Senior Application Security Engineer
Core
Senior Application Security Engineer embedding security into the SDLC, CI/CD pipelines, and cloud-native environments for a health-tech company.
Role type
Senior IC Application Security Engineer
Builds
Secure design patterns, CI/CD security controls, policy-as-code, and security services for Azure, AKS, Databricks, and Snowflake.
Domain
Health-tech / Cloud-native / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Terraform, Python, KQL, SAST/DAST/IAST/SCA implementation, OPA/Azure Policy, GitHub Actions, Kubernetes/AKS security, API security, threat modelling, Agile/DevSecOps, ISO 27001 knowledge
Preferred skills
Data platform security (Databricks/Dagster/Snowflake), unit testing, code reviews, debugging
Technologies
Azure, AKS, Databricks, Snowflake, Dagster, GitHub Actions, OPA, Azure Policy, Terraform, Python, KQL
Responsibilities
Partner with engineering teams to embed security in code and containers; implement and operate code scanning tools; mature SDLC and embed security in CI/CD; advise on securing APIs and high-risk components; develop and adopt policy-as-code; document security processes and designs; support threat modelling and ISO 27001 activities.
Seniority
Senior, hands-on IC