AVP Cybersecurity
Core
Build, run, and mature the organization's application security program while remaining an active technical contributor to secure software development.
Role type
Senior IC/Lead Application Security Engineer (DevSecOps)
Builds
Secure SDLC tooling, automation, and application-layer vulnerability management for healthcare revenue cycle solutions
Domain
Healthcare technology / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security program management, Secure SDLC strategy, DevSecOps tooling and automation, Threat modeling, Security architecture reviews, Vulnerability triage and remediation, Secure code reviews, CI/CD pipeline integration, Cloud and container security, Software composition analysis, Programming (Java, Python, JavaScript/TypeScript, Go, C#)
Preferred skills
Leadership and team mentoring, Executive reporting, AI process innovation
Technologies
SAST, DAST, SCA, Checkmarx, Veracode, Snyk, Semgrep, Fortify, Jenkins, GitHub Actions, GitLab CI, Azure DevOps, AWS, Azure, GCP, Docker, Kubernetes, STRIDE
Responsibilities
Build and mature AppSec/DevSecOps program, Perform secure code reviews and threat modeling, Mentor security engineers, Design and tune AppSec toolchain, Own vulnerability management program, Partner on shift-left security, Develop security policies and playbooks, Report risk posture to leadership, Participate in security incident response
Seniority
Senior, hands-on IC with leadership responsibilities