5 дней назад
Application Security Engineer (Healthcare)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (Healthcare): Building and maturing an application security program for web, API, and pipeline applications with an accent on Secure SDLC practices, security tooling, and healthcare data protection. Focus on integrating SAST, DAST, SCA, and IAST into CI/CD pipelines, performing penetration tests, remediating vulnerabilities, and supporting HIPAA, NIST, and GDPR compliance.
Location: Remote work is listed, while the physical work environment is described as an onsite/hybrid role based in Houston, Texas. Occasional travel may be required for meetings, conferences, or audits.
Company
is a clinical genetic testing organization handling sensitive patient data across web, API, and pipeline applications.
What you will do
- Build and mature the application security program and embed Security by Design and Privacy by Design across the SDLC.
- Implement and manage SonarQube and complementary SAST, DAST, SCA, and IAST tools in CI/CD pipelines and check-in scans.
- Perform penetration testing and vulnerability assessments across web, API, and pipeline applications.
- Partner with engineering teams to triage findings, conduct threat modeling and secure architecture reviews, and drive remediation.
- Develop remediation programs and report application security, vulnerability management, and risk assessment status to technical and executive audiences.
- Collaborate with IT, Privacy, Compliance, business units, and auditors; provide evidence and draft security policies and procedures.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent education and experience.
- 3–5 years of experience in application security, DevSecOps, or software engineering with a security focus.
- Hands-on SonarQube experience and experience integrating SAST, DAST, SCA, and IAST tooling into CI/CD pipelines.
- Knowledge of the OWASP Top 10, common attack vectors, secure coding, penetration testing, code review, and vulnerability management.
- Working knowledge of Java, C#/.NET, Python, or JavaScript and compliance frameworks including HIPAA, NIST, and GDPR.
- Strong communication, analytical, problem-solving, collaboration, and risk-prioritization skills.
Nice to have
- OSCP, CSSLP, GWAPT, CISSP, or an equivalent certification.
- Experience securing web applications, APIs, and cloud-native or containerized workloads.
- Knowledge of SAML, OAuth, or OpenID Connect.
- Experience in healthcare, clinical laboratories, or another regulated HIPAA/PHI environment.
Culture & Benefits
- Cross-functional collaboration with engineering, IT, Privacy, Compliance, and business teams.
- Work in a fast-moving environment with a self-directed, detail-oriented approach.
- Support for measurable organizational risk reduction and protection of sensitive patient data.
- Inclusive equal opportunity workplace.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Application Security Engineer (AI)
85 000 - 105 000$
Writer
9 дней назад
Security Engineer, Applications (AI Security)
11 дней назад
Application Security Engineer
90 000 - 130 000$
5 дней назад
Senior Application Security Engineer (Blue Team) (Fintech)
200 000 - 240 000$
11 дней назад
Application Security Engineer - Assistant Vice President
100 000 - 130 000$
6 дней назад
Product Security Engineer (AI)
145 300 - 244 850$