Distinguished Engineer - Application Security
Core
Senior technical leader and strategist for Application Security, defining architectural direction for securing web, mobile, API, microservice, and AI-native applications across cloud, on-prem, SaaS, and hybrid environments.
Role type
Distinguished Engineer (Application Security)
Builds
Enterprise application security tooling stack (SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC/container scanning, ASPM) integrated into developer platforms and CI/CD pipelines.
Domain
Healthcare technology / Application Security / DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
Application security strategy, software engineering (Java, C#, JavaScript/TypeScript, Python, Go), threat modeling, secure design review, CI/CD integration, software supply chain security, cloud-native architecture, developer experience partnership, executive communication
Preferred skills
AI-assisted software development governance, AI-native application security tooling, OWASP LLM Top 10, NIST AI RMF, healthcare security compliance (HIPAA, HITRUST, PCI DSS), runtime application security (RASP, eBPF)
Technologies
Kubernetes, serverless, microservices, REST, GraphQL, gRPC, GitHub Actions, GitLab CI, Jenkins, Argo, CycloneDX, SPDX, SLSA, OWASP ASVS, NIST SSDF
Responsibilities
Set architectural direction for enterprise application security; own technical strategy and end-to-end architecture of the application security tooling stack; chart enterprise course for AI-assisted software development and AI-native security tooling; partner with Developer Experience team to deliver secure-by-default paved paths and secure coding standards; operate as a trusted bridge between technical engineering teams and business stakeholders.
Seniority
Distinguished, hands-on IC with strategic leadership