Lead Application Security Engineer- DevSecOps
Core
Lead the technical direction and implementation of application security capabilities, focusing on API security and SDLC adoption within a healthcare environment.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Secure software delivery pipelines, API security testing programs, and security-hardened platforms
Domain
Healthcare + Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
Software architecture, SAST/SCA/DAST, API security testing, CI/CD security, Docker, Terraform, OAuth 2.0, OpenID Connect, JWT, SAML, RESTful services, vulnerability management
Preferred skills
HIPAA, HITRUST, PCI-DSS knowledge
Responsibilities
Drive execution of security best practices across R&D, own the evaluation and implementation of application security capabilities, lead the API security testing program, partner with DevOps and infrastructure teams to design security-hardened platforms
Seniority
Senior, hands-on IC