Information Protection Advisor- Hybrid
Core
Identify, evaluate, and lead technical security analyses to ensure systems and processes meet information security requirements.
Role type
Information Protection Advisor (Application Security)
Builds
Secure CI/CD pipelines, automated security controls, and secure application lifecycles
Domain
Healthcare technology / Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
Automating security solutions in CI/CD pipelines, Static application security testing (SAST), Dynamic application security testing (DAST), Application security posture management, False positive triage automation, SBOM evaluation, Python scripting, Ansible playbooks, Docker container security, Authentication and Authorization design, Vulnerability management
Preferred skills
Integrating security into design and implementation phases, Referencing security standards (ISO27001, SOC 2 Type II, Open-Source Licensing)
Technologies
Checkmarx, BlackDuck, NowSecure, RedHat ACS, PrismaCloud, Apiiro, Azure DevOps, Jenkins
Responsibilities
Embed security assessments into development and operational workflows, Provide in-depth technical analysis of security requirements, Collaborate with engineering teams to ensure secure design, Partner with stakeholders to define security requirements, Conduct comprehensive security assessments of third-party service providers, Design and implement automated security processes
Seniority
Mid-level, hands-on IC