Security Engineer II (Application Security) at MyFitnessPal
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
At MyFitnessPal, we believe good health starts with what you eat. We provide tools, resources, and support to enable users to reach their health goals.
We are looking for a Security Engineer II with a focus on Application Security to join the MyFitnessPal Security team. Our users rely on MyFitnessPal to power their health and fitness journeys every day, and you will leverage your technical skills to secure the code, applications, and development processes that create the MyFitnessPal product experience. In addition to technical expertise, you'll find that your teammates value collaboration, mentorship, and inclusive environments.
About the team:
The Productivity Engineering: Automation & Self-Service (PEAS) team is responsible for the automation, CI/CD, and self-service platforms that product teams rely on to build, test, and ship features quickly and safely.
The PEAS team is part of the Technology Operations (TechOps) organization, which includes IT, Infrastructure, Security, Reliability, and DevOps/DevEx disciplines. TechOps seeks to enable MyFitnessPal to “ship with confidence” by delivering a secure, reliable, and low-friction runway to build and operate software at scale. Within TechOps, you’ll represent the Security discipline — protecting the applications and development processes that keep our mobile and backend software safe for millions of users.
Essential Duties:
As a Security Engineer II, you will own the day-to-day operation of our application security vulnerability management program and act as a trusted security partner to product engineering teams. You’ll triage what our tooling and researchers find, drive it to remediation, and build the automation that makes the whole program run with less manual effort. This is a hands-on technical position with real ownership and substantial opportunity for growth.
What you’ll be doing:
- Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets through our SVM process to resolution
- Operate and grow our bug bounty program — scoping engagements, triaging researcher submissions, validating findings, and coordinating with vendors
- Leverage AI and agentic tooling (for example, Claude Code and agentic pipelines) to accelerate security workflows — from vulnerability triage and enrichment to automated remediation support — and help ensure our AI-assisted development practices remain secure
- Build and maintain security automation (for example, in our SOAR platform and with Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces the metrics and reporting that keep the program transparent
- Partner with product engineering teams on remediation — joining triage and refinement discussions, answering questions, and representing security as a business enabler rather than a blocker
- Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance
- Advocate secure coding practices and contribute to developer-facing security documentation and training
- Administer and tune application security tooling across the SDLC, and help evaluate and implement new security technology
- Support identity and access management workflows and the automation behind them
Qualifications to be successful in this role:
- 2-4 years of experience in security engineering, application security, software engineering, or a closely related role
- Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings
- Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS)
- Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work
- Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers
- Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code)
- Strong communication skills, enabling collaboration across cross-functional teams, and the judgment to raise a security finding and land it as a shared problem to solve, not a fight to win
- Ability to create documentation that describes technical details clearly, including for non-technical audiences
- Ability & desire to learn new product lines and technologies quickly & efficiently
- Education and/or certifications equivalent to BS in Computer Science or IS related field; GIAC (e.g., GWEB, GCIH), OSCP, CSSLP, Security+, or vendor-specific certifications are a plus
Preferred Qualifications:
- Experience automating security processes (e.g., Python, SOAR platforms, workflow automation) is strongly preferred
- Experience with security scanning in CI/CD pipelines and orchestration tools (e.g., GitHub Actions) is a plus
- Experience operating or triaging for a bug bounty program is a plus
Values you’ll model:
- Be Kind and Care — build with empathy; assume positive intent; support teammates and members.
- Live Good Health — champion healthy habits and balance in how we work and what we ship.
- Be Data-Inspired — ground decisions in research and data; measure what matters.
- Champion Change — lean into ambiguity; iterate, learn, and improve continuously.
- Leave it Better than You Found It — raise quality, clarify systems, and document as you go.
- Make It Happen — bias to action; deliver impact with craft and accountability.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at MyFitnessPal
Explore Top Companies in this Space
Insight Timer
Mental Health & Wellness Platforms / Consumer Healthtech & EdTech SaaS / Direct-to-Consumer Audio Streaming / Enterprise Corporate Wellness
Chefman
Consumer Goods / Manufacturing / Home Appliances
fiscal.ai
Financial Data / Investment Research / Artificial Intelligence / Enterprise Software
SpaceInch
Custom Software Development / Digital Product Agency / Enterprise Software / Product Strategy
MyFitnessPal
View Company ProfileMyFitnessPal (operating under myfitnesspal.com, legally MyFitnessPal, Inc.) is the premier, enterprise-grade digital nutrition tracking platform, consumer health informatics pioneer, and metabolic wellness orchestration powerhouse engineered to act as the definitive, high-velocity diet diary, custom meal planning, and biometric telemetry layer for more than 280 million health-conscious users globally. Founded in 2005 by technology innovators Mike Lee and Albert Lee, the company completely eliminates the severe systemic friction of modern lifestyle and wellness management—where consumers suffer from intense cognitive overload tracking nutritional macros, lose logging consistency across fragmented software interfaces, and fail to secure clinically actionable data regarding calorie burn and insulin-modulating behaviors—by deploying a unified, data-rich global health matrix. Moving far beyond traditional, passive journaling books or restrictive recipe binders, MyFitnessPal natively unifies an unmatched database of over 20 million foods across 68,500 brands and 380+ restaurant chains, advanced machine-learning-driven photo-based food scanning, predictive personalized macro targets, and specialized tools tailored for modern GLP-1 weight management clinical support into a single high-availability mobile ecosystem. Following high-profile ownership epochs with athletic apparel giant Under Armour, the enterprise was acquired by global private equity leader Francisco Partners in 2020 to stand as an independent digital health powerhouse. Under the leadership of Chief Executive Officer Mike Fisher, MyFitnessPal has rapidly executed an aggressive AI-first platform consolidation strategy, acquiring meal planning pioneer Intent and integrating advanced visual recognition with the acquisition of bootstrap sensation Cal AI. Under the hood, its technology core utilizes optimized programmatic search indexes, seamless API integrations with top-tier fitness wearables (including Apple Health, Garmin, and Google Fit), and secure SOC 2-compliant data transfer layers engineered to process billions of meal logs with real-time analytics delivery. What sets MyFitnessPal apart is its uncompromising dedication to replacing fragmented, manual diet diaries with absolute nutritional predictability, frictionless visual logging, and accessible, data-driven wellness paths; by bridging the gap between performance-intensive relational food databases and immediate, consumer-first behavior modification, the company remains the definitive cornerstone of modern consumer healthtech and global nutritional transformation.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
