Senior Application Security Engineer
Core
Lead application security efforts including penetration testing, threat modeling, and vulnerability remediation for web, mobile, and FDA-regulated medical device software to safeguard sensitive healthcare data.
Role type
Senior Application Security Engineer (Penetration Testing & Security Engineering)
Builds
Secure web/mobile applications and SaMD products for physicians and patients
Domain
Healthcare / Cybersecurity / Medical Devices
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing (black-box/grey-box), Mobile security (iOS/Android, reverse engineering), Threat modeling, HIPAA/GDPR/FDA compliance, Cloud security (AWS/Azure/GCP), Scripting (Python/Go/PowerShell), Secure SDLC
Preferred skills
OSCP/OSCE/OSWE, eCMAP/GMOB, CEH/CSSLP/GPEN/GWAPT, UL 2900 training
Technologies
Burp Suite, MobSF, Ghidra, Frida, REST/GraphQL APIs, DICOM, HL7
Responsibilities
Execute advanced penetration tests on web, APIs, and internal systems; Perform mobile security assessments including reverse engineering; Lead security testing and threat modeling for FDA-regulated medical devices; Develop technical reports on exploit chains and business logic flaws; Automate security testing with custom tools; Mentor junior team members and provide security training
Seniority
Senior, hands-on IC
