Cyber Security Engineer (Application Security)

New
T
TherapyNotesHealthcare software
Workable workplace: remote; Workable locations: Philadelphia, Pennsylvania, United StatesFull-TimeSenior
SalaryCompetitive salary - $110,000-$150,000
Apply NowOpens the employer's application page

Job Details

Experience
5+ years in application security or security engineering.
Required Skills
CI/CDTerraformGitHub ActionsHIPAA

Requirements

  • Have 5+ years of experience in application security or security engineering.
  • Bring demonstrated experience securing CI/CD pipelines and GitHub Actions.
  • Have experience with SAST/DAST and triaging code, secret, and dependency-scanning findings; examples include GitHub Advanced Security and Snyk.
  • Understand runner and workflow-permission security, third-party action risk, and software supply-chain risk.
  • Have experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
  • Have working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage.
  • Understand Zero Trust architecture principles and their application to application and identity access.
  • Have a strong understanding of HIPAA, HITECH, and HITRUST and their impact on application security.
  • Have experience with API security, particularly healthcare-system integrations; familiarity with HL7 or other healthcare data standards is preferred.
  • Have experience securing cloud environments; Azure is preferred and AWS is a plus.
  • Be willing to participate in an incident-response on-call rotation.
  • A bachelor's degree in information security, computer science, or a related field is preferred; equivalent experience is considered.
  • Relevant certifications such as GWAPT, OSWE, GPEN, or an Azure/AWS cloud security certification are ideal; CISSP or HCISPP is a plus.

Responsibilities

  • Integrate security into the Software Development Lifecycle and CI/CD pipeline in collaboration with development teams.
  • Enforce secure coding standards and perform application security assessments, code reviews, and threat modeling.
  • Operate GitHub Advanced Security; triage code, secret, and dependency-scanning findings and improve scanning coverage and workflows.
  • Secure GitHub Actions identities, runners, permissions, and secrets, and reduce software supply-chain risk through action review, dependency controls, action pinning, and artifact provenance.
  • Review Terraform and other infrastructure-as-code for security issues and partner with IT platform teams on scanning and secure deployment practices.
  • Align application security measures with HIPAA, HITRUST, and HITECH requirements and support regular audits.
  • Guide developers in remediating vulnerabilities and applying patches or mitigation measures.
  • Develop, deploy, and manage security tools such as SAST, DAST, and vulnerability management systems.
  • Support application security incident response, root-cause identification, and resolution strategies.
  • Contribute to development-team security awareness focused on secure coding and proactive security measures.
View Full Description & ApplyYou'll be redirected to the employer's site
Competitive salary - $110,000-$150,000
Apply Now