Senior Security Engineer - Secure SDLC
$102.7k - $164.6kHighmark Health
Company : enGen Job Description :
JOB SUMMARY
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.
This is a high-impact, hands-on engineering role for a security professional who is passionate about preventing vulnerabilities before they happen . You will be at the forefront of our shift-left security strategy, working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.
If you thrive at the intersection of security engineering, developer collaboration, and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.
What You'll Do
Build & Enforce Shift-Left Security Controls
- Design and implement security guardrails to catch vulnerabilities as early as possible in development (IDE, commit time, CI/CD pipelines).
- Configure and enforce enterprise-wide pipeline security gates, ensuring code meets security standards before reaching production.
- Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST) across our GitLab-based development platform.
- Develop scalable security-as-code policies and enforcement rules for a large, distributed engineering organization.
Drive Vulnerability Risk Reduction
- Lead risk-based triage and prioritization of detected vulnerabilities, using exploitability signals like EPSS scores, Known Exploited Vulnerability (KEV) status, and reachability analysis.
- Establish and track remediation SLAs based on vulnerability severity and business risk, focusing on eliminating Critical and High findings pre-production.
- Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, and developer education.
- Monitor and report on key security health metrics, including Mean Time to Remediate (MTTR), security debt trends, and pre- vs. post-production detection rates.
Automate & Optimize the Security Toolchain
- Architect and maintain the enterprise application security toolchain, ensuring proper integration, tuning, and delivery of high-fidelity, actionable signals.
- Build automation workflows for vulnerability triage, escalation, assignment, and reporting to reduce manual overhead and accelerate response times.
- Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
- Develop dashboards and reporting pipelines to provide engineering and security leadership with real-time visibility into the organization's security posture.
Enable & Empower Developers
- Serve as a trusted, embedded security advisor to engineering teams, offering hands-on guidance, code review support, and practical remediation recommendations.
- Design and deliver security training, workshops, and reference materials that make secure coding accessible and actionable for all developers.
- Build and grow a Security Champions program, embedding security advocates within engineering teams to extend the AppSec program's reach.
- Create and maintain secure coding standards, design patterns, and reusable security libraries to reduce the security burden on individual developers.
Measure, Report & Continuously Improve
- Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
- Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
- Support audit and compliance activities by ensuring security controls are documented, measurable, and consistently enforced.
- Benchmark program maturity against industry frameworks like OWASP SAMM and BSIMM, and drive year-over-year improvement.
Preferred Qualifications:
- Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, and Compliance Frameworks
- Deep proficiency with application security scanning tools — SAST, DAST, SCA/Dependency Scanning, Container Scanning, and Secret Detection
- Deep proficiency with JFrog security and compliance tools such as Xray and Curation -- Policies, Watches, Impact Analysis and Reports
- Familiarity with threat modeling methodologies such as STRIDE or PASTA
- Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, or NIST CSF
- Industry certifications such as CSSLP, GWEB, GWAPT, OSCP , or equivalent
- Prior experience as a software developer — we strongly value candidates who understand what it's like to be on the other side of a security finding
- Experience coordinating or conducting penetration testing and red team exercises
ESSENTIAL RESPONSIBILITIES
Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.
Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.
Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.
Implement, monitor, configure, and maintain security systems.
Assure compliance to required standards, procedures, guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
- Bachelor's Degree in Computer Science, Information Systems, or closely related field
Substitutions
- None
PREFERRED EDUCATION
- Master's Degree in Computer Science, Information Security or related field
EXPERIENCE
Required
7 years with Information Security and Systems Analysis
7 years with Information Security and/or Information Risk Management and/or Information Technology
7 years with Operating Systems and Software Administration
7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
Preferred:
10 years with Information Security and Systems Analysis
7 years in IT / Information Security Risk advisory
7 years in-depth understanding of network security architecture, network and networking protocols
7 in Database Management, System Administration and Software Development Life-Cycle
3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
SKILLS
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
Strong teamwork and inter-personal skills
Additional Skills:
- Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins, or equivalent
- Proficiency in at least one scripting or programming language (Python, Go, Bash, or equivalent) for security automation
- Familiarity with container and cloud-native security concepts (Docker, Kubernetes, cloud provider security services)
- Ability to conduct focused secure code reviews and analysis
- Familiarity with AI Security
- Preparing and delivering regular security posture briefings to engineering and security leadership — including trend analysis, KPI performance, and forward-looking recommendations
- Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, or equivalent) across multiple package ecosystems
- Generating, maintaining, and interpreting Software Bills of Materials in CycloneDX or SPDX formats
- Applying container security best practices — minimal base images, non-root execution, read-only filesystems, and image signing
- Designing security gates that block non-compliant code from advancing through the pipeline while minimizing developer friction (Gitlab, JFrog XRay)
LICENSES or CERTIFICATIONS
Required
- None
PREFERRED
- Certified Information Systems Security Professional (CISSP), Security +
LANGUAGE REQUIREMENT ( other than English )?
None
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
Position Type:
Office-Based
Office-Based Positions
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$102,700.00Pay Range Maximum:
$164,600.00Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on aiapply.co
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
$167.5k - $226.3k
...Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s... ...like Claude Code, Cursor, etc.).Solid experience with Secure-SDLC processes and DevSecOps, including secure design, threat...SeniorCasual workWork at officeLocal area$130k
...Senior Security Engineer New York, NY, USA; San Francisco, CA, USA About the Role We are looking for a versatile Security Software Engineer... ...testing and threat modeling Embed security into the SDLC Build automation, tooling, and guardrails Streamline vulnerability...SeniorFull timeWork at officeLocal areaRemote work$144.8k - $261.45k
...DoOwn the design and delivery of AI-driven security features, from Azure OpenAI integrations... ...across products.Guide product security engineers, developers, and product teams as a technical... ...of owning features.Command of Secure SDLC practices, application security, threat modeling...SeniorFull timeTemporary workLocal areaWorldwide- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around... ...leading the security of the software development life cycle (SDLC) from design to completion. You will work at the...SeniorFull timeWork experience placementWork at officeFlexible hours
$174k - $252k
Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.Drive... ...or threat modeling.5 years of experience with security engineering, computer and network security and security protocols.5 years...Senior$195k - $240k
Here at Datadog, we think about offensive security a little bit differently. We embrace automation... ...environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking for a Senior Security Engineer who can execute sophisticated...SeniorWork at office$165k - $242k
...in March 2025. Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing how our... ...more productive, this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls...SeniorPermanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$135k - $168k
Senior IT Security Engineer - Full Time | Hybrid A rapidly growing mid-sized financial institution is expanding its technology leadership team and strengthening its cybersecurity posture. This is a key role for an experienced security engineer who wants to design, enhance...SeniorFull timeRemote work$174k - $252k
Perform investigations on a wide variety of security and privacy events from various sources to determine whether they pose a threat... ...reviews or threat modeling.5 years of experience with security engineering, computer and network security and security protocols.5 years...Senior- ...you, you’ll fit right in.Who You AreJustworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and mature Justworks’ Security. As a Senior Detection Engineer, you’ll design, build, and maintain the detection logic that...SeniorCasual workLocal area
- ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security...SeniorWork at officeRelocation3 days per week1 day per week
$160k - $200k
...Senior Application Security Engineer New York, New York, United States The Senior Application Security Engineer plays a critical role in driving... ...enterprise SAST, DAST, and code-review tools. Champion SDLC to promote secure application development and infrastructure...Senior- Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge... .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate... ...Seoul, Germany and Paris. Join us!As a Senior Security Engineer you will:Serve as...SeniorWork at officeLocal areaRemote workHome officeFlexible hours
$168k - $270.25k
NVIDIA Security is seeking a Senior Detection Engineer to join the Detection and Automation Engineering team. On this team, we build reliable detection coverage that helps responders identify real threats quickly, reduce unnecessary noise, and protect NVIDIA's enterprise...SeniorFull timeRemote work$200k - $225k
...re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative on JLL's Falcon team, owning the product's security...SeniorFull timeLocal areaImmediate startRemote work$130k
About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security, infrastructure security, enterprise security, and security/compliance automation. This is a hands-on, high-impact role for...SeniorFull timeWork at officeLocal areaRemote work$165k - $242k
...into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .Senior Security Engineer, SOARWhat You’ll Do:CoreWeave’s Detection and Response team is responsible for empowering and deploying decisive action across...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$163.94k - $215.18k
Hi, we're Oscar. We're hiring a Senior Security Engineer 1, GRC to join our Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind...SeniorFull timeWork at officeFlexible hours$10k
...to do it.About the RoleYou'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD... ...to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers...SeniorFull timeWork at officeRemote workHome officeFlexible hours$163.94k - $215.18k
Hi, we're Oscar. We're hiring a Senior Identity and Access Manager to join our Security Team.Oscar is the first health insurance company built around a full stack... ...in the family.As an Identity and Access Management Engineer, you will build Oscar's identity and access...SeniorFull timeWork at officeFlexible hours$163.94k - $215.18k
Hi, we're Oscar. We're hiring a Senior Security AI Engineer 1 to join our Security Engineering team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create...SeniorFull timeWork at officeFlexible hours$139k - $204k
...and build the capabilities to stay left of boomWork alongside security partners who hold a high bar and expect you to raise itShape how... ...can see the fire directlyServing as a clear, credible voice to senior leadership during active incidents — translating fast-moving technical...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$164k - $242k
...Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:CoreWeave’s Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeRemote workFlexible hours- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...Senior
$128.9k - $180k
...team at your back. If Braze sounds like a place where you can thrive, we can't wait to meet you. WHAT YOU'LL DO As a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and...SeniorWork at officeLocal areaFlexible hours- A tech consulting firm is looking for a Sr. Infrastructure Security Engineer to develop and enhance security systems across AWS, GCP, and Azure. This remote role requires expertise in cloud security and automation, with responsibilities including architecting security systems...SeniorRemote job
$77k - $202k
...SectorNot ApplicableSpecialismManaged ServicesManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs an AWS Security Engineer - Senior Associate, you will play a crucial role in designing and implementing secure IT systems that support business operations,...SeniorFull timeH1b$160k - $200k
...Security Engineer At Intenseye, we believe protecting people at work is non-negotiable. That's why we're building the world's most advanced... ..., finance, and customer success. Embed security into the SDLC: define secure coding standards, introduce SAST/DAST tooling,...Senior$130k - $140k
...where and when people need it most. It’s healthcare that shows up. Who You Are You are a hands-on, deeply technical Security Engineer who designs, builds, deploys, and operates security across cloud, application, network, and physical infrastructure— not from...SeniorRemote work$135k
...areas of the company.• Ability to join a growing company with professional development opportunities.Position SummaryThe Senior Security Engineer AI Model and Application is a hands-on, systems-level role at the intersection of security engineering and artificial intelligence...SeniorFull timeTemporary workWork at officeMonday to FridayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer - Secure SDLC. Be the first to apply!
- senior cloud security engineer New York State
- aws cloud security engineer New York State
- senior application security engineer New York State
- sr information security engineer New York State
- senior lead project manager New York State
- senior robotics software engineer New York State
- senior devops engineer remote New York State
- senior network engineer remote New York State
- senior accountant controller New York State
- senior manager executive compensation New York State

