Back to jobs
HealthStream

Application Security Analyst

USA Remote - Nashville, TN 37203Posted Today
Full-timeonsite

Job Description

Company Overview
 

HealthStream is the leader in healthcare workforce solutions. We help organizations work better by helping their people work smarter.
 

HealthStream provides the leading learning, clinical development, credentialing, and scheduling applications delivered on healthcare’s #1 platform. We streamline everyday tasks while improving performance, engagement, and safety – fostering a workplace where people flourish, and care thrives.


 

Why Join Us

 

At HealthStream, you’ll have the opportunity to make a meaningful impact on the future of healthcare by collaborating with a team of talented professionals dedicated to innovation and excellence. We offer competitive compensation, comprehensive benefits, and a supportive work environment where creativity and collaboration thrive.

 

Our shared vision is to enhance the quality of healthcare by empowering the people who deliver care – a commitment we have upheld for over 30 years through providing innovative solutions and driving constant growth. Join us in revolutionizing the healthcare industry and shaping the future of patient care. As a HealthStreamer, you will be at the forefront of healthcare technology innovation, making a recurring impact on the industry.

 

 

We’re proud of our values-forward culture that offers our people:
 

  • Mission-oriented work
  • Diverse and inclusive culture
  • Competitive Compensation & Bonuses
  • Comprehensive Insurance Plans
  • Mental and Physical Health Support
  • Work-from-home flexibility
  • Fitness Center Reimbursements
  • Streaming Good time off for volunteering
  • Wellness workshops
  • Buddy Program for new HealthStreamers
  • Collaborative work environment
  • Career growth opportunities
  • Continuous learning opportunities
  • Inspiring workspaces to collaborate and connect with other HealthStreamers
  • Free employee parking at our Resource Centers in Nashville and San Diego

 

 

At HealthStream, our thriving culture encourages collaboration and values contributions, allowing our team members to continuously solve big problems and grow. We offer flexibility and paid time off to support work-life integration for all employees, including a hybrid work environment and Streaming Good volunteer day. For team members in commutable distance, HealthStream has Resource Centers in Nashville, TN and San Diego, CA. Our resource centers provide an inspiring workspace to collaborate and recharge as well as company-sponsored onsite social events for development, connection, and celebration.

 

We are committed to driving innovation in healthcare and ensuring that patients receive competent care from qualified professionals. As a HealthStream team member, you will help bring this vision to life. If you want to work for a company committed to its values and vision, HealthStream is the place for you!

 

HealthStream is an equal opportunity employer. HealthStream prohibits employment practices that discriminate against individual employees or groups of employees on the basis of age, color, disability, national origin, race, religion, sex, sexual orientation, pregnancy, veteran or military status, genetic information or any other category deemed protected by state and/or federal law.

 

 

 

Position Information

 

 

Position Overview

The Application Security Analyst plays a hands-on role in supporting and executing the application security program at HealthStream. Working closely with and under the guidance of the Sr. Application Security Architect, this role focuses on identifying, assessing, and helping remediate security vulnerabilities across our software products and cloud environments. The Analyst will partner with Engineering, DevOps, and Product teams to embed security practices into the software development lifecycle (SDLC), operate security tooling, and contribute to a culture of security awareness. This is an excellent opportunity for a motivated security professional looking to grow within a collaborative, mission-driven healthcare technology organization. 

 

Key Responsibilities

You will be responsible for adhering to all HealthStream security policies, procedures, and assigned training.

Application Security Testing & Vulnerability Management 

  • Operate and manage automated application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST). 
  • Triage, validate, and prioritize vulnerability findings from security scans, penetration tests, and bug reports, working with development teams to track remediation to closure. 
  • Conduct or support manual security assessments and penetration testing of web applications, APIs, and mobile applications. 
  • Produce clear, actionable vulnerability reports with risk ratings and remediation guidance for development teams. 
  • Manage and maintain vulnerability findings within the Snyk, Invicti and SonarQube or equivalent vulnerability management platform. 

 

Secure Development Lifecycle (SDLC) Support 

  • Support the integration of security into CI/CD pipelines and DevSecOps workflows, including automated security gate checks. 
  • Participate in design and architecture reviews with a security lens, helping identify potential risks early in the development process. 
  • Assist in threat modeling exercises for new features and systems under the guidance of the AppSec Architect. 
  • Perform security-focused code reviews and provide developers with clear, constructive feedback and guidance. 
  • Contribute to the maintenance of a secure code library and reusable security patterns for development teams. 

 

Security Tooling & Cloud Security 

  • Support the management and configuration of application security tools such as Synk, Invicti, SonarQube and DefectDojo. 
  • Assist in implementing and monitoring security controls for cloud-based environments, including AWS and Azure. 
  • Evaluate and test emerging security tools and contribute recommendations to the AppSec team. 
  • Support API security testing and assist in securing third-party and open-source integrations. 

 

Security Awareness & Collaboration 

  • Collaborate with cross-functional teams including Engineering, DevOps, and Product to promote security best practices and a shift-left mindset. 
  • Deliver security awareness content and assist in conducting security training sessions for development staff. 
  • Stay current on emerging security threats, vulnerabilities (CVEs), and attack techniques, sharing relevant intelligence with the team. 
  • Assist in maintaining security documentation, standards, runbooks, and internal knowledge base articles. 
  • Support compliance-related activities, including evidence gathering for audits related to HIPAA, SOC 2, HITRUST or other applicable frameworks. FedRAMP experience is a plus. 
  • Other Duties as assigned. 

Requirements

  • Bachelor’s degree in information security, Computer Science, Software Engineering, or a related field. Equivalent practical experience will be considered. 
  • 2 to 4 years of experience in application security, information security, or software development with a security focus. 
  • Working knowledge of the OWASP Top 10, common web application vulnerabilities, and secure coding principles. 
  • Hands-on experience with application security testing tools such as SAST, DAST, or IAST (e.g., Synk, Invicti, Checkmarx, SonarQube, Burp Suite, or similar). 
  • Familiarity with cloud security concepts and hands-on exposure to AWS or Azure environments. 
  • Understanding of CI/CD pipelines and experience integrating security checks into DevOps workflows. 
  • Experience with API security testing and a solid understanding of RESTful service security. 
  • Proficiency in at least one scripting or programming language such as Python, JavaScript, Java, or Go for automation and security tooling purposes. 
  • Strong analytical and problem-solving skills with attention to detail. 
  • Excellent written and verbal communication skills, with the ability to explain security concepts to both technical and non-technical audiences. 
  • Ability to manage multiple tasks and vulnerabilities simultaneously, prioritizing effectively in a fast-paced environment. 

 

 

Qualifications

  • Relevant security certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), GWAPT, eWPT, or equivalent. 
  • Experience using vulnerability management platforms such as Snyk, Invicti, or similar. 
  • Familiarity with security frameworks and standards including OWASP SAMM, NIST, or CIS Controls. 
  • Exposure to healthcare industry security and privacy regulations, including HIPAA. 
  • Experience with secure methods of integration with third-party platforms and open-source components. 
  • Participation in bug bounty programs, Capture the Flag (CTF) competitions, or open-source security research. 
  • Awareness of AI/ML security trends and their implications for application security. 
  • Experience with Identity and Access Management (IAM) security concepts and OAuth/OpenID Connect. 
  • Core Competencies 
    • Collaborative team player with the ability to work effectively across engineering and security teams. 
    • Proactive learner committed to continuously developing security knowledge and skills. 
    • Strong work ethic with a commitment to quality and thoroughness in all security activities. 
    • Solutions-oriented mindset identifies problems and drives them toward resolution. 
    • Adaptable and comfortable working in an evolving, high-growth technology environment. 

 

Compensation

  • The salary range for this position is $78,628 - $85,000. Salary will be determined on the candidate’s level of experience and qualifications. Compensation will be commensurate with skills, relevant experience, and performance in similar roles.

 

 

Benefits

 

 HealthStream offers a comprehensive benefits package to eligible employees, including: 

 

  • Medical, Dental and Vision insurance 
  • Paid Time Off 
  • Parental Leave 
  • 401k and Roth 
  • Flexible Spending Account 
  • Health Savings Account 
  • Life Insurance 
  • Short- and Long-Term Disability 
  • Medical Bridge Insurance 
  • Critical Illness Insurance 
  • Accident Insurance 
  • Identity Protection 
  • Legal Protection 
  • Pet Insurance 
  • Employee Assistance Program 
  • Fitness Reimbursement 

 

 

Are you passionate about enhancing healthcare outcomes and empowering healthcare professionals? Join the HealthStream team and become a HealthStreamer! Together, we can make a difference in the world of healthcare.

 

 

Recruitment Fraud Notice: HealthStream is committed to protecting job seekers from recruitment fraud. All legitimate communications from HealthStream’s Talent Acquisition team will come from an official HealthStream email address. HealthStream will never ask candidates to pay fees, purchase equipment, provide banking information, or share sensitive personal information outside of our secure hiring and onboarding process. If you receive a suspicious message claiming to be from HealthStream, please proceed with caution and report it to the appropriate authorities.

 

Req #46890

 

See Your Match Score

Sign up and Renata will show you how this job matches your skills and experience.

Get Started Free
Application Security Analyst at HealthStream | Renata