Senior Security Engineer - Secure SDLC
$102.7k - $164.6kHighmark Health
Company : enGen Job Description :
JOB SUMMARY
***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.
This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.
If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.
Build & Enforce Shift-Left Security Controls
- Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.
- Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards.
- Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform.
- Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization.
- Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.
Drive Vulnerability Risk Reduction
- Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.
- Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production.
- Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.
- Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.
- Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.
Automate & Optimize the Security Toolchain
- Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal.
- Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains.
- Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times.
- Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
- Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance.
- Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.
Enable & Empower Developers
- Serve as a trusted, embedded security advisor to engineering teams, providing hands-on guidance, code review support, AI security consultation, and practical remediation recommendations.
- Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels.
- Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.
- Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams.
- Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications.
- Partner with development, architecture, and platform teams to embed secure-by-default AI development practices throughout the SDLC.
Measure, Report & Continuously Improve
- Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
- Establish and report on AI security metrics such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings.
- Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
- Support audit, risk, and compliance activities by ensuring security controls, AI governance requirements , and secure development standards are documented, measurable, and consistently enforced.
- Benchmark program maturity against industry frameworks such as OWASP SAMM, BSIMM, OWASP Top 10 for LLM Applications , and emerging AI security best practices, driving year-over-year improvement.
- Continuously assess emerging threats, vulnerabilities, and attack techniques affecting modern software delivery pipelines, software supply chains, and AI-enabled applications.
Assist in AI Application Security & Governance
- Assist with security reviews and threat modeling for AI-enabled applications, LLM integrations, AI agents, and AI-assisted development platforms.
- Collaborate with Security Architecture to recommend and establish technical controls and guardrails supporting enterprise AI governance requirements.
- Evaluate security risks associated with AI models, prompts, training data, model supply chains, MCP integrations, and agentic workflows.
- Partner with Architecture, ISRM, and Software Delivery Enablement teams to define secure AI development standards and implementation patterns across the enterprise.
Preferred Qualifications
- Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, Compliance Frameworks, and security controls supporting AI-assisted development workflows.
- Deep proficiency with application security scanning tools including SAST, DAST, SCA/Dependency Scanning, Container Scanning, Secret Detection, API Security Testing , and emerging AI application security assessment capabilities.
- Deep proficiency with JFrog security and compliance tools such as Xray and Curation , including Policies, Watches, Impact Analysis, Software Supply Chain controls, and reporting.
- Familiarity with threat modeling methodologies such as STRIDE, PASTA , and their application to AI-enabled systems, LLM integrations, and agentic workflows.
- Working knowledge of common AI security risks including prompt injection, insecure output handling, excessive agency, retrieval risks, model poisoning, training data exposure, sensitive data leakage, and model supply chain threats.
- Experience designing or reviewing security controls for AI-enabled applications, AI assistants, AI agents, or LLM integrations.
- Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, NIST CSF, NIST AI RMF , or equivalent governance frameworks.
- Industry certifications such as CSSLP, GWEB, GWAPT, OSCP, AI Security certifications , or equivalent.
- Prior experience as a software developer. We strongly value candidates who understand what it's like to be on the other side of a security finding and can balance security, delivery, and developer experience.
- Experience coordinating or conducting penetration testing, red team exercises, AI security assessments, and application threat modeling engagements.
- Experience establishing security controls and governance requirements for AI-assisted software development platforms (e.g., GitLab Duo, GitHub Copilot, Claude Code, Cursor, MCP-based tooling, or equivalent) within a large enterprise environment.
ESSENTIAL RESPONSIBILITIES
Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.
Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.
Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects.
Implement, monitor, configure, and maintain security systems.
Assure compliance to required standards, procedures, guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
- Bachelor's Degree in Computer Science, Information Systems, or closely related field
Substitutions
- None
PREFERRED EDUCATION
- Master's Degree in Computer Science, Information Security or related field
EXPERIENCE
Required
7 years with Information Security and Systems Analysis
7 years with Information Security and/or Information Risk Management and/or Information Technology
7 years with Operating Systems and Software Administration
7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
Preferred:
10 years with Information Security and Systems Analysis
7 years in IT / Information Security Risk advisory
7 years in-depth understanding of network security architecture, network and networking protocols
7 in Database Management, System Administration and Software Development Life-Cycle
3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
SKILLS
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
Strong teamwork and inter-personal skills
Additional Skills:
Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins , or equivalent, including security policy enforcement and pipeline governance.
- Proficiency in at least one scripting or programming language ( Python, Go, Bash , or equivalent) for security automation, workflow development, and security tooling integrations.
- Familiarity with container and cloud-native security concepts including Docker, Kubernetes, cloud provider security services , and modern platform engineering practices.
- Ability to conduct focused secure code reviews and security architecture reviews across both human-authored and AI-generated code.
- Experience evaluating security implications of AI coding assistants, AI agents, MCP-enabled tooling, and AI-powered developer platforms.
- Understanding of secure AI development principles, including governance controls for AI-generated code, model consumption, prompt handling, data protection, and human review requirements.
- Preparing and delivering regular security posture briefings to engineering and security leadership, including trend analysis, KPI performance, risk summaries, AI security metrics, and forward-looking recommendations.
- Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, JFrog Xray, or equivalent) across multiple package ecosystems.
- Generating, maintaining, and interpreting Software Bills of Materials (SBOMs) in CycloneDX or SPDX formats.
- Applying container security best practices including minimal base images, non-root execution, read-only filesystems, image signing, and software supply chain verification.
- Designing security gates that prevent non-compliant code, dependencies, containers, or deployment artifacts from advancing through the pipeline while minimizing developer friction (GitLab, JFrog Xray, or equivalent).
- Experience implementing or supporting software supply chain security controls including artifact governance, package repository management, dependency trust validation, and build integrity protections.
- Knowledge of industry frameworks and guidance related to AI and application security, including OWASP Top 10 for LLM Applications, OWASP SAMM, BSIMM, NIST Secure Software Development Framework (SSDF), and NIST AI Risk Management Framework (AI RMF) .
- Ability to partner with Architecture, Software Delivery Enablement, Engineering, and Risk Management teams to define and operationalize secure AI development standards and guardrails.
LICENSES or CERTIFICATIONS
Required
- None
PREFERRED
- Certified Information Systems Security Professional (CISSP), Security +
LANGUAGE REQUIREMENT ( other than English )?
None
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS
Position Type:
Office-Based
Office-Based Positions
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
Pay Range Minimum:
$102,700.00Pay Range Maximum:
$164,600.00Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at View email address on aiapply.co
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
$119k - $169.4k
...Chicago, IL office. Role Overview The Network Security Team is seeking a Sr. Network and Firewall Security Engineer to secure and operate connectivity across global... ...the ability to communicate effectively with senior leadership—translating deep technical issues, risks...SeniorFull timeWork at officeImmediate startNight shift$2,500 per month
The Red Team - SrSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes information system security administration and maintenance, vulnerability management, and configuration...SeniorFull timeWork experience placement- ...Competitive PTO and fully paid time off opportunities to volunteer within your community About the Role We are seeking a Senior Cloud Security Engineer to drive the implementation and continuous improvement of security controls across our cloud environments. This role...Senior
$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate... ..., threat modeling, secure code review, cryptography, and the SDLC. Ability to clearly communicate best practices and effective...SuggestedWork at officeRemote work$130k - $195k
...Posting Type Remote Job Overview The Senior IAM Engineer is a technically authoritative leader who sets the direction for the enterprise... ...identity domains. Partnering with the Manager of Enterprise Security and leading cross-functional teams, the role reduces...SeniorFull timeRemote workFlexible hours$119.6k - $215.4k
...customers? Is Network and Infrastructure Security your passion? Join our Enterprise... ...is a core part of the pre-sales solution engineering group. We collaborate across our global... ...helping to close the sale. As a Pre-Sales Senior Enterprise Security Architect, you will...SeniorWork experience placementWork at office- ...financial services organization to build an innovative AI-driven security capability that transforms how application vulnerabilities are... ...model behavior. ~ Strong software architecture and engineering experience. Preferred Qualifications ~ Application security...Senior
$106.3k - $234.6k
...products that meet the needs of our customers who are tackling some of the world’s biggest challenges. As a Principal Hardware Security Engineer you will be involved in ensuring that the compute hardware that is used in the Oracle Cloud Infrastructure meets the security...Temporary workFlexible hours- BTC - Business Technology Consulting AG sucht Berater im Security-Modern-Workplace-Umfeld. Sie führen Readiness-Checks durch, priorisieren Risiken und entwickeln Roadmaps zur Härtung von Identitäten, Endpunkten und Collaboration-Workloads. Sie beraten zur Ziel- und Referenzarchitektur...SeniorRemote job
- Security im Modern Workplace ist weit mehr als das Aktivieren einzelner Features. Sie entscheidet darüber, ob digitale Zusammenarbeit skalierbar, belastbar und vertrauenswürdig bleibt. Das erwartet dich Du führst Readiness-Checks durch, priorisierst Risiken und entwickelst...SeniorWork at officeRemote work
- ...Security Engineer TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response...
$40k
...mission-critical programs across national security, defense, and public service delivery.... ...national scale. The Junior Security Engineer supports 24x7 enterprise cybersecurity operations... ...activities. The role works under senior guidance to execute defined cyber...Contract workRemote work- ...Job Description Job Description Foresite is seeking a highly motivated and passionate Security Engineer with a specialized focus on Google Security Operations (SecOps) to join our growing team. In this client-facing role, you will be instrumental in helping our clients...Temporary work
$195k
...derivatives, foreign exchange, digital assets, and securities. The organisation operates critical infrastructure across... ...across on-prem and hybrid environments Act as a senior escalation point, mentor junior engineers and help drive operational best practices...Full time- Insight Global is seeking a Senior Business Analyst for hybrid work in Overland Park, KS, on a 12-month contract. You will lead IT security initiatives across the full SDLC, focusing on IAM, data security, and data loss prevention. You will gather requirements from technical...SeniorContract work
- ...a motivated IT Administrator to safeguard our IT infrastructure and customer environments. You'll design, implement, and optimize security controls while ensuring reliable operations across cloud and on-premises systems. The role emphasizes Google Workspace/GCP, identity...
- Overview We are seeking a full-time Cyber Security Vulnerability Analyst 2 at Garmin's U.S. headquarters in the Greater Kansas City area. In this role, you will be responsible for operating independently to configure and perform vulnerability scanning and assessments to...Full timeWork experience placement
$222k - $304.5k
...a Prisma AIRS business unit aligned Domain Consultant for AI Security, you provide technical expertise and guidance in securing customers... ...the customer, partnering directly with Product Management and Engineering to channel real-world field feedback into future releases of...SeniorFull timeRemote workVisa sponsorshipWork visa- An established industry player is seeking a Senior Database Engineer to lead cloud migration efforts and ensure robust database security. In this role, you will oversee the migration of databases to cloud platforms, implement security measures, and develop disaster recovery...Senior
- ..., compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic monitoring... ...any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual...Minimum wageContract workTemporary workWork experience placementRemote work
$160.2k - $246.3k
...Remote - United States Full time JR-202613817 Job Description The Role : We're looking for a seasoned Security Software Engineer to join our IAM team (Identity Access Management) to help develop, architect and advance our suite of applications and services...Full timeFor contractorsLocal areaRemote workWork from homeRelocation packageFlexible hours- Garmin is seeking a full-time Cyber Security Vulnerability Analyst 2 at its U.S. headquarters in the Greater Kansas City area. You will independently configure and perform vulnerability scanning to identify risks to networks, OS, applications, and other information system...Full time
- ...Waldensecurity is seeking an Intermediate Supervisor to manage government-facing coordination and contract execution, supervising security personnel and staffing, ensuring performance compliance and property accountability. The role includes daily COR liaison, emergency...SeniorContract work
$118.7k - $243.7k
Position Summary As a Manager in AI Security Engineering, you will play a critical role in securing the development and deployment of... ...Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities...- ...Spirit AeroSystems, Inc. in Wichita, KS, seeks an experienced Security Manager to lead a growing team and protect people, property, and information across shifts. The role involves cross‑functional collaboration with HR, legal, and law enforcement, plus managing access...SeniorShift work
- ...Foresite is looking for a highly technical, results-oriented Cloud Security Engineer to serve as the technical lead for onboarding customers to... ...from technical kickoff to final handoff without constant senior oversight. Strategic Communicator: You can translate deep...Temporary work
- ...We are looking for a a Cyber Security Engineer to join our Information Security Team in Kasas City. The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access management. We are looking for hands-on experience with modern security...Work experience placementRemote work
- ...Cyber Security Engineer Cyber Security Engineer CSA Global LLC Cyber Security Engineer Fort Leavenworth, KS • Army & Other Agencies Job Type Full-time Description Client Solution Architects (CSA) is currently seeking a Cyber Security Engineer to support our program...Full timeTemporary workWork at office
- ...Cybersecurity Analyst The Cybersecurity Analyst operates as a cross-functional security role responsible for integrating Security Operations (SIEM/SOC), and Governance, Risk & Compliance (GRC). This role goes beyond alert monitoring and provides assistance with security...Work at officeLocal area
- ...Cyber Security EngineerLocation: Bellevue WA, Overland Park KS, Frisco TX, Ravinia GA, or Herndon VAOnsite positionDuration: 12 monthsJD:Cyber Security: 10+ Years Java, frameworks, Python, Nodejs: 5+ Years Threat Modelling like STRIDE, PASTA, TRIKE, ATTACK TREE, DREAD...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer - Secure SDLC. Be the first to apply!
- information technology security engineer Kansas
- senior cloud security engineer Kansas
- security software engineer Kansas
- security infrastructure engineer Kansas
- security engineer Kansas
- cloud security engineer Kansas
- network security engineer Kansas
- aws cloud security engineer Kansas
- endpoint security engineer Kansas
- IT security engineer Kansas



