
Cyber Security Engineer – Application Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Pennsylvania.
• Take ownership of application security throughout the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipeline.
• Work closely with development teams to seamlessly integrate security measures into the SDLC and CI/CD processes.
• Implement secure coding standards and best practices to ensure the confidentiality, integrity, and availability of customer data.
• Conduct security assessments, code reviews, and threat modeling activities.
• Manage and operate GitHub Advanced Security, including the triage of findings related to code, secrets, and dependency scanning.
• Detect recurring patterns of vulnerabilities and propose comprehensive solutions.
• Enhance scanning coverage, configuration, and workflows.
• Secure CI/CD pipelines and GitHub Actions, covering identities, runners, permissions, and secrets.
• Mitigate software supply-chain risks through thorough reviews of third-party actions, dependency controls, action pinning, and artifact provenance.
• Review Terraform and other infrastructure-as-code for security vulnerabilities.
• Collaborate with IT platform teams on Infrastructure as Code (IaC) scanning and secure deployment practices.
• Ensure that application security measures comply with HIPAA, HITRUST, and HITECH and assist in regular audits.
• Partner with developers to address vulnerabilities and ensure effective patching or mitigation strategies.
• Develop, deploy, and manage Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and vulnerability management tools.
• Provide support for application security incident response, root-cause analysis, and resolution strategies.
• Contribute to secure-coding awareness initiatives for development teams.
• Participate in broader security engineering efforts, including vulnerability management, incident response, and identity and access security.
• Preferred: Bachelor's degree in information security, computer science, or a related field; equivalent experience will be considered.
• At least 5 years of experience in application security or security engineering.
• Proven experience in securing CI/CD pipelines and GitHub Actions, including SAST/DAST, triage of code/secret/dependency scanning, runner and workflow-permission security, and managing third-party action/supply-chain risks.
• Experience in reviewing Terraform or other infrastructure-as-code for security misconfigurations.
• Practical knowledge of SIEM, EDR/XDR, and DLP platforms, encompassing deployment, tuning, and alert triage.
• Familiarity with Zero Trust architecture principles and their application in application and identity access security.
• Strong knowledge of HIPAA, HITECH, and HITRUST and their implications for application security.
• Experience with API security, particularly in integrating with other healthcare systems.
• Previous experience securing cloud environments; Azure preferred, with AWS as a plus.
• Willingness to participate in an on-call rotation for incident response.
• Industry certifications such as GWAPT, OSWE, GPEN, or Azure/AWS cloud security certification are preferred; CISSP or HCISPP is a plus but not a substitute for practical tooling experience.
• Familiarity with HL7 or other healthcare data standards is preferred.
• Employer-sponsored health, dental, vision, life, and disability insurance.
• Retirement plan with company contributions.
• Annual profit-sharing opportunities.
• Personal development and training budget.
• Open and collaborative work environment.
• Comprehensive 2-week onboarding program.
• Robust mentorship program.
Centene Corporation
Innomotics
GE Vernova
Honeywell
Get handpicked remote jobs straight to your inbox weekly.