Software Technologist - Security Engineer
Core
Design, build, review, and secure modern cloud-native applications, APIs, and microservices by embedding security controls throughout the software development lifecycle.
Role type
Senior IC application security engineer
Builds
Secure cloud-native applications, APIs, and microservices
Domain
Health technology / Cloud security
Deliverable
production ML models | product features
Required skills
Secure software development, Threat modeling, Vulnerability risk assessments, Identity and Access Management (IAM), Role-Based Access Control (RBAC), Secrets Management, Data Protection and Encryption, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Container Security Scanning
Preferred skills
OAuth2, OpenID Connect (OIDC), JWT, SAML, Multi-Factor Authentication (MFA), REST APIs, gRPC services, Database security controls, Privacy and regulatory requirements
Technologies
Java, Spring Boot, Spring Security, C#, ASP.NET Core, .NET Framework/.NET Core, Microsoft Azure, AWS, GitHub Actions, Docker, Kubernetes, SonarQube, GHAS, Burp Suite
Responsibilities
Design and implement authentication, authorization, and identity management solutions; Remediate vulnerabilities and reduce application security risk; Evaluate and recommend security technologies, frameworks, and architectural patterns
Seniority
Senior, hands-on IC