Senior Security Engineer II Application Security
Washington DC, WA - USA
Job Summary
- Working cross functionally to design build and operate solutions that continuously improve and automate our security capabilities
- Leveraging data to understand trends metrics and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
- Leading and enhancing incident / issues response efforts spearheading analysis containment and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues
- Helping craft and refine security documentation pertinent to our Security Program such as policies standards baselines and standard operating procedures
- Mentoring and coaching more junior engineers or analysts
- BS/BTech (or higher) in Computer Science Information Technology Cybersecurity or a related field 10 years security domain experience without degree
- 6 years of experience in securing and deploying applications within Cloud Native environments
- 3 years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes
- Knowledge of health-tech systems like Electronic Health Records Clinical data PHI etc direct experience preferred.
- Experience architecting developing and deploying large-scale distributed systems at scale.
- Extensive experience identifying evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools.
- Proven experience conducting code reviews and threat modeling.
- Extensive experience with developing automated security testing and validation systems using Terraform Cloudformation Python etc.
- Proficient in coding languages such as Python R C Javascript.
- Extensive experience working in AWS/Azure/GCP software development environment..
- Proven experience with implementing security controls for web-based SaaS applications such as API Security WAF etc.
- In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them.
- In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices.
- Strong familiarity with server-side web technologies (eg: Java Python Scala C# C Go).
- 4 years of experience acting as a trusted technical decision-maker in a team setting solving for short-term and long-term business value
- Experience with health-tech systems like Electronic Health Records Clinical data etc preferred.
- Must be able to sit for prolonged periods of time
Required Experience:
Senior IC
About Company
Who We Are: Aledade PBC, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helpi ... View more