
Senior Security Engineer II - Application Security
Aledade
🇺🇸 United States
Remote
Senior
2 weeks ago
- DevSecOps
- SAST
- DAST
- Threat Modeling
- Terraform
- CloudFormation
- Python
- C++
- JavaScript
- AWS
- Azure
- GCP
- WAF
- AI
- Machine Learning
- OWASP
- Java
- Scala
- C#
- Health insurance
2 weeks ago
Primary Duties:
- Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
- Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
- Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
- Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures
- Mentoring and coaching more junior engineers or analysts
Minimum Qualifications:
- BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree
- 6+ years of experience in securing and deploying applications within Cloud Native environments
- 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes
Preferred Knowledge, Skills, and/or Abilities:
- Application Security
- Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc, direct experience preferred.
- Experience architecting, developing, and deploying large-scale distributed systems at scale.
- Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.
- Proven experience conducting code reviews, and threat modeling.
- Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc.
- Proficient in coding languages such as Python, R, C++, Javascript.
- Extensive experience working in AWS/Azure/GCP software development environment..
- Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc.
- In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them.
- In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices.
- Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go).
- 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value
- Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred.
Physical Requirements
- Must be able to sit for prolonged periods of time
Senior Security Engineer II - Application Security · Aledade