Senior Security Engineer (Application Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Engineer (Application Security): Building and scaling application security controls across web applications, APIs, cloud-native services, and the software development lifecycle with an accent on secure architecture, automated security testing, and regulated healthcare technology. Focus on designing CI/CD security automation, identifying complex application and cloud risks, and improving security posture across a healthcare AI platform.
Location: Hybrid role based in New York, NY, United States
Salary: $150,000–$200,000 USD
Company
is a healthcare technology company providing an AI-powered virtual care engine and virtual primary care solutions for patients, providers, and health systems.
What you will do
- Lead application security protocols across architecture, design, development, testing, and deployment.
- Partner with engineering teams to integrate security into the full software development lifecycle.
- Perform hands-on security testing of web applications, APIs, distributed systems, cloud services, and infrastructure.
- Build and improve CI/CD security automation covering static analysis, dependency scanning, secrets detection, container scanning, and dynamic testing.
- Develop secure coding standards and developer-focused documentation while reducing false positives and developer friction.
- Support vulnerability management, incident investigations, third-party risk reviews, and healthcare compliance activities.
Requirements
- 4+ years of professional experience in application, product, or software security, or software engineering experience transitioned into security.
- Strong knowledge of application vulnerabilities, OWASP Top 10, API security, authentication, authorization, session management, cryptography, and secrets management.
- Experience manually testing modern web applications, APIs, and distributed systems and reviewing architecture and source code for security weaknesses.
- Experience integrating application security tools into CI/CD workflows, including SAST, DAST, secrets detection, container security, and infrastructure-as-code scanning.
- Strong cloud expertise in AWS, GCP, or Azure and familiarity with modern programming languages and AI-assisted coding security implications.
- Demonstrated experience establishing and rolling out enterprise-wide security policies and guidelines.
Nice to have
- Experience exploring and implementing emerging security technologies.
- Experience with Datadog, Sumo Logic, Torq, Flare, GCP, Entitle, Okta, Orca, GitLab, or Prisma.
Culture & Benefits
- Work as part of a lean, cross-functional information security team spanning application security, cloud security, security operations, IT security, and compliance.
- Autonomy to define and implement security solutions across the technical ecosystem.
- Opportunity to protect sensitive healthcare systems and customer trust against evolving threats.
- Competitive compensation based on role, level, experience, expertise, and geographic location.
- Equal opportunity employment and a commitment to an inclusive workplace.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →