
Lead Application Security Engineer- DevSecOps
Athenahealth1 day ago
Base Salary
$143k - $243k/yr
Responsibilities
- Drive security best practices and Security Development Lifecycle adoption across the R&D organization.
- Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities.
- Support SAST, SCA, DAST, API security testing, vulnerability management, and CI/CD security control workflows.
- Lead API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness.
- Identify and explain feature-level design and architectural weaknesses that could create security issues.
- Document and automate coverage for common abuse cases and attacks.
- Partner with engineering, DevOps, infrastructure, IAM, API Gateway, NOC, and enterprise security teams to design and operate security-hardened platforms.
- Track, prioritize, and follow through on resolution of security issues with enterprise security leadership.
Requirements
- Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or a similar field, or equivalent experience.
- At least 3 years of experience as a software developer and 3–5 years in a security-focused development role in an agile environment.
- Experience with software and product design and architecture, product security, and security issue prevention and mitigation.
- Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages.
- Practical experience with Docker and Terraform.
- Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication.
- Understanding of RESTful services, service bus architectures, JSON, and related web services concepts.
- Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls.
- Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD.
- Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus.
Benefits
- Base salary range is $143,000–$243,000, with potential annual discretionary bonuses, variable compensation, and equity plans.
- Health and financial benefits are provided, along with location-specific commuter support, employee assistance programs, tuition assistance, employee resource groups, and collaborative workspaces.
- The company supports flexible work arrangements with in-office collaboration and digital collaboration tools.
- Employees can participate in book clubs, external speaker events, hackathons, and an inclusive learning-oriented culture.
About Athenahealth
Athenahealth builds cloud-based electronic health records, practice management, revenue cycle, and patient engagement software for medical practices and health systems, often paired with technology-enabled billing services. The company sells its platform on a subscription basis and supports high-volume clinical and financial workflows across its network. Founded in 1997 and headquartered in Boston, it is privately held under Bain Capital.