Application Security Engineer
Core
Staff Software Engineer leading application security for cloud-native SaaS platforms, embedding security into design, development, and operations for healthcare and payment data systems.
Role type
Staff Software Engineer (Application Security)
Builds
Cloud-native SaaS applications handling PHI and payment data
Domain
Healthcare technology, Cloud security, HIPAA/PCI DSS compliance
Deliverable
production ML models | product features | infrastructure
Required skills
Secure coding standards, Threat modeling, Secure design patterns, Authentication/Authorization, Encryption/Key management, Secure session management, Vulnerability remediation, DevSecOps integration, Agile development, Risk management
Preferred skills
CSSLP certification, Cloud security certifications (GCP), Application security certifications (GWAPT, GWEB)
Technologies
Cloud-native platforms, GCP, DevSecOps tools
Responsibilities
Establish and evolve secure coding standards and best practices; Lead secure design reviews and code reviews; Identify and remediate vulnerabilities; Define and validate security controls for auth, encryption, and data protection; Partner with Compliance to translate regulatory obligations into engineering controls; Validate security controls via threat-driven testing and regression testing; Coach engineers on secure design patterns.
Seniority
Staff, technical leadership & hands-on contribution