Senior Security Engineer - Application Security
Core
Lead application security protocols throughout the SDLC, perform hands-on security testing, and build automated security tooling for web apps, APIs, and cloud-native services.
Role type
Senior IC Application Security Engineer
Builds
Automated security testing pipelines, secure coding standards, and enterprise-wide security policies
Domain
Healthcare technology, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Application security vulnerabilities (OWASP Top 10), manual security testing of web apps/APIs, code review for security weaknesses, CI/CD integration, static/dynamic testing, secrets detection, container security, IaC scanning, authentication/authorization/cryptography, cloud technology (AWS/GCP/Azure), secure API design, enterprise security policy implementation
Preferred skills
Generative coding utilities, AI code development security implications, specific tools (Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma)
Technologies
Datadog, Sumologic, Torq, flare.io, GCP, Entitle, Okta, Orca, GitLab, Prisma
Responsibilities
Lead development of application security protocols in SDLC, partner with engineering on secure architecture, perform hands-on security testing, build automated security testing in CI/CD, evaluate application security tools, develop secure coding standards, contribute to vulnerability management and incident reviews, evaluate third-party integrations, ensure healthcare regulatory compliance
Seniority
Senior, hands-on IC
