MyFitnessPal

MyFitnessPal

MyFitnessPal is a top nutrition tracking app with a calorie tracker, BMR calculator, and food tracker. It helps users reach health goals by tracking meals and physical activity, offering nonstop motivation for a healthier life.

Health Care Providers & Services
10K-50K
Founded 2005

Description

  • Manage application security vulnerabilities from SAST, SCA, DAST, and mobile security tools through triage, remediation, and resolution.
  • Operate and expand the bug bounty program, including scoping engagements, validating submissions, and coordinating with vendors.
  • Use AI and agentic tooling to accelerate vulnerability triage, enrichment, and remediation workflows.
  • Build and maintain Python and SOAR-based automation for vulnerability intake, notifications, SLAs, metrics, and reporting.
  • Partner with product engineering teams on remediation, security guidance, and issue resolution.
  • Review new features, services, and third-party integrations using pragmatic, risk-based security analysis.
  • Promote secure coding practices through documentation, training, and developer support.
  • Administer, tune, evaluate, and implement application security tools across the SDLC.
  • Support identity and access management workflows and related automation.

Requirements

  • 2–4 years of experience in security engineering, application security, software engineering, or a related field.
  • Understanding of SAST, DAST, SCA, penetration testing, vulnerability triage, and remediation.
  • Knowledge of secure web and mobile application development practices, including OWASP Top 10 and OWASP MASVS.
  • Experience with AI-assisted or agentic tooling, LLM-powered workflows, or similar automation.
  • Experience communicating security findings and remediation guidance to engineering teams.
  • Familiarity with cloud microservices, containers, Kubernetes, and infrastructure as code.
  • Strong cross-functional communication, judgment, and collaboration skills.
  • Ability to document technical concepts clearly for technical and non-technical audiences.
  • Education or certifications equivalent to a bachelor’s degree in Computer Science, Information Systems, or a related field.
  • Security automation with Python or SOAR platforms, CI/CD security scanning, GitHub Actions, or bug bounty experience preferred; GIAC, OSCP, CSSLP, Security+, or vendor certifications are a plus.

Benefits

  • Estimated salary of $90,000–$130,000, plus an annual performance bonus.
  • Medical, dental, and vision coverage; 401(k) with employer match.
  • Responsible time off, two annual volunteer days, and paid maternity and paternity leave.
  • Parental planning, fertility support, mental health benefits, and dedicated mental health days.
  • Monthly wellness and technology allowances, plus MyFitnessPal Premium access.
  • Mentorship, virtual learning resources, and professional development opportunities.
  • Flexible work practices with team meetups and an annual company gathering.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a Security Engineer to partner with engineering and product teams remotely, building secure-by-default systems and driving measurable application security outcomes.

AWS Docker GCP Go Java Kubernetes Python Ruby Terraform
4 days, 20 hours ago

Staff Application & Product Security Engineer

Cleo 251-1K Internet Software & Services

Cleo is hiring a Staff Application Security Engineer to own secure product development and the security posture of its SaaS and customer-hosted products, partnering with engineering and security teams from design through release.

AWS Burp Suite CI/CD GitHub Go Java Jenkins Kubernetes Penetration Testing Python SAML Terraform TypeScript
4 days, 21 hours ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is seeking an Application Security Engineer to triage and validate vulnerability submissions across client bug bounty programs, communicate with researchers and customers, and escalate critical security incidents.

Burp Suite Nmap
1 week, 5 days ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is seeking a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices throughout product development.

CI/CD DevSecOps Java JavaScript Kubernetes OpenID Connect Python SAML Secrets Management TLS
1 week, 5 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers