Senior Security Engineer - Secure SDLC
$102.7k - $164.6kHighmark Health
Company : enGen Job Description :
JOB SUMMARY
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.
This is a high-impact, hands-on engineering role for a security professional who is passionate about preventing vulnerabilities before they happen . You will be at the forefront of our shift-left security strategy, working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.
If you thrive at the intersection of security engineering, developer collaboration, and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.
What You'll Do
Build & Enforce Shift-Left Security Controls
- Design and implement security guardrails to catch vulnerabilities as early as possible in development (IDE, commit time, CI/CD pipelines).
- Configure and enforce enterprise-wide pipeline security gates, ensuring code meets security standards before reaching production.
- Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST) across our GitLab-based development platform.
- Develop scalable security-as-code policies and enforcement rules for a large, distributed engineering organization.
Drive Vulnerability Risk Reduction
- Lead risk-based triage and prioritization of detected vulnerabilities, using exploitability signals like EPSS scores, Known Exploited Vulnerability (KEV) status, and reachability analysis.
- Establish and track remediation SLAs based on vulnerability severity and business risk, focusing on eliminating Critical and High findings pre-production.
- Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, and developer education.
- Monitor and report on key security health metrics, including Mean Time to Remediate (MTTR), security debt trends, and pre- vs. post-production detection rates.
Automate & Optimize the Security Toolchain
- Architect and maintain the enterprise application security toolchain, ensuring proper integration, tuning, and delivery of high-fidelity, actionable signals.
- Build automation workflows for vulnerability triage, escalation, assignment, and reporting to reduce manual overhead and accelerate response times.
- Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
- Develop dashboards and reporting pipelines to provide engineering and security leadership with real-time visibility into the organization's security posture.
Enable & Empower Developers
- Serve as a trusted, embedded security advisor to engineering teams, offering hands-on guidance, code review support, and practical remediation recommendations.
- Design and deliver security training, workshops, and reference materials that make secure coding accessible and actionable for all developers.
- Build and grow a Security Champions program, embedding security advocates within engineering teams to extend the AppSec program's reach.
- Create and maintain secure coding standards, design patterns, and reusable security libraries to reduce the security burden on individual developers.
Measure, Report & Continuously Improve
- Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
- Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
- Support audit and compliance activities by ensuring security controls are documented, measurable, and consistently enforced.
- Benchmark program maturity against industry frameworks like OWASP SAMM and BSIMM, and drive year-over-year improvement.
Preferred Qualifications:
- Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, and Compliance Frameworks
- Deep proficiency with application security scanning tools — SAST, DAST, SCA/Dependency Scanning, Container Scanning, and Secret Detection
- Deep proficiency with JFrog security and compliance tools such as Xray and Curation -- Policies, Watches, Impact Analysis and Reports
- Familiarity with threat modeling methodologies such as STRIDE or PASTA
- Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, or NIST CSF
- Industry certifications such as CSSLP, GWEB, GWAPT, OSCP , or equivalent
- Prior experience as a software developer — we strongly value candidates who understand what it's like to be on the other side of a security finding
- Experience coordinating or conducting penetration testing and red team exercises
ESSENTIAL RESPONSIBILITIES
Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.
Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.
Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.
Implement, monitor, configure, and maintain security systems.
Assure compliance to required standards, procedures, guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
- Bachelor's Degree in Computer Science, Information Systems, or closely related field
Substitutions
- None
PREFERRED EDUCATION
- Master's Degree in Computer Science, Information Security or related field
EXPERIENCE
Required
7 years with Information Security and Systems Analysis
7 years with Information Security and/or Information Risk Management and/or Information Technology
7 years with Operating Systems and Software Administration
7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
Preferred:
10 years with Information Security and Systems Analysis
7 years in IT / Information Security Risk advisory
7 years in-depth understanding of network security architecture, network and networking protocols
7 in Database Management, System Administration and Software Development Life-Cycle
3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
SKILLS
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
Strong teamwork and inter-personal skills
Additional Skills:
- Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins, or equivalent
- Proficiency in at least one scripting or programming language (Python, Go, Bash, or equivalent) for security automation
- Familiarity with container and cloud-native security concepts (Docker, Kubernetes, cloud provider security services)
- Ability to conduct focused secure code reviews and analysis
- Familiarity with AI Security
- Preparing and delivering regular security posture briefings to engineering and security leadership — including trend analysis, KPI performance, and forward-looking recommendations
- Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, or equivalent) across multiple package ecosystems
- Generating, maintaining, and interpreting Software Bills of Materials in CycloneDX or SPDX formats
- Applying container security best practices — minimal base images, non-root execution, read-only filesystems, and image signing
- Designing security gates that block non-compliant code from advancing through the pipeline while minimizing developer friction (Gitlab, JFrog XRay)
LICENSES or CERTIFICATIONS
Required
- None
PREFERRED
- Certified Information Systems Security Professional (CISSP), Security +
LANGUAGE REQUIREMENT ( other than English )?
None
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
Position Type:
Office-Based
Office-Based Positions
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$102,700.00Pay Range Maximum:
$164,600.00Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on aiapply.co
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
- Job TitleLocation: Alpharetta, GA; Charlotte, NC; Chicago, IL; Colorado Springs, CO; Conshohocken, PA; Dallas, TX; Denver, CO; Fargo, ND; Garden City, NY; Houston, TX; Jacksonville, IL; Lenexa, KS; Los Angeles, CA; Lubbock, TX; Morristown, NJ; Mt Juliet, TN; New York, ...Senior
- ...operations, assisting with execution of directed cyber actions under senior guidance. - Perform basic containment activities, including... ...of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating issues...SuggestedMinimum wageContract workTemporary workWork experience placementRemote work
- ...implementing, and supporting tailored IT solutions that help customers achieve their business goals. This opportunity is for a Cyber Security Engineer with expertise in Identity and Access Management (IAM) to join a growing cybersecurity practice. The role involves designing,...SeniorFull time
- ..., compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring... ...any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual...SuggestedMinimum wageContract workTemporary workWork experience placementRemote work
- ...Sie bringen mehrjährige Erfahrung in der Beratung von Cloud-Lösungen mit und haben Kenntnisse in Bereichen wie Migration, Data & AI oder Security. Flexibilität im Arbeitsmodell sowie zahlreiche Vorteile, darunter 30 Urlaubstage, sind geboten. #J-18808-Ljbffr SkaylinkSenior
- ...job description- Senior Data Ops Engineer Location-Remote Role Overview: We are looking for a Senior Data Ops Engineer to manage, automate,... ...skills. Good understanding of data quality, governance, security, and operational best practices. For applications and...Remote work
- ..., California. This Long-term Contract position will focus on cloud services, infrastructure reliability, endpoint management, and security operations while supporting business-critical systems across the organization. The ideal candidate brings deep technical expertise...Long term contractPermanent employmentContract workTemporary workRemote work
- ...Position Summary: Under the direction of the IT Compliance and Risk Manager, this position serves as a Security Awareness and Compliance Analyst within the Enterprise Information Security Office (EISO), supporting the Commonwealth's Governance, Risk, and Compliance (GRC...Work at officeLocal area
$85k - $130k
...System which makes everything possible.The Senior Project Manager - Digital / IT is... ...degree in Information Systems, Business, Engineering, or a related discipline.Project management... ...experience in the use of project management and SDLC methodologies and tools Demonstrated...SeniorHourly payFull time$100 - $130 per hour
...$130.00 USD Hourly Description: Serve as the technical cloud security leader for enterprise-wide patching and vulnerability management... ...platforms. Partner closely with infrastructure, platform engineering, and security teams to strengthen the organization's cyber resilience...Hourly pay- ...Role: Lead Data Engineer (Azure, Snowflake, DB) Location: Remote Duration: Long Term W2 Consultants preferred. Skill Focus Azure , Snowflake, DB Key Responsibilities: Design and develop ETL/ELT pipelines using Azure Data Factory, Snowflake...Remote work
$126.2k - $264.1k
...transformation. About the Role As an Senior Principal Product Manager, you will own... ...drive alignment across product, design, engineering, clinical, compliance, support,... ...sales, support, engineering, design, QA, security, privacy, compliance, and operations to...SeniorTemporary workFlexible hours$71.2k - $166.1k
...Government Services is seeking a skilled Federal Senior Engineer/Architect (Principal Consultant) to join... ..., and be comfortable operating within a secure and dynamic engineering environment. You... ...with systems development life cycle (SDLC) methodologies, business/application re-...SeniorTemporary workFlexible hours$82.97k - $133k
...meaningful business value? Whether you bring deep expertise as a senior leader or strategic enterprise-level experience as a principal... ..., we’ve been at the forefront of designing, building, and engineering premium, award-winning products. Today, Marvin is also proud to...SeniorContract workWork at office- ...und unterstützt bei Analytics‑, AI‑ und Machine‑Learning‑Projekten Security: Du konzipierst sichere Cloud‑Architekturen und unterstützt bei Security‑, Compliance‑ und Governance‑Anforderungen Engineering: Du automatisierst Cloud‑Plattformen, setzt Infrastructure as Code...Senior
- Allwyn UK seeks a Senior Data Engineer to design, build and optimise scalable data solutions on the AWS data platform. You’ll work with Redshift... ...and costs, and mentor peers while supporting governance and security requirements. This is a transformative role within The...Senior
$40 - $66 per hour
...and Java programmingExperience also preferred:SQL REST/SOAP API call experienceSummaryThe Senior Identity Systems Engineer is responsible for designing, implementing, and securing enterprise identity and access management infrastructure that enables reliable authentication...SeniorFull timeWork experience placementShift workDay shift$230k - $265k
...System which makes everything possible.The Senior Director, IT Business Applications is... ...architected for integration, data flow, security, and resilience to enable seamless cross... ...Bachelor’s degree in Information Systems, Engineering, Business, or a related discipline;...SeniorFull time$20 - $22 per hour
...thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:Healthcare (medical, dental, vision)Basic term and optional term...SeniorLocal area- ...involves:JLL is seeking an experienced and commercially astute Senior Property Manager to join our dynamic Property & Asset Management... ...recruitment process. We endeavour to keep your personal information secure with appropriate level of security and keep for as long as we...SeniorFull timeWork at officeFlexible hours
- ...with the help of AI agents, companies can secure the resources they need to innovate... ...Startups. Your Role We’re looking for a Senior Solutions Consultant with Finance / Procurement... ...closely with the product and engineering teams to determine which customer requests...SeniorHome officeFlexible hours
- ...Motorola Solutions is hiring a Cybersecurity Analyst to assess client information systems and automate security assessment workflows. You will interview clients, analyze documentation, and drive automation through scripting to improve efficiency and evidence collection...Remote work
$160k - $180k
...Bailly location)Typical Day in the LifeThe Senior Microsoft Solution Architect serves as a... ...applications, data, AI, automation, and security.Client Advisory & StrategyLead executive... ...client expectations.Mentor consultants, engineers, and junior architects to build...SeniorLocal areaRemote workVisa sponsorship$149.52k - $175.9k
...thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:Healthcare (medical, dental, vision)Basic term and optional term...SeniorFull timeLocal areaShift work- Click here to learn more about our benefits offerings! (this link is for US only)As an equal opportunity employer, we are committed to delivering value for all our employees and fostering a culture of respect. US applicants: CNH Industrial is an equal opportunity employer...Senior
- ...RSM US LLP is seeking a Senior Payroll Specialist to join our Payroll Services practice. You will manage full cycle payroll processing for multi-state clients, ensure compliance with payroll regulations, and prepare client reports. You will collaborate with internal teams...Senior
- ...Senior Pastor Opportunity At Kulm Baptist Church Kulm Baptist Church in Kulm, North Dakota, is seeking a Senior Pastor to shepherd our congregation with biblical faithfulness, servant-hearted leadership, and a heart for community engagement. Located in a friendly rural...Senior
- ...Job Description Job Description Job Description Job Title: Senior DevOps Engineer Location: O n-site in Grand Forks, North Dakota Security Clearance: Active Secret Clearance Certifications: Security+ (current) We question. We listen. We adapt....Senior
- ...Senior Logistics Management Specialist Location: US-ND-Grand Forks Company Overview We are a world-class team of professionals who deliver... ...(AR). QinetiQ US's dedicated experts in defense, aerospace, security, and related fields all work together to explore new ways of...Senior
- ...protect our nation’s vital interests. Requisition #: 1328 Job Title: Senior Defense Capture Manager (Air Force) Location: McLean, VA... ...and market research platforms. Eligible to obtain and maintain a security clearance (as required). Preferred Skills 5+ years of...SeniorCasual workWork at officeRemote workAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer - Secure SDLC. Be the first to apply!
- information technology security engineer North Dakota
- senior cloud security engineer North Dakota
- security software engineer North Dakota
- security infrastructure engineer North Dakota
- security engineer North Dakota
- cloud security engineer North Dakota
- network security engineer North Dakota
- aws cloud security engineer North Dakota
- azure security engineer North Dakota
- endpoint security engineer North Dakota



