Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer - Secure SDLC

$102.7k - $164.6k
Full-time

Highmark Health

Company : enGen

Job Description :

JOB SUMMARY

***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***

Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.

This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.

If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.

Build & Enforce Shift-Left Security Controls

  • Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.
  • Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards.
  • Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform.
  • Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization.
  • Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.

Drive Vulnerability Risk Reduction

  • Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.
  • Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production.
  • Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.
  • Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.
  • Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.

Automate & Optimize the Security Toolchain

  • Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal.
  • Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains.
  • Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times.
  • Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
  • Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance.
  • Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.

Enable & Empower Developers

  • Serve as a trusted, embedded security advisor to engineering teams, providing hands-on guidance, code review support, AI security consultation, and practical remediation recommendations.
  • Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels.
  • Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.
  • Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams.
  • Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications.
  • Partner with development, architecture, and platform teams to embed secure-by-default AI development practices throughout the SDLC.

Measure, Report & Continuously Improve

  • Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
  • Establish and report on AI security metrics such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings.
  • Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
  • Support audit, risk, and compliance activities by ensuring security controls, AI governance requirements , and secure development standards are documented, measurable, and consistently enforced.
  • Benchmark program maturity against industry frameworks such as OWASP SAMM, BSIMM, OWASP Top 10 for LLM Applications , and emerging AI security best practices, driving year-over-year improvement.
  • Continuously assess emerging threats, vulnerabilities, and attack techniques affecting modern software delivery pipelines, software supply chains, and AI-enabled applications.

Assist in AI Application Security & Governance

  • Assist with security reviews and threat modeling for AI-enabled applications, LLM integrations, AI agents, and AI-assisted development platforms.
  • Collaborate with Security Architecture to recommend and establish technical controls and guardrails supporting enterprise AI governance requirements.
  • Evaluate security risks associated with AI models, prompts, training data, model supply chains, MCP integrations, and agentic workflows.
  • Partner with Architecture, ISRM, and Software Delivery Enablement teams to define secure AI development standards and implementation patterns across the enterprise.

Preferred Qualifications

  • Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, Compliance Frameworks, and security controls supporting AI-assisted development workflows.
  • Deep proficiency with application security scanning tools including SAST, DAST, SCA/Dependency Scanning, Container Scanning, Secret Detection, API Security Testing , and emerging AI application security assessment capabilities.
  • Deep proficiency with JFrog security and compliance tools such as Xray and Curation , including Policies, Watches, Impact Analysis, Software Supply Chain controls, and reporting.
  • Familiarity with threat modeling methodologies such as STRIDE, PASTA , and their application to AI-enabled systems, LLM integrations, and agentic workflows.
  • Working knowledge of common AI security risks including prompt injection, insecure output handling, excessive agency, retrieval risks, model poisoning, training data exposure, sensitive data leakage, and model supply chain threats.
  • Experience designing or reviewing security controls for AI-enabled applications, AI assistants, AI agents, or LLM integrations.
  • Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, NIST CSF, NIST AI RMF , or equivalent governance frameworks.
  • Industry certifications such as CSSLP, GWEB, GWAPT, OSCP, AI Security certifications , or equivalent.
  • Prior experience as a software developer. We strongly value candidates who understand what it's like to be on the other side of a security finding and can balance security, delivery, and developer experience.
  • Experience coordinating or conducting penetration testing, red team exercises, AI security assessments, and application threat modeling engagements.
  • Experience establishing security controls and governance requirements for AI-assisted software development platforms (e.g., GitLab Duo, GitHub Copilot, Claude Code, Cursor, MCP-based tooling, or equivalent) within a large enterprise environment.

ESSENTIAL RESPONSIBILITIES

  • Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.

  • Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.

  • Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.

  • Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.

  • Implement, monitor, configure, and maintain security systems.

  • Assure compliance to required standards, procedures, guidelines and processes.

  • Other duties as assigned or requested.

REQUIRED EDUCATION

  • Bachelor's Degree in Computer Science, Information Systems, or closely related field

Substitutions

  • None

PREFERRED EDUCATION

  • Master's Degree in Computer Science, Information Security or related field

EXPERIENCE

Required

  • 7 years with Information Security and Systems Analysis

  • 7 years with Information Security and/or Information Risk Management and/or Information Technology

  • 7 years with Operating Systems and Software Administration

  • 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences

  • 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms

Preferred:

  • 10 years with Information Security and Systems Analysis

  • 7 years in IT / Information Security Risk advisory

  • 7 years in-depth understanding of network security architecture, network and networking protocols

  • 7 in Database Management, System Administration and Software Development Life-Cycle

  • 3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework

SKILLS

  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3

  • Familiarity with secure SDLC best practices

  • Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.

  • Strong teamwork and inter-personal skills

Additional Skills:

  • Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins , or equivalent, including security policy enforcement and pipeline governance.

  • Proficiency in at least one scripting or programming language ( Python, Go, Bash , or equivalent) for security automation, workflow development, and security tooling integrations.
  • Familiarity with container and cloud-native security concepts including Docker, Kubernetes, cloud provider security services , and modern platform engineering practices.
  • Ability to conduct focused secure code reviews and security architecture reviews across both human-authored and AI-generated code.
  • Experience evaluating security implications of AI coding assistants, AI agents, MCP-enabled tooling, and AI-powered developer platforms.
  • Understanding of secure AI development principles, including governance controls for AI-generated code, model consumption, prompt handling, data protection, and human review requirements.
  • Preparing and delivering regular security posture briefings to engineering and security leadership, including trend analysis, KPI performance, risk summaries, AI security metrics, and forward-looking recommendations.
  • Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, JFrog Xray, or equivalent) across multiple package ecosystems.
  • Generating, maintaining, and interpreting Software Bills of Materials (SBOMs) in CycloneDX or SPDX formats.
  • Applying container security best practices including minimal base images, non-root execution, read-only filesystems, image signing, and software supply chain verification.
  • Designing security gates that prevent non-compliant code, dependencies, containers, or deployment artifacts from advancing through the pipeline while minimizing developer friction (GitLab, JFrog Xray, or equivalent).
  • Experience implementing or supporting software supply chain security controls including artifact governance, package repository management, dependency trust validation, and build integrity protections.
  • Knowledge of industry frameworks and guidance related to AI and application security, including OWASP Top 10 for LLM Applications, OWASP SAMM, BSIMM, NIST Secure Software Development Framework (SSDF), and NIST AI Risk Management Framework (AI RMF) .
  • Ability to partner with Architecture, Software Delivery Enablement, Engineering, and Risk Management teams to define and operationalize secure AI development standards and guardrails.

LICENSES or CERTIFICATIONS

Required

  • None

PREFERRED

  • Certified Information Systems Security Professional (CISSP), Security +

LANGUAGE REQUIREMENT ( other than English )?
None

TRAVEL REQUIREMENT:

0% - 25%

PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS

Position Type:

Office-Based

Office-Based Positions

Teaches/Trains others regularly

Occasionally

Travels regularly from the office to various work sites or from site-to-site

Occasionally

Works primarily out-of-the office selling products/services (Sales employees)

Does Not Apply

Physical Work Site Required

Yes

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies

As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.

Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Pay Range Minimum:

$102,700.00

Pay Range Maximum:

$164,600.00

Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.

California Consumer Privacy Act Employees, Contractors, and Applicants Notice

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer - Secure SDLC in New York State vacancy
  • $167.5k - $226.3k

     ...Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s...  ...like Claude Code, Cursor, etc.).Solid experience with Secure-SDLC processes and DevSecOps, including secure design, threat... 
    Senior
    Casual work
    Work at office
    Local area

    Justworks

    New York, NY
    4 days ago
  • $180k - $215k

     ...The Senior Security Engineer, AI Security is a hands-on technical expert responsible for designing, implementing, and continuously enhancing the...  ...AI security operations at scale. ~ Knowledge of Secure SDLC, OWASP Top 10, API Security, software supply chain security,... 
    Senior
    Visa sponsorship
    Work visa

    Simpson Thacher and Bartlett LLP

    New York, NY
    2 days ago
  •  ...Position: Senior Security Engineer - Application Security Location: New York City, NY (HYBRID: 4 days a week in office) Duration: DIRECT...  ...security controls throughout the Software Development Lifecycle (SDLC). Partner with engineering teams to incorporate security... 
    Senior
    Full time
    Work at office

    STEPS Talent

    New York, NY
    4 days ago
  •  ...Rippling is seeking a hands-on senior security engineer to drive Rippling's Product Security program. As an early member of the security team, you...  ...to mitigate vulnerabilities and embed security into the SDLC. You will collaborate with Engineering to implement scalable... 
    Senior

    Rippling

    New York, NY
    4 days ago
  • $225k - $300k

    CLEAR is building THE secure identity company of the future. Our mission is to make...  ...experiences.We are seeking a Senior Product Security Engineer to serve as a technical leader and strategic...  ...in secure application design, SDLC integration, and offensive security (... 
    Senior
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    2 days ago
  • $150k - $160k

     ...most high-tech companies in the market. About the role: The Senior Security Engineer (AWS) is a senior individual contributor responsible for supporting...  ...Contribute to secure Software Development Lifecycle (SDLC) practices, including shift-left security efforts Participate... 
    Senior
    Remote work
    Flexible hours
    Shift work

    Pacvue

    New York, NY
    5 days ago
  •  ...Services firm in search for an Application Security professional to join their team....  ...into the software development lifecycle (SDLC), creating and maintaining models to anticipate...  ..., Information Management, Computer Engineering, Cybersecurity or equivalent Certifications... 
    Senior
    Full time
    Visa sponsorship

    Lawrence Harvey

    New York, NY
    1 day ago
  •  ...ownership. Learn more at li.me. Lime is seeking an experienced Senior Security Engineer to join our Product Security team. In this role, you'll be...  ...Android) and API security Secure development practices and SDLC security integration (SAST, DAST, SCA, secrets management)... 
    Senior
    Local area
    Remote work
    Shift work

    Lime

    New York, NY
    6 days ago
  • $174k - $252k

    Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.Drive...  ...or threat modeling.5 years of experience with security engineering, computer and network security and security protocols.5 years... 
    Senior

    Google

    New York, NY
    4 days ago
  • $218.4k - $365.2k

     ...Salesforce.We are seeking a transformative security leader who can evolve Slack's...  ...autonomous agents are first-class actors. As Senior Director of Security Engineering, you will lead a globally...  ...infrastructure at machine speedTransform the SDLC security model — Evolve from gate-... 
    Senior
    Full time
    Shift work

    Salesforce

    New York, NY
    4 days ago
  • $165k - $242k

     ...in March 2025. Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing how our...  ...more productive, this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls... 
    Senior
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $152.5k - $205k

     ...encouraged and everyone is a stakeholder.What you'll be responsible for:Circle is seeking a hands-on and technically sharp Senior Security Engineer, Executive & Endpoint Security to contribute to Circle’s security program while serving as the primary on-site technical... 
    Senior
    Contract work
    Work at office
    Local area
    Remote work
    Flexible hours

    Circle

    New York, NY
    5 days ago
  •  ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security... 
    Senior
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    1 day ago
  •  ...you, you’ll fit right in.Who You AreJustworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and mature Justworks’ Security. As a Senior Detection Engineer, you’ll design, build, and maintain the detection logic that... 
    Senior
    Casual work
    Local area

    Justworks

    New York, NY
    5 days ago
  •  ...official communication will only be sent from @Rippling.com addresses.About The RoleWe are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Rippling's security program forward. This role offers the opportunity to... 
    Senior
    Full time
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    5 days ago
  • $78.8k - $131.3k

    Are you a collaborative Sec Ops Engineer looking to work for a mission driven global organization...  ...?About our TeamYou’ll be joining the Security Engineering team within Elsevier’s...  ...across our cloud estate.About the RoleAs a Senior Security Engineer, you help lead in... 
    Senior
    Full time
    Local area
    Work from home

    Elsevier

    New York, NY
    5 days ago
  • $182k - $228k

     ...Ireland. Come join us! About the Role We're looking for a Senior Product Security Engineer to lead the design and implementation of secure, scalable,...  ...cloud security engineering. Deep understanding of secure SDLC, threat modeling, and secure architecture design. Ability... 
    Senior
    Local area

    AlphaSense, Inc.

    New York, NY
    4 days ago
  • $260k - $310k

    Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge...  .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate...  ..., Paris, Berlin and Seoul. Join us!As a Senior Security Engineer you will:Serve as... 
    Senior
    Work at office
    Local area
    Remote work
    Home office
    Flexible hours

    Cohere

    New York, NY
    4 days ago
  • $10k

     ...to do it.About the RoleYou'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD...  ...to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers... 
    Senior
    Full time
    Work at office
    Remote work
    Home office
    Flexible hours

    Ramp

    New York, NY
    5 days ago
  • $175k - $200k

     ...Doppel is building the future of social engineering defense. Our AI-native platform uses agentic...  ..., Human Risk Management and Email Security, Doppel connects threats into a real-time...  ...Strengthen security controls throughout the SDLC and CI/CD pipeline, including code and... 
    Senior
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Doppel

    New York, NY
    4 days ago
  •  ...Cybersecurity to lead penetration testing engagements. You will identify vulnerabilities and collaborate on remediation efforts, ensuring the security of critical banking applications. The ideal candidate has over 5 years of experience in offensive security, with expertise in... 
    Senior

    J.P. Morgan

    New York, NY
    4 days ago
  • $146k - $172k

     ...with high standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission is to...  ...behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Senior
    Work at office
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    4 days ago
  • $180k - $220k

     ...thrive in a collaborative, fast-moving environment where trust and impact matter, you’ll feel at home here.About the RoleAs a Senior Security Engineer, Detection and Response you will develop, scale, and evolve Aircall's threat detection and response capabilities. You will... 
    Senior
    Full time
    Worldwide

    Aircall

    New York, NY
    3 days ago
  • $134k - $179k

     ...) in March 2025. Learn more at .What You’ll DoOn this team, you will:Design cutting-edge detection strategies at scales most security engineers only dream aboutCollaborate with talented peers in an innovative environment focused on excellenceEnjoy the autonomy and encouragement... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    New York, NY
    5 days ago
  • $139k - $204k

     ...and build the capabilities to stay left of boomWork alongside security partners who hold a high bar and expect you to raise itShape how...  ...can see the fire directlyServing as a clear, credible voice to senior leadership during active incidents — translating fast-moving technical... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    New York, NY
    3 days ago
  • $175k - $220k

    Location: New York City or San Francisco - 4 days in officeAbout the RoleWe are looking for a highly technical Senior Security Engineer who thrives on building security capabilities from the ground up. This role is ideal for someone who enjoys solving complex security... 
    Senior
    Full time
    Work at office

    Sigma Computing

    New York, NY
    4 days ago
  • $163.94k - $215.18k

    Hi, we're Oscar. We're hiring a Senior Security AI Engineer 1 to join our Security Engineering team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create... 
    Senior
    Full time
    Work at office
    Flexible hours

    Oscar Health Insurance

    New York, NY
    2 days ago
  • $164k - $242k

     ...Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:CoreWeave’s Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect... 
    Senior
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    2 days ago
  • The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software... 
    Senior

    The Estée Lauder Companies Inc.

    New York, NY
    5 days ago
  •  ...Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration, and cloud security...  ...partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat... 
    Senior

    Estée Lauder Companies

    New York, NY
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer - Secure SDLC. Be the first to apply!