Athena Health

Lead Application Security Engineer- DevSecOps

Athena Health$143K — $243K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cyber Security, or similar, or equivalent experience
  • 3-5 years in a security-focused development role in an agile environment
  • Experience in software and product design and architecture
  • Strong software engineering skills with coding proficiency
  • Practical experience with Docker and Terraform
  • Strong knowledge of OAuth 2.0, SAML, and service authentication
  • Hands-on experience with cloud platforms and CI/CD security controls

Responsibilities

  • Drive security strategy and SDLC adoption for product development
  • Advance key security practices across the R&D organization
  • Contribute to the enterprise security catalog of best practices
  • Own application security capabilities design, implementation, and improvement
  • Support various security testing workflows including SAST and DAST
  • Lead the API security testing program and manage its operational elements
  • Partner with cross-functional teams to resolve security issues

Benefits

  • Access to continuous professional development and training opportunities
  • Flexible working arrangements to support work-life balance
  • Collaborative and innovative work environment focused on security advancement
  • Opportunities for cross-departmental teamwork
  • Employee wellness programs with a focus on health and well-being
Full Job Description
athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security. This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes. About the Team This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth's products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment. Core Responsibilities - Security strategy and SDLC adoption - Socialize and drive execution of key security best practices across the R&D organization. - Contribute to the enterprise security catalog of best practices, techniques, and patterns. - Improve the quality and adoption of Security Development Lifecycle practices. - Application security capability ownership - Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities. - Support SAST, SCA, DAST, API security testing, and vulnerability management workflows. - Document, share, and help automate coverage for common abuse cases and attacks. - API security program leadership - Lead the API security testing program. - Manage API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness. - Identify and explain feature-level design or architectural weaknesses that could create security issues. - Cross-functional partnership and issue management - Partner with enterprise security leadership to track and prioritize open issues and follow through on resolution. - Work with DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to design and operate security-hardened platforms. Required Experience & Skills - Bachelor's degree in Computer Science, Computer Engineering, Cyber Security, or similar, or equivalent experience. - At least 3 years of experience as a software developer and 3-5 years in a security-focused development role in an agile environment. - Experience in software and product design and architecture, product security, and security issue prevention and mitigation. - Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages. - Practical experience with Docker and Terraform. - Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication. - Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts. - Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls. - Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD. - Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus. Why This Role Matters This role is central to strengthening secure software delivery across athenahealth. It combines technical depth, security leadership, and cross-functional influence to improve how security is built into products from the start. Expected Compensation $143,000 - $243,000 The base salary range shown reflects the full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates. Base pay is only one part of our competitive Total Rewards package - depending on role eligibility, we offer both short and long-term incentives by way of an annual discretionary bonus plan, variable compensation plan, and equity plans.

About Athena Health

Athenahealth, Inc. is a provider of cloud-based services for healthcare providers. The company was founded in 1997 by Jonathan Bush and Todd Park and is headquartered in Watertown, Massachusetts. Athenahealth's services include electronic health records, revenue cycle management, and patient engagement. The company serves healthcare providers in the United States and has been recognized for its innovative approach to healthcare technology. In 2018, Athenahealth generated $1.2 billion in revenue.
Learn more about Athena Health
Size
5,100 employees
Industry

Similar Jobs

More Jobs at Athena Health

More Information Technology Jobs

Find similar Lead Application Security Engineer- DevSecOps jobs: