7 days ago
Remote, United StatesStaff+

Base Salary

$172k - $258k/yr

Responsibilities

  • Build, lead, and mature an application security and DevSecOps program spanning secure SDLC, SAST, DAST, SCA, container and cloud-native security, and API security.
  • Perform secure code reviews, threat modeling, security architecture reviews, critical vulnerability triage, and hands-on remediation guidance.
  • Mentor and develop application security engineers and embedded security champions.
  • Design, implement, tune, and troubleshoot the AppSec toolchain and integrate security gates into CI/CD pipelines.
  • Own vulnerability management, including triage, prioritization, remediation SLAs, escalations, and high-severity response.
  • Partner with engineering, product, and architecture teams to embed security requirements and threat modeling into product design.
  • Develop application security policies, secure coding standards, DevSecOps playbooks, and engineering training.
  • Manage third-party and open-source software risk and vulnerable dependency remediation.
  • Report application security risk posture, program metrics, and remediation trends to executive leadership.
  • Participate in application-level security incident response, root cause analysis, and remediation planning.

Requirements

  • 8+ years of experience in application security, secure software development, or DevSecOps, including hands-on engineering or security engineering work.
  • 3+ years in a leadership or technical lead capacity with the ability to remain hands-on while managing or mentoring a team.
  • Relevant certification preferred, such as CSSLP, OSCP, GWAPT, or CISSP.
  • Familiarity with OWASP ASVS, OWASP Top 10, and NIST SSDF.
  • Hands-on experience configuring, tuning, and troubleshooting SAST, DAST, and SCA tools such as Checkmarx, Veracode, Snyk, Semgrep, and Fortify.
  • Working proficiency in one or more programming languages, including Java, Python, JavaScript/TypeScript, Go, or C#.
  • Experience integrating security into CI/CD pipelines and DevOps toolchains such as Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.
  • Experience with cloud security and container/orchestration security using platforms and tools such as AWS, Azure, GCP, Docker, or Kubernetes.
  • Experience conducting threat modeling, including STRIDE, and security architecture reviews.
  • Experience building and scaling vulnerability management programs with remediation SLAs and executive reporting.
  • Strong communication, presentation, analytical, and critical-thinking skills, including the ability to translate technical risk for non-technical stakeholders.
  • Ability to work independently, lead a highly skilled AppSec team, remain a credible technical practitioner, prioritize under pressure, and meet deadlines.

Benefits

  • Remote position limited to candidates residing and authorized to work in the United States, with travel and onsite work at client, temporary, or corporate offices as business needs require.
  • Comprehensive benefits supporting physical, emotional, and financial health, including healthcare, time off, retirement, and well-being programs.
  • Professional development investment, including a relevant professional certification for each associate and tuition reimbursement.
  • Quarterly and annual incentive programs for employees.
  • Collaborative culture focused on growth, innovation, flexibility, and work-life balance.
Ensemble Health Partners

About Ensemble Health Partners

5,001-10,000 employees
Contact me