Full Job Description
Staff Engineer, DevSecOps Security Engineering
Health 100 Focus | Security Implementation, Migration and Automation Leadership
Role Overview
The Staff Engineer, DevSecOps Security Engineering, isresponsible for leadingtechnicalimplementation, migration, automation, mobile application security and standardizationacross the Health 100 portfolio. This roletranslates applicationsecuritystrategy into scalable engineering solutions that strengthen release readiness, improvevulnerability remediation,expand security and mobile testing coverage, and enable secure-by-default deliveryacross engineering teams.
Who You Are
A seniortechnical employeewith deepexpertise inapplication security, DevSecOps, automation and secure deliverypractices.
Experiencedtranslatingsecuritystrategy into implementations that development teams can adopt consistently.
Strong inautomation, tooling integrationandprocess improvementthat reduce manualeffortand improveengineering outcomes.
Comfortable using metrics to communicate technical risk, delivery progress and measurable outcomes.
Able to balance hands-on engineering depth with cross-functional influence acrossapplication,platform,cloudand security teams.
Role Responsibilities
1. Health 100 Security Enablement
Support application onboarding andsecurityenablementforHealth 100 initiatives.
Help development teams meet security requirements throughstandardtooling, pipelineintegration and repeatable implementation patterns.
Translate release-readiness expectations into repeatable technical patterns and evidence.
Ensuremobile applicationsare included in Health 100 security enablementthrough mobile application security testing,secureconfigurationvalidationandclear remediation guidance.
2. Security Implementation & Major Initiatives
LeadDevSecOpsimplementationinitiatives aligned to security goals and engineering priorities.
Own technicalplanning, architecture, delivery,issueresolutionand implementation outcomes.
Coordinate across application,platformand security teams to remove blockers and sustain adoption.
3. Pipeline Enforcement & Automation
Design, implementandimproveCI/CD security controls,pipeline enforcement and automated scanning workflows.
Partner with developmentandplatform teams to embed security controlswithoutcreating unnecessary delivery friction.
Build self-service security solutions and reusable automation that reduce manual intervention and improve engineering efficiency.
Automatesecret-detectionand CI/CD security workflows, including Gitleaks or comparable capabilities.
4. Security Tool Migration & Standardization
Lead security-tool migrations, including transitions such as Checkmarx to Snyk, from design through stable productionoperation.
Produce and validate initial post-migration scan results to demonstrate successful implementation and integration.
Standardize tooling configurations across development teams to improve consistency, ease ofuseand policy alignment.
Partner with platform teams to reduce legacy pipeline risk, fragmentedconfigurationsand duplicated manual processes.
5. Vulnerability Reduction & SLA Compliance
Drive remediation of critical and high-risk vulnerabilities across Health 100 applications with clear technical ownership and follow-through.
Monitor remediation against established SLAs andidentifyaging,recurrenceand systemic issues.
Lead technical prioritization of high-impact open-source and software supply chain exposures affecting multiple applications.
Provide remediation guidance and scalable fixes that teams can adopt consistently.
6. Supply Chain, Cloud & Container Security
Improve open-source visibility through SBOM coverage and related software supply chain practices.
Drive secure-by-default dependency usage and remediation of high-risk third-party components.
Engineer controls for public cloud, container, Kubernetes, Security-as-Codeand Infrastructure-as-Code environments.
Applynetwork-securityandcloud-architectureexpertiseto design practical, resilient solutions.
Applymobile securityexpertise to assessiOS and Android applicationrisk, validatemobile security testing results and guideremediationof mobile-specific findings.
7. Metrics, Reporting & Continuous Improvement
Trackand reportscan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption,tool coverage andpipeline compliance.
Use metrics toidentifycontrol gaps, adoptionbarriersand opportunities for continuous improvement.
Provide concise, executive-ready updates on implementation progress, deliveryriskand measurable security outcomes.
8. Technical Leadership & Knowledge Enablement
Serve as a senior technical authority for DevSecOps implementation,migrationand automation decisions.
Mentorengineers,establishreusable engineering patterns and strengthen technical consistency across teams.
Create clear implementation guidance and education that foster developer self-service and security awareness.
Build resilient ownership and support models that reduce single points of failure.
Success Measures
Migration delivery:Tooling and process migrationsaredeliveredwith validated results and minimal operational disruption.
Automation enablement:Secret detection and CI/CD security workflows are automated, reducing manual effort and improving consistency.
Standardization:Security tooling and pipeline configurations are standardized across participating development teams.
Risk reduction:Critical and high-risk vulnerabilities are reduced, with remediation performance measured against established SLAs.
Coverage and adoption:Scan coverage, mobileapplication security testingcoverage, tool adoption, pipeline compliance and self-service usageshow measurable improvement.
Release readiness:Health 100 applications have consistent, enforceable security controls and clear evidence supporting launch decisions.
Qualifications
Basic Qualifications
7+ years of experience in DevSecOps, application security engineering, platform security or software engineering.
Experienceintegrating SAST, SCA, secrets detection, container scanning, IaC scanning or comparablesecurity controlsinto CI/CD pipelines.
Experience leading security implementations or tool migrations in large or complex engineering environments.
Proficiencyin public cloud platforms such as AWS,Azureor GCP, plus cloud and netwo