Salary RawUSD 146000-175000 per-year-salary
Salary Min146,000
Salary Max175,000
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://jobs.lever.co/artera-2/c77979d2-dd2a-49c3-9945-1083fc6a08a9
Apply URLhttps://jobs.lever.co/artera-2/c77979d2-dd2a-49c3-9945-1083fc6a08a9/apply
First Seen At2026-05-29 07:07:39Z
Last Seen At2026-06-06 19:27:48Z
Last Checked At2026-06-06 19:27:48Z
Last Changed At2026-06-03 12:25:55Z
Inactive At
Source Posted At2026-05-15 19:05:39Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=artera-2/date=2026-06-06/2026-06-06T19-27-47-673Z-049d9d70a8105e61a42dcdc5580f5f560910c6c4e20074aaeba9cd65efc142ad.json
Event Fields
{
  "content_hash": "728238683b6914f4544caf40a60d206c8aef30a262f4f9fa0a4e1ea372d7e474",
  "source_hash": "57ad25287221b91dc64092a7fc0bc0c35e637ab682deefd2216d4bb5ec20c8e6",
  "last_changed_at": "2026-06-03T12:25:55.423Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Seattle, Washington",
    "city": "Seattle",
    "region": "WA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.85
  },
  "salary_max": 175000,
  "salary_min": 146000,
  "inferred_at": "2026-06-06T19:27:48.480Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Seattle, Washington",
      "city": "Seattle",
      "region": "WA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.85
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": "year",
  "workplace_type": "hybrid",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "Responsibilities ",
      "content": "\n<li><strong>AI Threat Modeling</strong>: Threat-model agentic and LLM-powered features end-to-end: data ingress/egress, agent identity, tool-use boundaries, and the unique risks that come with frontier AI work</li>\n<li><strong>Paved Road Tooling</strong>: Build the secure SDLC paved road — secure SDLC guardrails, prompt/agent identity patterns, secrets management, PHI/PII redaction patterns</li>\n<li><strong>Security Gates</strong>: Embed SAST, DAST, SCA, and infrastructure scanning into CI/CD so security gates are part of the pipeline, not an afterthought</li>\n<li><strong>AI Monitoring Strategy</strong>: Identify and pilot an AI monitoring tool to fill the gap our current tooling (Zscaler) doesn't cover</li>\n<li><strong>Policy -&gt; Practice</strong>: Translate existing security policy into safe tool-use patterns for the Artera Primitives team, Systems Engineers, and other AI Builder squads</li>\n<li><strong>Cross Functional Partnership</strong>: Partner cross-functionally with DevOps, Systems Engineering, and the AI builder teams — meeting AI Builders and engineers in the middle and finding the secure path forward, not the \"no\" path</li>\n<li><strong>Security Ownership</strong>: Own AWS identity and access management patterns, secrets management, and security tooling decisions in our AWS environment. Collaborate with System Engineers / DevOps on implementation.</li>\n<li><strong>Security Framework Application</strong>: Apply frameworks like MITRE ATT&amp;CK, MITRE ATLAS, OWASP Top 10, and OWASP LLM Top 10 to architectural decisions.</li>\n"
    },
    {
      "text": "Requirements",
      "content": "\n<li><strong>AppSec Tenure:</strong> 6–10 years in Application Security, with a hands-on engineering orientation</li>\n<li><strong>LLM &amp; Agent Security</strong>: Demonstrable experience with LLM and agent security — OWASP LLM Top 10, MITRE ATLAS, prompt/output filtering, agent identity, and tool-use risk</li>\n<li><strong>Threat Modeling Expertise</strong>: You’ve built end-to-end threat models for production platforms and translated them into corrective controls</li>\n<li><strong>Pipeline Scanning Tools</strong>: SAST, DAST, and infrastructure scanning tools in production CI/CD environments</li>\n<li><strong>Shift-Left Security Experience</strong>: Taking policy, codifying it as infrastructure-as-code (Terraform), and gating CI/CD pipelines on security findings</li>\n<li><strong>Cloud Depth</strong>: Significant AWS experience (GCP or Azure background acceptable; AWS is learnable, but cloud depth is required)</li>\n<li><strong>Regulated Environment Experience</strong>: Background in regulated environments — healthcare (HIPAA/HITRUST), federal (FedRAMP), or fintech (PCI)</li>\n<li><strong>Collaborative Communicator</strong>: Strong cross-functional communicator;able to partner with engineers and AI builders, find the secure path together.</li>\n"
    },
    {
      "text": "Bonus",
      "content": "\n<li><strong>Agentic AI Modeling</strong>: Direct experience threat modeling agentic AI systems (rare — but if you have it, you're the cherry on top)</li>\n<li><strong>Agentic Platform Exposure</strong>: AWS Agent Core, MCP, or similar agent-platform exposure</li>\n<li><strong>Growth Stage AI Experience</strong>: Experience at a growth-stage company (~50–500 people) that has already adopted agentic AI</li>\n<li><strong>Fintech to Agentic Path</strong>: Background in fintech transitioning into agentic systems (a common path into this kind of work today)</li>\n<li><strong>AI Monitoring Tool Ownership</strong>: Past ownership of an AI monitoring tool rollout or evaluation</li>\n"
    }
  ],
  "country": "US",
  "createdAt": 1778871939224,
  "updatedAt": null,
  "categories": {
    "team": "Security",
    "location": "Seattle, Washington",
    "commitment": "Full Time",
    "department": "Engineering",
    "allLocations": [
      "Seattle, Washington"
    ]
  },
  "salaryRange": {
    "max": 175000,
    "min": 146000,
    "currency": "USD",
    "interval": "per-year-salary"
  },
  "workplaceType": "hybrid"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/feebf14c11ae34d70b84028bd2048dd65c20d684?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/79b75c42-5334-4fe2-af4a-c4101c13eb8aJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/194a4761-1929-47d8-9917-8118c4beaafbJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/feebf14c11ae34d70b84028bd2048dd65c20d684/eventsJSON