Назад
Company hidden
5 дней назад

Application Security Engineer (Healthcare)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Healthcare): Building and maturing an application security program for web, API, and pipeline applications with an accent on Secure SDLC practices, security tooling, and healthcare data protection. Focus on integrating SAST, DAST, SCA, and IAST into CI/CD pipelines, performing penetration tests, remediating vulnerabilities, and supporting HIPAA, NIST, and GDPR compliance.

Location: Remote work is listed, while the physical work environment is described as an onsite/hybrid role based in Houston, Texas. Occasional travel may be required for meetings, conferences, or audits.

Company

hirify.global is a clinical genetic testing organization handling sensitive patient data across web, API, and pipeline applications.

What you will do

  • Build and mature the application security program and embed Security by Design and Privacy by Design across the SDLC.
  • Implement and manage SonarQube and complementary SAST, DAST, SCA, and IAST tools in CI/CD pipelines and check-in scans.
  • Perform penetration testing and vulnerability assessments across web, API, and pipeline applications.
  • Partner with engineering teams to triage findings, conduct threat modeling and secure architecture reviews, and drive remediation.
  • Develop remediation programs and report application security, vulnerability management, and risk assessment status to technical and executive audiences.
  • Collaborate with IT, Privacy, Compliance, business units, and auditors; provide evidence and draft security policies and procedures.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent education and experience.
  • 3–5 years of experience in application security, DevSecOps, or software engineering with a security focus.
  • Hands-on SonarQube experience and experience integrating SAST, DAST, SCA, and IAST tooling into CI/CD pipelines.
  • Knowledge of the OWASP Top 10, common attack vectors, secure coding, penetration testing, code review, and vulnerability management.
  • Working knowledge of Java, C#/.NET, Python, or JavaScript and compliance frameworks including HIPAA, NIST, and GDPR.
  • Strong communication, analytical, problem-solving, collaboration, and risk-prioritization skills.

Nice to have

  • OSCP, CSSLP, GWAPT, CISSP, or an equivalent certification.
  • Experience securing web applications, APIs, and cloud-native or containerized workloads.
  • Knowledge of SAML, OAuth, or OpenID Connect.
  • Experience in healthcare, clinical laboratories, or another regulated HIPAA/PHI environment.

Culture & Benefits

  • Cross-functional collaboration with engineering, IT, Privacy, Compliance, and business teams.
  • Work in a fast-moving environment with a self-directed, detail-oriented approach.
  • Support for measurable organizational risk reduction and protection of sensitive patient data.
  • Inclusive equal opportunity workplace.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →