Sr. Application Security Engineer

| Remote
Sorry, this job was removed at 12:34 p.m. (CST) on Thursday, June 2, 2022
Find out who’s hiring remotely
See all Remote jobs
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Back to Career Site


Our Mission is to Make Healthcare Right. Together. Built upon the belief that by connecting and aligning the best local resources in healthcare delivery with the financing of care, we can deliver a superior consumer experience, lower costs, and optimized clinical outcomes.

What drives our mission? The company values we live and breathe every day. We keep it simple: Be Brave. Be Brilliant. Be Accountable. Be Inclusive. Be Collaborative.

If you share our passion for changing healthcare so all people can live healthy, brighter lives – apply to join our team.


SCOPE OF ROLE

The Application Security Engineer is a member of the Bright Health Information Security Organization and involved in building, maintaining and supporting public cloud security and engineering initiatives. This person will be required to work effectively and seamlessly with our engineering organization’s existing security, engineering and cloud operations.

ROLE RESPONSIBILITIES

  • Serve as a subject matter expert for application security, providing guidance to engineering and product teams
  • Develop roadmap for application security through the assessment of the application portfolio for Dynamic Application Security Testing (DAST) and develop processes for vulnerability identification, analysis and remediation coordination
  • Implement capabilities to conduct Static Application Security Testing (SAST) and Software Composition Analysis (SCA) and develop processes required to integrate into the SDLC
  • Lead research into suspected application vulnerabilities
  • Lead efforts around secure development training for our engineering team
  • Coordinate application pentests efforts for all our products
  • Maintain awareness of known vulnerabilities in application technologies used within BHG
  • Assist with performing thorough threat modeling of web applications
  • Effectively partner and communicate with Development, Product, and Management

EDUCATION, TRAINING, EXPERIENCE

  • Bachelors degree in technical field (required), Masters degree (preferred).  
  • 5+ years of application security experience 
  • Competency in dynamic web application testing, SAST & DAST scanning 
  • Basic understanding of vulnerability management tools 
  • Demonstrated skills in modern programming and scripting languages (Python, Go, JavaScript) and experience with Infrastructure-as-Code frameworks (Terraform, Ansible)
  • A proven understanding of Kubernetes multi-tenant deployments at scale. This includes security, hardening, policies, and deployment in infrastructures such as Azure AKS or Amazon EKS or Google Cloud Platform GKE.
  • Strong understanding of OWASP TOP 10 
  • Strong understanding of cloud architecture 
  • Candidates must have excellent verbal and written communication skills, including experience speaking in public forums and writing/contributing to technical publications. 
  • Familiar with waterfall and agile development processes and have experience integrating secure development practices into both models 
  • Familiarity with industry standards and regulations including HIPAA, SOC2, PCI, SOX, and ISO27001 is desired 
  • Security experience with native iOS, native Android, APIs, and React - that's a big plus!
  • ISACA, (ISC)2, Offensive Security or relevant industry certifications preferred

 

We’re Making Healthcare Right. Together.

We are realizing a completely different healthcare experience where payors, providers, doctors, and patients can all feel connected, aligned and unified on the same team. By eradicating the frictions of competing needs, we are making it possible to give everyone more of what they want and deserve. We do this by:

 

Focusing on Consumers
We understand patient pain points, eliminating complexity while increasing transparency, for greater access and easier navigation.

 

Building on Alignment
We integrate and align individual incentives at all levels, from financing to optimization to delivery of care.

 

Powered by Technology

We employ our purpose built, integrated data platform to connect clinical, financial, and social data, to deliver exceptional outcomes.

 

          

 

As an Equal Opportunity Employer, we welcome and employ a diverse employee group committed to meeting the needs of Bright Health, our consumers, and the communities we serve. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

 


Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Location

We are downtown at 515 Congress Avenue, right in the heart of downtown! Tons of restaurants and close to public transportation.

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Bright HealthFind similar jobs