Mayo Clinic

SR Information Security Engineer - IS-Mod - 80651

Mayo Clinic • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field with 5 years of experience, or a Master's degree with 4 years of experience preferred.
  • Certifications required: CISSP, CISM, GSEC, OSCP, or equivalent.
  • Strong experience in software, systems, and platform engineering in modern development environments.
  • Proficient understanding of Secure Software Development Lifecycle (SSDLC) and application security practices.
  • Familiarity with CI/CD pipelines and application security controls like SAST and SCA.

Responsibilities

  • Lead complex security engineering initiatives to optimize security solutions.
  • Translate security requirements into scalable solutions while collaborating with IT.
  • Design and maintain CI/CD pipelines for application security tool evaluation.
  • Create workflows to test and validate security controls in agentic development.
  • Research and assess security risks associated with AI-assisted software practices.

Benefits

  • Opportunity to work with advanced security frameworks and technologies.
  • Significant autonomy as a technical authority in a senior-level role.
  • Collaboration across multidisciplinary teams to influence security practices.
  • Involvement in cutting-edge initiatives related to AI and application security.
Full Job Description
Job Description

The Senior Information Security Engineer is a senior-level technical position responsible for leading complex security engineering initiatives and providing advanced expertise across multiple information security domains. The position operates with significant autonomy, serves as a technical authority, and is accountable for designing, implementing, and optimizing security solutions that address enterprise risk, regulatory requirements, and business objectives.

Depending on the area of focus, the Senior Information Security Engineer may lead Secure Software Development Lifecycle (SSDLC) initiatives focused on enabling security across software development and delivery pipelines or advancing security practices for agentic and AI-assisted software development. Examples of such activities include the following:
  • Serves as a technical subject matter expert, collaborating across Information Security and IT to translate security requirements into practical and scalable solutions. Provide adoption guidance for developers.
  • Design and maintain representative development environments and CI/CD pipelines to evaluate, validate, and demonstrate application security tools and controls.
  • Design and maintain representative agentic development workflows to test and validate security controls.
  • Research emerging agentic and AI-assisted development practices and associated security risks and controls.
  • Evaluate security technologies and capabilities for risks introduced by agentic and AI-assisted software development.


Qualifications

Bachelor's degree in applicable field plus five (5) years of relevant experience. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

Master's degree in applicable field plus four (4) years of relevant experience preferred. Pertinent fields of study and experience include, but are not limited to, information security, computer science, information systems, engineering, or a related field.

One or more of the following certifications (or equivalent) are required at time of hire: CISSP, CISM, GSEC, OSCP.

Preferred Qualifications
  • Strong software, systems, platform, or security engineering experience supporting modern application development and delivery environments.
  • Strong understanding of SSDLC and application security practices, with experience translating security requirements into technical solutions and guidance.
  • Experience with CI/CD pipelines, build processes, cloud or container technologies, and application security controls such as SAST, SCA, and software supply chain security.
  • Experience with AI-assisted and agentic software development technologies and workflows, including associated application security risks and controls.
  • Strong technical leadership, communication, and collaboration skills across security and technology teams.


This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.

About Mayo Clinic

Mayo Clinic is a nonprofit academic medical center based in Rochester, Minnesota, focused on integrated clinical practice, education, and research. It employs more than 4,500 physicians and scientists and 58,400 administrative and allied health staff. The practice specializes in treating difficult cases through tertiary care and destination medicine. It is home to the Mayo Clinic College of Medicine and Science, which includes a medical school and research programs. Mayo Clinic has a large presence in three U.S. metropolitan areas: Rochester, Minnesota; Jacksonville, Florida; and Phoenix, Arizona. It also has several affiliated hospitals and clinics elsewhere in the United States and around the world.
Learn more about Mayo Clinic
Size
74,000 employees
Industry
Founded
1919

Similar Jobs

More Jobs at Mayo Clinic

More Information Technology Jobs

Find similar SR Information Security Engineer - IS-Mod - 80651 jobs: