Cyber Security Engineer (Application Security)
New
T
TherapyNotesHealthcare software
Workable workplace: remote; Workable locations: Philadelphia, Pennsylvania, United StatesFull-TimeSenior
SalaryCompetitive salary - $110,000-$150,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years in application security or security engineering.
- Required Skills
- CI/CDTerraformGitHub ActionsHIPAA
Requirements
- Have 5+ years of experience in application security or security engineering.
- Bring demonstrated experience securing CI/CD pipelines and GitHub Actions.
- Have experience with SAST/DAST and triaging code, secret, and dependency-scanning findings; examples include GitHub Advanced Security and Snyk.
- Understand runner and workflow-permission security, third-party action risk, and software supply-chain risk.
- Have experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
- Have working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage.
- Understand Zero Trust architecture principles and their application to application and identity access.
- Have a strong understanding of HIPAA, HITECH, and HITRUST and their impact on application security.
- Have experience with API security, particularly healthcare-system integrations; familiarity with HL7 or other healthcare data standards is preferred.
- Have experience securing cloud environments; Azure is preferred and AWS is a plus.
- Be willing to participate in an incident-response on-call rotation.
- A bachelor's degree in information security, computer science, or a related field is preferred; equivalent experience is considered.
- Relevant certifications such as GWAPT, OSWE, GPEN, or an Azure/AWS cloud security certification are ideal; CISSP or HCISPP is a plus.
Responsibilities
- Integrate security into the Software Development Lifecycle and CI/CD pipeline in collaboration with development teams.
- Enforce secure coding standards and perform application security assessments, code reviews, and threat modeling.
- Operate GitHub Advanced Security; triage code, secret, and dependency-scanning findings and improve scanning coverage and workflows.
- Secure GitHub Actions identities, runners, permissions, and secrets, and reduce software supply-chain risk through action review, dependency controls, action pinning, and artifact provenance.
- Review Terraform and other infrastructure-as-code for security issues and partner with IT platform teams on scanning and secure deployment practices.
- Align application security measures with HIPAA, HITRUST, and HITECH requirements and support regular audits.
- Guide developers in remediating vulnerabilities and applying patches or mitigation measures.
- Develop, deploy, and manage security tools such as SAST, DAST, and vulnerability management systems.
- Support application security incident response, root-cause identification, and resolution strategies.
- Contribute to development-team security awareness focused on secure coding and proactive security measures.
View Full Description & ApplyYou'll be redirected to the employer's site