LabCorp

Application Security Strategist

LabCorp$160K — $170K *
US-AnywhereRemote in Durham, NC
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of experience in application security or secure software development without a degree; or 8+ years with a Bachelor's in relevant fields; or 6+ years with a Master's.
  • 8+ years focusing on application security risks identification and mitigation.
  • 5+ years applying secure coding principles and translating risks into actionable guidance using OWASP Top 10 best practices.
  • 3+ years working with frameworks like NIST CSF or CIS Controls and aligning practices accordingly.
  • 5+ years designing or securing architectures for web applications, APIs, or microservices.

Responsibilities

  • Define secure development standards for modern application architectures, grounded in OWASP and NIST guidelines.
  • Develop reusable security patterns for common application scenarios such as APIs and microservices.
  • Translate complex security risks into developer-friendly guidance for easy adoption.
  • Collaborate with engineers on secure architecture during design discussions and identify early security pitfalls.
  • Guide on secure integration and data protection patterns including API security and session management.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Life insurance, short-term and long-term disability insurance.
  • 401(k) plan for retirement savings with matching.
  • Paid Time Off (PTO) or Flexible Time Off (FTO) options.
  • Tuition reimbursement for continued education.
Full Job Description
Application Security Strategist to join our team in a remote capacity.

Location: Remote

Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility.

Work Schedule: This is a full-time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in your local time zone. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible.

Work Authorization: This position requires permanent authorization to work in the United States without employer sponsorship now or in the future. Sponsorship (including H-1B, OPT/CPT, EAD, or other temporary work authorization) is not available.

Job Responsibilities

Application Security Design Standards & Patterns
  • Define and document secure development standards and patterns for modern application architectures (web, API, microservices), with guidance grounded in industry best practices such as OWASP and informed by broader frameworks (e.g. NIST, CIS Controls).
  • Develop reusable patterns for common application scenarios such as secure APIs, service-to-service communication and front-end/back-end architecture.
  • Develop reference implementations, code samples, and starter templates that demonstrate secure design patterns in practice and accelerate standards adoption across development teams.
  • Translate complex security risks into clear, developer-focused guidance that can be easily adopted.
  • Contribute to the creation of machine-consumable security patterns to support AI-enabled and automated development tools.


Secure Design Enablement
  • Collaborate with engineers and architects during design discussions to provide guidance on secure application architecture and design decisions.
  • Identify common security pitfalls early in the lifecycle.
  • Provide guidance on secure integration and data protection patterns. For example:
    • Input validation and output encoding
    • API security and authentication flows
    • Session management and token handling
    • Secrets management and secure configuration
  • Promote secure-by-design and secure-by-default principles to enable efficient and secure development practices.
  • Support the integration of authentication and authorization patterns within application architecture.
  • Coach development teams on secure implementation of protocols such as OAuth 2.0, OIDC, and SAML.
  • Guide alignment of application security practices with identity and access management, identity governance, and privileged access management solutions.


Cross-Functional Collaboration
  • Partner with Digital Identity Services, Cybersecurity Engineering, Product Security Testing, and other teams to provide application security guidance and support risk mitigation.
  • Collaborate with the Governance, Risk, and Compliance team to align application security practices with enterprise policies and regulatory requirements.
  • Work with Cybersecurity Operations to enhance detection and response capabilities for application-level threats.
  • Engage with Enterprise Architecture teams to influence secure design decisions.
  • Support data protection initiatives by advising teams on appropriate controls for sensitive data handling and exposure mitigation.


Risk Advisory
  • Review vulnerability patterns and provide guidance on prioritization and remediation of application security risks.
  • Serve as a trusted advisor to engineering and architecture teams, offering practical and actionable security recommendations.
  • Lead the standardization of application security risk management practices across teams.


Continuous Improvement and Innovation
  • Stay current with emerging threats, vulnerabilities, and trends in application security.
  • Evaluate and evolve security standards to support cloud native, API first, distributed, and AI enabled applications.
  • Contribute to the development of scalable, consistent application security enablement practices across the organization.


Minimum Qualifications
  • 8 or more years of combined experience across application security and software development, with a focus on translating application-layer risks into secure design standards and actionable guidance.
  • 5 or more years of experience applying secure coding principles (OWASP Top 10) and designing or securing web applications, APIs, and microservices architectures.
  • 3 or more years of experience with enterprise security frameworks (NIST CSF, CIS Controls, ISO 27001), secure design patterns, and operating in a consultative cross-functional role.
  • 3 or more years of experience with hands-on application or software development, or equivalent demonstrated experience with the ability to credibly engage developers on secure coding practices and design decisions.
  • 2 or more years of experience securing cloud-native applications in AWS or Azure and working with authentication protocols such as OAuth 2.0, OIDC, and SAML.


Preferred Qualifications
  • 3 or more years of experience defining secure development standards, reference architectures, or integrating security into the SDLC, including DevSecOps practices and CI/CD workflows.
  • 2 or more years of experience working with API security frameworks and tooling, with the ability to guide teams on securing modern API-driven architectures.
  • 2 or more years of experience applying threat modeling methodologies to identify design-level risks and guide mitigation strategies with engineering and architecture teams.
  • 2 or more years of experience working with application security testing tools (SAST, DAST, SCA), including interpreting findings and helping teams prioritize and remediate effectively.
  • 1 or more years of experience enabling the secure design of AI-enabled applications, including emerging risks and secure design patterns.


Additional Job Standards
  • Experience supporting security testing or assessment teams.
  • Familiarity with identity and access management platforms such as Okta, Microsoft Entra ID, or SailPoint.
  • Broad familiarity with cloud platform security capabilities and their integration into enterprise environments.
  • Relevant certifications such as CSSLP, GWAPT, or CISSP.
  • Strong analytical and problem-solving skills with a pragmatic approach to security solutions.
  • Developer-focused mindset with an understanding of modern application development practices.
  • Ability to simplify complex technical concepts for diverse audiences.
  • Strong collaboration skills across engineering, security, and architecture teams.
  • Proven ability to deliver practical, scalable, and reusable solutions.
  • High level of professionalism, adaptability, and continuous learning mindset.
  • Strong communication skills with the ability to translate complex security concepts into practical guidance.


About the Role

The Application Security Strategist plays a critical role in strengthening Labcorp's application security posture by enabling secure design and development practices. This position serves as a trusted security advisor to application developers, architects, and leadership, combining deep technical expertise with a consultative approach to guide teams in building secure, scalable applications. It supports enterprise security strategy by embedding security standards, improving risk management practices, and advancing secure development capabilities.

Application Window: 9/30/2026

Pay Range: $160-170k

All job offers will be based on a candidate's skills and prior relevant experience, applicable degrees/certifications, as well as internal equity and market data.

Benefits: Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan. Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan. Employees who are regularly scheduled to work a 7 on/7 off schedule are eligible to receive all the foregoing benefits except PTO or FTO. For more detailed information, please click here.

About LabCorp

LabCorp is a leading global life sciences company that is deeply integrated in guiding patient care through its comprehensive clinical laboratory and end-to-end drug development services. The company provides diagnostic, drug development and technology-enabled solutions for more than 160 million patient encounters annually.
Learn more about LabCorp
Size
70,000 employees
Market Cap
$20.6 billion
Industry
Net Income
$1.5 billion
Founded
1976
5 Year Trend
+11%
Revenue
$13.9 billion

Similar Jobs

More Jobs at LabCorp

More Information Technology Jobs

Find similar Application Security Strategist jobs: