S
Saviance
Posted 24 days agoVerified live 1d ago

Application Security Engineer

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Application SecuritySonarQubeSASTDASTSCAIASTCI/CD PipelinesOWASP Top 10Secure CodingJavaC#/.NETPythonJavaScriptPenetration TestingVulnerability ManagementHIPAANIST

Job description

Summary

The organization is a leader in clinical genetic testing that handles sensitive patient data across web, API, and pipeline applications. It is seeking an Application Security Engineer to build and mature its application security program, embed security throughout the SDLC, manage code analysis tooling, support remediation efforts, and help maintain HIPAA compliance.

Responsibilities

  • Implement and manage static and dynamic code analysis, integrating SonarQube (and complementary SAST/DAST/SCA tools) into CI/CD pipelines and check-in scans, and partner with engineering to triage and remediate findings
  • Perform penetration tests and vulnerability assessments across web, API, and pipeline applications, and lead consistent, timely remediation of identified findings
  • Develop and maintain a structured remediation program that addresses and resolves security findings quickly, consistently, and in priority order
  • Evolve the organization's SDLC into a Secure SDLC (SSDLC) by embedding Security by Design and Privacy by Design principles at every stage
  • Integrate secure coding practices with development teams, providing guidance, threat modeling, and secure architecture reviews for new features and releases
  • Generate regular reports on the status of application security initiatives, vulnerability management, and risk assessments for technical and executive audiences
  • Collaborate with auditors during internal and external audits, providing explanations, evidence, and documentation, and draft security policies and procedures as needed
  • Partner cross-functionally with IT, Privacy, Compliance, and business units to support initiatives and drive measurable risk reduction

Skills

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field — or an equivalent combination of education and experience
  • Minimum of 3–5 years of experience in application security, DevSecOps, or software engineering with a security focus
  • Hands-on experience with SonarQube for static code analysis and code quality/security gating
  • Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines
  • Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript
  • Familiarity with penetration testing, code review, and vulnerability management processes
  • Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR
  • Excellent written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and collaborate cross-functionally
  • Detail-oriented, self-directed, and able to prioritize in a fast-moving environment
  • Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent
  • Experience securing web applications, APIs, and cloud-native/containerized workloads
  • Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect)
  • Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field — or an equivalent combination of education and experience
  • Minimum of 3–5 years of experience in application security, DevSecOps, or software engineering with a security focus
  • Hands-on experience with SonarQube for static code analysis and code quality/security gating
  • Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines
  • Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript
  • Familiarity with penetration testing, code review, and vulnerability management processes
  • Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR
  • Excellent written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and collaborate cross-functionally
  • Detail-oriented, self-directed, and able to prioritize in a fast-moving environment

Nice to Haves

  • Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent
  • Experience securing web applications, APIs, and cloud-native/containerized workloads
  • Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect)
  • Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment

Benefits

  • Remote work arrangement in the United States

More jobs like this