Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer - Secure SDLC

$102.7k - $164.6k
Full-time

Highmark Health

Company : enGen

Job Description :

JOB SUMMARY

Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.

This is a high-impact, hands-on engineering role for a security professional who is passionate about preventing vulnerabilities before they happen . You will be at the forefront of our shift-left security strategy, working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.

If you thrive at the intersection of security engineering, developer collaboration, and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.

What You'll Do

Build & Enforce Shift-Left Security Controls

  • Design and implement security guardrails to catch vulnerabilities as early as possible in development (IDE, commit time, CI/CD pipelines).
  • Configure and enforce enterprise-wide pipeline security gates, ensuring code meets security standards before reaching production.
  • Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST) across our GitLab-based development platform.
  • Develop scalable security-as-code policies and enforcement rules for a large, distributed engineering organization.

Drive Vulnerability Risk Reduction

  • Lead risk-based triage and prioritization of detected vulnerabilities, using exploitability signals like EPSS scores, Known Exploited Vulnerability (KEV) status, and reachability analysis.
  • Establish and track remediation SLAs based on vulnerability severity and business risk, focusing on eliminating Critical and High findings pre-production.
  • Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, and developer education.
  • Monitor and report on key security health metrics, including Mean Time to Remediate (MTTR), security debt trends, and pre- vs. post-production detection rates.

Automate & Optimize the Security Toolchain

  • Architect and maintain the enterprise application security toolchain, ensuring proper integration, tuning, and delivery of high-fidelity, actionable signals.
  • Build automation workflows for vulnerability triage, escalation, assignment, and reporting to reduce manual overhead and accelerate response times.
  • Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
  • Develop dashboards and reporting pipelines to provide engineering and security leadership with real-time visibility into the organization's security posture.

Enable & Empower Developers

  • Serve as a trusted, embedded security advisor to engineering teams, offering hands-on guidance, code review support, and practical remediation recommendations.
  • Design and deliver security training, workshops, and reference materials that make secure coding accessible and actionable for all developers.
  • Build and grow a Security Champions program, embedding security advocates within engineering teams to extend the AppSec program's reach.
  • Create and maintain secure coding standards, design patterns, and reusable security libraries to reduce the security burden on individual developers.

Measure, Report & Continuously Improve

  • Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
  • Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
  • Support audit and compliance activities by ensuring security controls are documented, measurable, and consistently enforced.
  • Benchmark program maturity against industry frameworks like OWASP SAMM and BSIMM, and drive year-over-year improvement.

Preferred Qualifications:

  • Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, and Compliance Frameworks
  • Deep proficiency with application security scanning tools — SAST, DAST, SCA/Dependency Scanning, Container Scanning, and Secret Detection
  • Deep proficiency with JFrog security and compliance tools such as Xray and Curation -- Policies, Watches, Impact Analysis and Reports
  • Familiarity with threat modeling methodologies such as STRIDE or PASTA
  • Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, or NIST CSF
  • Industry certifications such as CSSLP, GWEB, GWAPT, OSCP , or equivalent
  • Prior experience as a software developer — we strongly value candidates who understand what it's like to be on the other side of a security finding
  • Experience coordinating or conducting penetration testing and red team exercises

ESSENTIAL RESPONSIBILITIES

  • Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.

  • Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.

  • Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.

  • Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.

  • Implement, monitor, configure, and maintain security systems.

  • Assure compliance to required standards, procedures, guidelines and processes.

  • Other duties as assigned or requested.

REQUIRED EDUCATION

  • Bachelor's Degree in Computer Science, Information Systems, or closely related field

Substitutions

  • None

PREFERRED EDUCATION

  • Master's Degree in Computer Science, Information Security or related field

EXPERIENCE

Required

  • 7 years with Information Security and Systems Analysis

  • 7 years with Information Security and/or Information Risk Management and/or Information Technology

  • 7 years with Operating Systems and Software Administration

  • 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences

  • 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms

Preferred:

  • 10 years with Information Security and Systems Analysis

  • 7 years in IT / Information Security Risk advisory

  • 7 years in-depth understanding of network security architecture, network and networking protocols

  • 7 in Database Management, System Administration and Software Development Life-Cycle

  • 3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework

SKILLS

  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3

  • Familiarity with secure SDLC best practices

  • Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.

  • Strong teamwork and inter-personal skills

Additional Skills:

  • Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins, or equivalent
  • Proficiency in at least one scripting or programming language (Python, Go, Bash, or equivalent) for security automation
  • Familiarity with container and cloud-native security concepts (Docker, Kubernetes, cloud provider security services)
  • Ability to conduct focused secure code reviews and analysis
  • Familiarity with AI Security
  • Preparing and delivering regular security posture briefings to engineering and security leadership — including trend analysis, KPI performance, and forward-looking recommendations
  • Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, or equivalent) across multiple package ecosystems
  • Generating, maintaining, and interpreting Software Bills of Materials in CycloneDX or SPDX formats
  • Applying container security best practices — minimal base images, non-root execution, read-only filesystems, and image signing
  • Designing security gates that block non-compliant code from advancing through the pipeline while minimizing developer friction (Gitlab, JFrog XRay)

LICENSES or CERTIFICATIONS

Required

  • None

PREFERRED

  • Certified Information Systems Security Professional (CISSP), Security +

LANGUAGE REQUIREMENT ( other than English )?
None

TRAVEL REQUIREMENT:

0% - 25%

PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS

Position Type:

Office-Based

Office-Based Positions

Teaches/Trains others regularly

Occasionally

Travels regularly from the office to various work sites or from site-to-site

Occasionally

Works primarily out-of-the office selling products/services (Sales employees)

Does Not Apply

Physical Work Site Required

Yes

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies

As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.

Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Pay Range Minimum:

$102,700.00

Pay Range Maximum:

$164,600.00

Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.

For accommodation requests, please contact HR Services Online at View email address on aiapply.co

California Consumer Privacy Act Employees, Contractors, and Applicants Notice

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer - Secure SDLC in Connecticut vacancy
  • $105.4k - $207.8k

    Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative... 
    Senior
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Stamford, CT
    3 days ago
  • $105.4k - $207.8k

    Position Summary Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and... 
    Senior
    Work experience placement
    Local area

    Deloitte

    Stamford, CT
    1 day ago
  •  ...Booking Holdings, the parent company of Booking.com, Priceline, Agoda, Kayak and OpenTable, seeks a Global Sr Enterprise Security Architect (Director level) in Norwalk, CT. This hybrid role combines strategic vision with hands-on architectural leadership across cloud,... 
    Senior

    Jobleads-US

    Norwalk, CT
    2 days ago
  • $128.4k - $192.6k

    Senior Security Engineer - IS07FEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too.... 
    Senior
    Full time
    Temporary work
    Work at office
    3 days per week

    The Hartford Financial Services Group

    Hartford, CT
    9 hours ago
  • $218.7k - $267.3k

     ...office.The Global Sr Enterprise Security Architect (Director level) is...  ...Holdings brands. This Senior role is an individual contributor...  ...security by design principles into engineering, product, and AI development...  ...architectures, and Secure SDLC. Experience with AI-driven... 
    Senior
    Full time
    Work at office
    Local area
    Immediate start

    BOOKING HOLDINGS

    Norwalk, CT
    1 day ago
  • We are looking for experienced Network Security professionals to join the Crane Co. Global Information Security Team in supporting our...  ...training activities with other Business Unit network/systems Engineers and IT support teamsWork closely with business and technology... 
    Full time
    Work experience placement
    Remote work

    Crane

    Stamford, CT
    3 days ago
  • Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting the company’s global information security program through exploitative testing for context-based risk analysis. The ideal candidate... 
    Full time
    Work experience placement
    Local area
    Remote work

    Crane

    Stamford, CT
    1 day ago
  • $122.6k - $186.8k

    Meet Our Team:Cloud Security Engineering (CSE) is responsible for protecting Pega’s cloud infrastructure, applications, and data across AWS and GCP environments. The team partners closely with Cloud Operations, Service Reliability, and Engineering to ensure our environments... 
    Flexible hours

    Pegasystems

    Connecticut
    1 day ago
  • $100 per hour

     ...large enterprises. Design, implement, and manage advanced security controls, protect critical systems, and respond to complex...  ...team? Apply now. Responsibilities: Work as a hands-on Senior Security Engineer / Security Architect to support the implementation of key... 
    Senior
    Hourly pay
    Contract work
    Remote work
    East Hartford, CT
    more than 2 months ago
  •  ...of state-of-the-art technologies that are integral to national security and defense. As part of our ongoing commitment to advancing mission...  ...complex digital landscape.THE WORKAs a Cyber Systems Security Engineer Sr, you will support the integration of modern cybersecurity... 
    Senior
    Part time
    Work at office
    Remote work
    Worldwide
    Flexible hours

    Lockheed Martin

    Stratford, CT
    1 day ago
  •  ...Job Description Job Description Job Title: Security Engineer II Location: Milford, DE Type: Direct Hire Job Summary: System One is seeking a Security Engineer II for a permanent opportunity in Milford, DE. The Security Engineer will work Technology Services to... 
    Permanent employment
    Local area
    Night shift
    Weekend work

    System One

    Milford, CT
    a month ago
  • $82.6k - $162.8k

     ...with confidence, and proactively manage to secure success. Identity security market is...  ...on 12/31/2026.Work you'll doAs a Security Engineer II on the Deloitte Cyber Identity & Access...  ...development From entry-level employees to senior leaders, we believe there’s always room... 
    Local area
    Visa sponsorship

    Deloitte

    Hartford, CT
    5 days ago
  •  ...of their portfolio allocation. Position Summary: Grayscale Investments is seeking a Senior AI Security Architect to partner with our AI Enablement squad and broader engineering organization to ensure the safe, controlled adoption of AI across the firm. You will... 
    Senior
    Full time
    Work experience placement

    Grayscale

    Stamford, CT
    a month ago
  • $103.1k - $171.9k

    Join a high-impact team driving the future of secure healthcare technology. As an Information Protection...  ...pipelines. You will partner closely with engineering teams to integrate security into every stage of the SDLC, helping protect critical applications while accelerating... 
    Full time
    Local area
    Work from home

    CIGNA

    Bloomfield, CT
    9 hours ago
  • $71.6k - $119.4k

     ...looking to work for a mission driven global organization?About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and... 
    Full time
    Local area
    Work from home

    RELX Group

    Connecticut
    1 day ago
  • $82.6k - $162.8k

     ...with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be...  ...development From entry-level employees to senior leaders, we believe there’s always room... 
    Local area
    Visa sponsorship

    Deloitte

    Hartford, CT
    1 day ago
  • $68k - $133.9k

    Position Summary Oracle Identity Analyst / Security Engineer I As an Oracle Identity Analyst, you’ll work with client and Deloitte teams...  ...Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities... 
    Local area
    Visa sponsorship

    Deloitte

    Hartford, CT
    9 hours ago
  • $130k - $160k

     ...offers the chance to take real ownership of an organization’s security posture and guide how it continues to evolve. The environment is...  ...Hybrid Salary - $130,000 - 160,000 +BonusYou will work closely with senior leadership, drive priorities, lead the MSP, and represent the... 
    Senior

    Smith Arnold Partners

    Danbury, CT
    9 hours ago
  • $134.5k - $265.1k

     ...confidence, and proactively manage their security posture.Recruiting for this role ends on...  ...you will do:As a Cyber Forward Deployed Engineer (FDE) Manager, you will lead delivery of...  ...goals.5+ Years experience working with senior client stakeholders to translate requirements... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Hartford, CT
    3 days ago
  •  ...automation, and intelligent insights. The RolePresidio is seeking Network and Security Practice Leads, in Boston MA. These individuals will be hands-on leaders, providing technical oversight for an engineering team throughout their services execution, ensuring engineers are... 
    Full time
    For contractors
    Local area

    Presidio

    Glastonbury, CT
    1 day ago
  •  ...innovative environment. Collaborate with top-tier professionals to enhance security measures. Advance your career in a role emphasizing cutting-edge technologies.Job DescriptionCyber Security Engineer OverviewThe Cyber Security Engineer will implement and maintain security... 

    Green Key Resources

    Stamford, CT
    3 days ago
  • $110.3k - $204.9k

     ...advanced electronics to undermine our way of life. As a cyber security professional at Lockheed Martin, you’ll protect the networks...  ...they can support our mission.THE WORKAs a Cyber RF Software Engineer Senior Staff, my typical day is filled with excitement and energy as... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Casual work
    Flexible hours

    Lockheed Martin

    Hanover, CT
    1 day ago
  • $135.7k - $251.9k

     ...advanced electronics to undermine our way of life. As a cyber security professional at Lockheed Martin, you’ll protect the networks that...  ..., so they can support our mission.THE WORKAs a Cyber Systems Engineer Staff you will:• Engage with members of the PMO to provide schedule... 
    Full time
    Temporary work
    Work experience placement
    Casual work
    Relocation package
    Flexible hours

    Lockheed Martin

    Hanover, CT
    1 day ago
  • $165k - $180k

     ...The Enterprise Platform Architect is a senior technical and strategic leader. They provide...  .... Their work ensures that solutions are secure, scalable, and reusable across the...  ..., adoption, and risk. Partner with engineering and operations teams to embed technical... 
    Permanent employment
    Temporary work
    Local area
    Flexible hours

    Openkyber

    Connecticut
    3 days ago
  •  ...Application Security Engineer Hybrid in Houston, TX (TX state candidate only) Must have LinkedIn Need 15+ years profiles Looking for an application security engineer doing software development using Java/script and has expertise in coding in Python.... 

    Openkyber

    Connecticut
    3 days ago
  •  ...Position: Physical Security Systems Engineer Location: Columbus -OH(Onsite) Deep hands-on experience with at least one enterprise PACS on your shortlist (Genetec, LenelS2 OnGuard, C CURE 9000, or Pro-Watch), ideally certified (e.g., Genetec SC-OMN/SYN, Lenel Certified... 

    Openkyber

    Connecticut
    3 days ago
  •  ...application allowlisting solutions across Windows and Linux environments. This consultant will play a key role in strengthening endpoint security by implementing application control technologies, reducing the attack surface, and collaborating with cross-functional IT and... 
    Permanent employment
    Contract work
    Temporary work
    Remote work

    Openkyber

    Connecticut
    3 days ago
  •  ...Role Title: Senior .NET Architect Application Security Employment Type: Contract Preferred Location: Remote working CST time zone Lead upgrade and remediation efforts for .NET Framework applications, with emphasis on RESTful services and web services... 
    Contract work
    Remote work

    Openkyber

    Connecticut
    3 days ago
  •  ...Build declarative solutions utilizing Salesforce automation tools, primarily advanced Flows, custom objects, validation rules, and security controls. Maintenance & Troubleshooting: Debug, troubleshoot, and resolve complex software errors, application bottlenecks,... 
    Local area

    Openkyber

    Connecticut
    3 days ago
  • $120k - $202.5k

    Who We Are Looking For We are seeking a Senior Security Testing Delivery Lead to help drive the execution, coordination, and operational management of State Street’s regulatory security testing and assurance activities. This role is ideal for a strong technical program... 
    Senior
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Stamford, CT
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer - Secure SDLC. Be the first to apply!