Cyber Security Engineer (Application Security)
Core
Own application security across the SDLC and CI/CD pipeline, securing code, dependencies, and infrastructure-as-code in a healthcare-regulated environment.
Role type
Senior IC application security engineer
Builds
Secure CI/CD pipelines, GitHub Actions workflows, and cloud infrastructure for behavioral health SaaS
Domain
Healthcare technology / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
CI/CD pipeline security, GitHub Actions security, SAST/DAST, code and dependency scanning, Terraform/IaC security, SIEM/EDR/XDR/DLP triage, Zero Trust architecture, API security, healthcare regulations (HIPAA/HITECH/HITRUST), cloud security (Azure/AWS)
Preferred skills
HL7 standards, supply chain risk management, incident response, security tool development
Technologies
GitHub Advanced Security, Snyk, Terraform, Azure, AWS, SIEM, EDR, XDR, DLP
Responsibilities
Integrate security into SDLC and CI/CD pipelines, perform security assessments and threat modeling, triage scanning findings, secure CI/CD identities and permissions, review IaC for misconfigurations, ensure compliance with healthcare regulations, remediate vulnerabilities with development teams, manage security tools, and support incident response.
Seniority
Senior, hands-on IC