Appsec - Lead Engineer
Core
Lead Application Security Engineer specializing in Software Composition Analysis (SCA) to manage open-source and third-party dependency risk, identify/remediate vulnerabilities, and drive secure dependency governance across engineering teams.
Role type
Senior IC Application Security Engineer (SCA Lead)
Builds
Secure software supply chain, SBOM processes, and integrated security scanning in CI/CD pipelines
Domain
Healthcare technology / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Software Composition Analysis (SCA), artifact repository management, SAST/DAST tool configuration, CI/CD pipeline integration, vulnerability triage, SBOM generation, secure coding guidance
Preferred skills
Container security, cloud security (AWS/Azure/GCP), API security testing, security frameworks (NIST, ISO 27001, PCI-DSS)
Technologies
JFrog Artifactory/Xray, Sonatype Nexus, Azure Artifacts, GitHub Packages, GitLab Package Registry, AWS CodeArtifact, Google Artifact Registry, Veracode, Checkmarx, HCL AppScan, SonarQube, Invicti, Acunetix, OWASP ZAP, Jenkins, GitLab CI, Azure DevOps, GitHub Actions
Responsibilities
Own end-to-end SCA program for dependency risk and license compliance; Configure and optimize artifact repositories with embedded scanning; Establish dependency governance policies; Monitor CVEs and drive remediation; Integrate SCA/SAST/DAST into CI/CD pipelines; Triage and prioritize vulnerabilities; Conduct manual code reviews; Partner with DevOps/Dev teams to embed security in SDLC; Track and report security metrics
Seniority
Senior, hands-on IC