Senior Security Engineer - Secure SDLC
Highmark Health1 day ago
Remote, United StatesSenior
Base Salary
$103k - $165k/yr
Responsibilities
- Design and enforce shift-left security controls, pipeline security gates, security-as-code policies, and secure SDLC standards across enterprise development workflows.
- Deploy, configure, integrate, and optimize SAST, DAST, dependency, container, secret detection, API security, and AI application security scanning tools.
- Lead vulnerability triage, risk prioritization, root cause analysis, remediation SLAs, and reduction of critical and high-severity findings.
- Assess and mitigate risks involving AI-generated code, LLM integrations, prompt injection, insecure agents, sensitive data exposure, model supply chains, and MCP-enabled tooling.
- Architect and maintain application security toolchains, automation workflows, dashboards, reporting pipelines, and security posture metrics.
- Advise engineering teams through code reviews, threat modeling, architecture reviews, remediation guidance, training, workshops, and Security Champions programs.
- Define and operationalize secure AI development, software supply chain, governance, compliance, and secure coding standards with architecture, platform, delivery enablement, and risk teams.
- Mentor less senior staff, lead requirements and delivery activities, maintain security systems, support audits, and present findings and recommendations to leadership.
Requirements
- Bachelor's degree in Computer Science, Information Systems, or a closely related field is required; no substitutions are permitted.
- At least seven years of experience is required in information security and systems analysis, information security or risk management or IT, operating systems and software administration, security and risk communications, and related security technologies.
- At least seven years of experience is preferred in IT or information security risk advisory, network security architecture and protocols, database management, system administration, and software development lifecycle work.
- At least three years of experience working with HITRUST CSF or the NIST 800-83 cybersecurity framework is preferred.
- Prior software development experience and hands-on experience with CI/CD security policy enforcement, scripting or programming, container and cloud-native security, secure code reviews, and security architecture reviews are required or strongly preferred.
- Experience with GitLab Ultimate security features, JFrog Xray and Curation, SAST, DAST, SCA, container scanning, secret detection, API security testing, SBOMs, CycloneDX, SPDX, and software supply chain controls is preferred.
- Knowledge of AI security risks, AI coding assistants, AI agents, LLM integrations, MCP tooling, AI governance, OWASP Top 10 for LLM Applications, OWASP SAMM, BSIMM, NIST SSDF, and NIST AI RMF is preferred.
- Familiarity with STRIDE, PASTA, penetration testing, red team exercises, threat modeling, healthcare or financial regulatory frameworks, and security certifications such as CISSP, Security+, CSSLP, GWEB, GWAPT, or OSCP is preferred.
- Candidates must be US citizens due to contractual and access requirements.
Benefits
- Office-based position with a required physical work site.
- Travel requirement is 0%–25%.
- The role may involve occasional training and travel between work sites and physical duties including lifting up to 50 pounds.
Tech Stack
Categories
About Highmark Health
Highmark Health is a Pittsburgh-based nonprofit parent company that combines health insurance and care delivery. It operates Highmark’s Blue Cross Blue Shield plans and owns Allegheny Health Network, a regional hospital and physician system in Western Pennsylvania, plus the technology subsidiary enGen. The organization’s revenue comes from insurance premiums and healthcare services, serving commercial, Medicare, and Medicaid members across its licensed markets.