Application Security Strategist
Core
Define and document secure development standards and patterns for modern application architectures (web, API, microservices) to enable secure-by-design practices across engineering teams.
Role type
Senior IC application security strategist (design & enablement)
Builds
Reusable secure design patterns, reference implementations, code samples, and starter templates for secure APIs and microservices
Domain
Healthcare technology / Application Security / Cloud Native
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security design, Secure coding principles (OWASP Top 10), Enterprise security frameworks (NIST CSF, CIS Controls, ISO 27001), Hands-on software development, Cloud-native security (AWS/Azure), Authentication protocols (OAuth 2.0, OIDC, SAML)
Preferred skills
Secure DevOps/CI-CD integration, API security frameworks, Threat modeling, Application security testing tools (SAST/DAST/SCA), AI-enabled application security design
Technologies
AWS, Azure, Okta, Microsoft Entra ID, SailPoint, OAuth 2.0, OIDC, SAML, NIST CSF, CIS Controls, ISO 27001
Responsibilities
Define secure development standards and patterns for web, API, and microservices architectures; Collaborate with engineers to provide guidance on secure application architecture and design decisions; Coach development teams on secure implementation of protocols and identity management; Review vulnerability patterns and lead standardization of risk management practices; Evaluate and evolve security standards to support cloud-native and AI-enabled applications
Seniority
Senior, hands-on IC