Senior Security Engineer II - Application Security
Primary Duties:
- Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
- Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
- Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
- Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
- Mentoring and coaching more junior engineers or analysts
Minimum Qualifications:
- BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree
- 6+ years of experience in securing and deploying applications within Cloud Native environments
- 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes
Preferred Knowledge, Skills, and/or Abilities:
- Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc, direct experience preferred.
- Experience architecting, developing, and deploying large-scale distributed systems at scale.
- Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.
- Proven experience conducting code reviews, and threat modeling.
- Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc.
- Proficient in coding languages such as Python, R, C++, Javascript.
- Extensive experience working in AWS/Azure/GCP software development environment..
- Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc.
- In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them.
- In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices.
- Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go).
- 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value
- Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred.
Physical Requirements
- Must be able to sit for prolonged periods of time
Skills
As published by lever · 10 questions · 1 written answer
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (1)
- What is your desired salary for this position?
Pick from a list (8)
- Are you legally eligible to work in the United States?
- Do you currently require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas.
- In the future, will you require the company’s sponsorship or need the company’s assistance to obtain or maintain authorization to work legally in the United States? This includes, but is not limited to, H-1B visas (lottery and transfers), TN visas, E-3 visas, or other company-sponsored visas.
- Please list the state that you plan to be physically located in while employed with our company? For employment at Aledade, it is required to be located within the United States; even for remote based roles. optional
- Are you subject to an agreement with a former employer or other party (such as non-competition agreement) that might, in any way, restrict your ability to work for our Company?*
- Would you like to opt-in to receiving text messages for this role regarding the hiring process (e.g., interview requests and reminders)? Note: Selecting “No” will not eliminate you from consideration. Message and data rates may apply. You can opt-out at any time by replying “STOP.”
- By clicking "Submit Application" I agree to the Aledade Applicant Privacy Policy & Terms of Service - https://www.aledade.com/privacy-policy-applicants optional
- By clicking "Submit Application" I certify that all statements made in this application are true and complete. I understand that any falsification, misrepresentation, or omission of fact is sufficient cause for my removal from consideration for employment or my dismissal if hired optional
Written answers (1)
- How did you learn about Aledade?