Senior Application Security Engineer
Core
Manage and optimize application security tooling (SAST, DAST, SCA, IaC, secret scanning) and integrate it into the SDLC to identify, triage, and remediate vulnerabilities in healthcare revenue cycle software.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Secure software development lifecycle for healthcare revenue cycle management platforms
Domain
Healthcare technology / Application Security
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Application security tooling (SAST, DAST, SCA, IaC, secret scanning), Secure coding principles, Scripting (Python, JavaScript, .NET), Vulnerability triage and risk prioritization, CI/CD pipeline integration, Secure code review, Threat modeling, Mentoring
Preferred skills
AI/ML exploration for security processes, Professional security certifications
Technologies
SAST, DAST, SCA, IaC scanners, ServiceNow, Aha!, Python, JavaScript, .NET
Responsibilities
Manage and optimize application security tools and ensure effective integration into CI/CD pipelines; Analyze source code and infrastructure-as-code for security vulnerabilities; Validate and triage findings from security tools, removing false positives; Create and manage remediation tickets; Collaborate with development teams to validate remediation efforts; Lead secure code reviews and contribute to threat modeling; Mentor junior engineers; Develop and maintain dashboards and reports on security posture; Identify recurring security issues and propose systemic improvements; Evaluate and pilot new application security tools.
Seniority
Senior, hands-on IC with mentorship responsibilities