
Cyber Security Engineer – Application Security
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Pennsylvania.
• Take charge of application security throughout the software development lifecycle and CI/CD pipeline.
• Work closely with development teams to seamlessly integrate security within the SDLC and CI/CD pipeline.
• Enforce secure coding standards and best practices to safeguard the confidentiality, integrity, and availability of customer data.
• Conduct security assessments, code reviews, and threat modeling to uncover vulnerabilities and risks.
• Utilize GitHub Advanced Security, managing code, secret, and dependency-scanning findings while enhancing scanning coverage, configuration, and workflows.
• Secure CI/CD pipelines and GitHub Actions, addressing identities, runners, permissions, and secrets.
• Mitigate software supply-chain risks through thorough reviews of third-party actions, dependency controls, action pinning, and artifact provenance.
• Assess Terraform and other infrastructure-as-code for security vulnerabilities and collaborate with IT platform teams on secure deployment methods.
• Ensure application security practices align with HIPAA, HITRUST, and HITECH standards and assist in regular audits.
• Partner with developers on vulnerability remediation and effective patching or mitigation strategies.
• Develop, implement, and manage SAST, DAST, vulnerability management, and other security tools.
• Assist in application security incident response, root cause analysis, and resolution strategies.
• Contribute to security awareness initiatives focusing on secure coding and proactive security practices.
• Engage in broader security engineering projects, including vulnerability management, incident response, and identity and access security.
• Preferred Bachelor's degree in information security, computer science, or a related field; equivalent experience will be considered.
• Over 5 years of experience in application security or security engineering.
• Proven experience in securing CI/CD pipelines and GitHub Actions, encompassing SAST/DAST, code/secret/dependency-scanning triage, runner and workflow permissions, as well as third-party action and supply-chain risk management.
• Experience in reviewing Terraform or other infrastructure-as-code for security misconfigurations.
• Familiarity with SIEM, EDR/XDR, and DLP platforms, including their deployment, tuning, and alert triaging.
• Understanding of Zero Trust architecture principles and their application to application and identity access.
• Strong knowledge of HIPAA, HITECH, and HITRUST and their implications for application security.
• Experience with API security, especially integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards is preferred.
• Prior experience in securing cloud environments; Azure is preferred, with AWS being a plus.
• Willing to participate in an incident response on-call rotation.
• Ideal candidates will hold industry certifications such as GWAPT, OSWE, GPEN, or an Azure/AWS cloud security certification; CISSP or HCISPP are advantageous but not substitutes for hands-on tooling experience.
• A commitment to continuous learning and professional growth.
• Ability to quickly adapt to new challenges.
• Strong work ethic and dedication to seeing projects through to completion.
• Excellent collaboration skills when working with cross-functional teams.
• Employer-sponsored health, dental, vision, life, and disability insurance.
• Retirement plan with company contributions.
• Annual company profit-sharing opportunities.
• Personal development and training budget.
• Open and collaborative work environment.
• Comprehensive 2-week onboarding program.
• Extensive mentorship program.
PowerSchool
PowerSchool
Thermal Scientific Works
Shure Incorporated
Get handpicked remote jobs straight to your inbox weekly.