Qualifications
Responsibilities
Benefits
Job Posting Title:
Senior Application Security Engineer----
Hiring Department:
Dell Medical School----
Position Open To:
All Applicants----
Weekly Scheduled Hours:
40----
FLSA Status:
Exempt from FLSA----
Earliest Start Date:
Immediately----
Position Duration:
Expected to Continue----
Location:
AUSTIN, TX----
Job Details:
General NotesThe Senior Application Security Engineer is responsible for embedding security throughout the software development lifecycle across Dell Medical School's cloud, platform, and enterprise application environments, including Microsoft Azure, Adobe Experience Cloud, and other cloud platforms. This role partners with development, infrastructure, cybersecurity, clinical, research, and operational teams to strengthen application security, support secure software delivery, and reduce organizational risk while enabling innovation across academic, research, and healthcare environments.
Important Employment InformationThis position is not eligible for employer-sponsored work authorization. Applicants requiring current or future visa sponsorship are not eligible for employment in this position.
PurposeThe Senior Application Security Engineer is responsible for integrating security throughout the software development lifecycle across cloud, platform, and enterprise application environments. This role leads secure code review, application security testing, vulnerability management, cloud security assessments, and secure development initiatives while partnering with development teams to ensure compliance with HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 requirements. The position supports applications developed for academic, research, and clinical environments, including biomedical systems operating within healthcare settings.
ResponsibilitiesSecure Development and Code Review
Develop, implement, and maintain Secure Software Development Lifecycle (SSDLC) standards supporting Azure-hosted applications, Adobe Experience Cloud, and other internally managed platforms
Support secure software development for academic, research, and clinical applications, with an emphasis on higher-risk clinical systems
Perform manual and automated secure code reviews for internally developed applications, identifying vulnerabilities aligned with the OWASP Top 10 and CWE Top 25
Integrate Static Application Security Testing (SAST) and Software Composition Analysis (SCA) into CI/CD pipelines
Partner with software developers to remediate vulnerabilities and promote secure coding practices through guidance and education
Security Testing and Vulnerability Management
Configure and operate Burp Suite Professional/Enterprise for Dynamic Application Security Testing (DAST) and authorized penetration testing
Utilize OWASP ZAP for automated and on-demand application security scanning
Perform controlled validation testing using Metasploit during authorized penetration testing engagements
Triage, prioritize, and track remediation efforts through a risk-based vulnerability management process
Coordinate security testing schedules with application owners to minimize operational disruption
Support QA and automated testing initiatives validating application security controls throughout deployment pipelines
Cloud and Platform Security
Assess Microsoft Azure and other cloud environments for security posture, including identity and access management, network segmentation, and resource-level security controls
Review Adobe Experience Cloud and SaaS/PaaS integrations to ensure secure configuration and appropriate data protection
Support secure API design, authentication, authorization, and data validation practices
Recommend improvements that strengthen cloud and enterprise application security architecture
AI, Robotics, and Biomedical Systems Security
Assess the security of AI/ML models, data pipelines, and AI-enabled applications
Review secure integration of generative AI tools, chatbots, and AI-driven APIs supporting institutional applications
Evaluate security controls for robotics programming, automation platforms, and robotic process automation (RPA) solutions
Support security assessments of biomedical systems and connected medical devices operating within clinical environments
Collaborate with research, innovation, and clinical teams to embed secure development practices throughout AI and robotics initiatives
Governance, Risk, and Compliance
Align application security practices with HIPAA, HITRUST CSF, NIST CSF 2.0, TAC 202, and UTS 165 requirements
Support third-party risk assessments (TPRM) and application security reviews
Participate in audit activities, including HITRUST readiness assessments
Develop and maintain application security policies, standards, and procedures
Cross-Functional Collaboration
Partner with Cybersecurity Analysts on threat modeling, incident response, and architecture reviews for new applications and integrations
Collaborate with the campus Information Security Office (ISO) to support application security standards, risk assessments, vulnerability management, and coordinated incident response
Work closely with Infrastructure, Development, and Platform Engineering teams to integrate security throughout project lifecycles
Communicate technical findings, security risks, and recommendations to technical and executive stakeholders
Marginal or Periodic Functions
Adhere to internal controls and reporting structure
Perform related duties as assigned
Tech Savvy
Maintain current knowledge of secure software development, cloud security, application security testing, and emerging cybersecurity technologies
Evaluate new tools and technologies that strengthen enterprise application security
Apply modern security practices across cloud, application, and software development environments
Decision Quality
Make sound security decisions balancing organizational risk, operational needs, and regulatory requirements
Evaluate vulnerabilities and recommend practical remediation strategies
Prioritize security initiatives using risk-based methodologies
Manages Complexity
Navigate complex cloud, application, and healthcare technology environments
Balance multiple priorities across development, security, and operational initiatives
Integrate security controls into rapidly evolving technology ecosystems
Collaborates
Build productive working relationships with development, infrastructure, cybersecurity, clinical, research, and operational teams
Promote security awareness and secure development practices throughout the organization
Facilitate collaboration across multidisciplinary technical teams
Action Oriented
Take ownership of application security initiatives and vulnerability remediation efforts
Drive continuous improvement of secure development practices
Respond proactively to emerging application security risks
Ensures Accountability
Maintain accountability for application security standards and vulnerability management activities
Promote compliance with organizational security policies and regulatory requirements
Support secure software delivery through consistent governance and oversight
Communicates Effectively
Communicate technical concepts clearly to both technical and non-technical audiences
Present security findings, recommendations, and risk assessments effectively
Develop documentation supporting secure development and application security best practices
Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field; or an equivalent combination of education and professional experience
Minimum of eight (8) years of experience in application security, secure code review, penetration testing, or secure software development
Hands-on experience using Burp Suite, OWASP ZAP, and Metasploit for application security testing and vulnerability validation
Experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools such as Checkmarx, Veracode, SonarQube, or similar platforms
Experience securing Microsoft Azure and other cloud environments
Experience implementing secure coding practices across common programming languages and web application frameworks
Knowledge of Secure Software Development Lifecycle (SSDLC) methodologies
Strong analytical, troubleshooting, and problem-solving skills
Excellent verbal and written communication skills
Ability to collaborate effectively with software developers, infrastructure teams, cybersecurity professionals, and business stakeholders
Relevant education and experience may be substituted as appropriate.
Preferred QualificationsExperience supporting healthcare or higher education environments
Knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 security frameworks
Experience securing Microsoft Azure, Adobe Experience Cloud, SaaS/PaaS platforms, and cloud-native applications
Familiarity with AI/ML security concepts, including model security, data governance, prompt injection risks, and adversarial attacks
Experience supporting robotics, robotic process automation (RPA), biomedical systems, or connected medical devices
Experience integrating application security testing into QA processes, automated testing frameworks, and CI/CD pipelines
Experience performing application threat modeling, secure architecture reviews, and third-party risk assessments (TPRM)
Licenses/Registrations/Certifications
Required
None
Preferred
Offensive Security Certified Professional (OSCP)
GIAC Web Application Penetration Tester (GWAPT)
Certified Secure Software Lifecycle Professional (CSSLP)
Certified Ethical Hacker (CEH)
Microsoft Azure Security Engineer Associate (AZ-500)
$120,000+ depending on qualifications
Working ConditionsStandard office environment and equipment
Repetitive use of a keyboard and computer
Hybrid work environment with on-site collaboration as business needs require
May participate in after-hours security testing, incident response, vulnerability remediation, or critical production support activities
May be exposed to communicable diseases, blood borne pathogens, ionizing and non-ionizing radiation, hazardous medications, and disoriented or combative patients while supporting healthcare environments
Resume/CV
3 work references with their contact information; at least one reference should be from a supervisor
Letter of interest
Important for applicants who are NOT current university employees or contingent workers: You will be prompted to submit your resume the first time you apply, then you will be provided an option to upload a new resume for subsequent applications. Any additional Required Materials (letter of interest, references, etc.) will be uploaded in the Application Questions section, where you may upload multiple files. Before submitting your online job application, ensure that all Required Materials have been uploaded. Once your job application has been submitted, you cannot make changes.
Important for Current University employees and contingent workers: As a current university employee or contingent worker, you must apply within Workday by searching Find UT Jobs. Log in to Workday, navigate to your Worker Profile, click the Career link in the left-hand navigation menu, and update your Professional Profile before applying. This information will be pulled into your application. The application is one page, and you will be prompted to upload your resume. In addition, you must respond to the application questions to upload any additional Required Materials noted above.
About University Of Texas
Similar Jobs


More Jobs at University Of Texas





More Healthcare Jobs
