The Opportunity:
TheSeniorApplicationSecurityEngineer, Cybersecurity willserve as a key member of the Cybersecurity Technical Assessments team, providing advancedexpertisein secure software development practices and application tooling.This roleis responsible formanaging andoptimizingthe application security tool stackincluding SAST, DAST, SCA,IaCscanning, and secret detectionand ensuring its effective integration into the software development
lifecycle (SDLC).The Senior Application Security Engineer will collaborate with development, engineering, and product teams toidentify, triage, and remediate vulnerabilities, while also mentoring junior engineers and contributing to the evolution of secure development practices across the organization.
Job Competencies:
Technical Proficiency:
- Deepexpertisein application security tooling (SAST, DAST, SCA,IaCscanning, secret scanning)
- Strong understanding of secure coding principles and SDLC integration
- Proficiencyin scripting and programing languages (e.g., .NET, Python, JavaScript)
Analytical Skills:
- Ability to analyzeandvalidatesecurity findings, prioritize risk, and guide remediation
- Strong attention to detail inidentifyingfalse positives and systemic security gaps
Communication Skills:
- Ability to clearly communicate technical issues to both technical and non-technical stakeholders
- Skilled in writing documentation, reports, and presenting findings to cross-functional teams
Team Collaboration:
- Experience working in Agile/DevOps environments with cross-functional teams
- Ability to mentor junior engineers and lead small-scale security initiatives
- Ability to work effectively with a remotelylocatedteam spanning multiple time zones
Continuous Learning:
- Commitment to stayingcurrentwithevolving security tools, threats, and best practices
- Active pursuit of professional development and relevant certifications
Essential Job Functions:
- Manage andoptimizeapplication security tools (SAST, DAST, SCA,IaC, secret scanning) and ensure effective integration into CI/CD pipelines andthe SDLC lifecycle
- Analyze source codeand infrastructure-as-code for security vulnerabilities andprovideactionable remediation guidance
- Validate and triage findings from security tools,removingfalse positives andensuringaccurateissue tracking
- Create and manage remediation tickets (e.g., Aha!Ideas, ServiceNow Requests),ensuring vulnerabilities are prioritized, assigned, and tracked to resolution
- Collaborate with development and engineering teams to validate remediation efforts and confirm closure of security issues
- Participate in the risk management process by documenting, reviewing, andmaintainingrisk exceptions for unresolved or accepted vulnerabilities
- Work with risk owners and business stakeholders to ensureappropriate compensatingcontrols are in place and documented
- Lead secure code reviews and contribute to threat modelingand design discussions for high-risk applications
- Mentorjunior engineers andprovidetechnical guidance on secure development practices
- Contribute to the development and refinement of secure coding standards, policies, and procedures
- Develop andmaintaindashboards and reports that communicate application security posture, remediation progress, and risk trends to leadership
- Identifyrecurring security issues and propose systemic improvements to reduce future risk
- Lead efforts to evaluate, pilot, and implement new application security tools and integrations that enhance automation and coverage
- Continuously refine scanning configurations and policies to improve signal-to-noise ratio in findings
- Stay informed on emerging threats, vulnerabilities, and industry trends, and recommend improvements totooling and processes
- Participate in the evaluation and onboarding of new security tools and technologies
- Work closely with cross-functional stakeholders to analyze and troubleshoot complex production issues
- This position pays between $101,000-$152,400 based on experience
- Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
- This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role27s range.
#LI-LP1
#LI-Remote