Senior Security Engineer II - Application Security
Core
Designing, implementing, and maintaining security services for cloud-native applications, focusing on automating security capabilities and securing the digital landscape.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Automated security testing and validation systems, secure SDLC/DevSecOps processes, and security controls for web-based SaaS applications
Domain
Cloud-native application security, health-tech systems
Deliverable
production ML models | product features | infrastructure
Required skills
Cloud-native security, DevSecOps, SAST/DAST, threat modeling, code reviews, automated security testing, API security, WAF, OWASP Top 10 remediation, server-side web technologies
Preferred skills
Health-tech systems (EHR, PHI), large-scale distributed systems architecture, AI/LLM security, Python/R/C++/Javascript/Java/Scala/C#/Go
Technologies
Terraform, Cloudformation, Python, AWS, Azure, GCP
Responsibilities
Design and operate solutions to automate security capabilities; leverage data to improve security posture; lead incident response and mitigation; craft security policies and standards; mentor junior engineers
Seniority
Senior, hands-on IC with technical decision-making
