Summary
✨ AI‑Generated
A remote application security engineering role focused on integrating security into software development workflows, identifying vulnerabilities, and protecting sensitive data through secure engineering practices.
Highlights
Fully remote security role focused on protecting sensitive applications, improving development practices, and strengthening software security processes.
Description
This is a Fully Remote Job
1.
About Our Client:
The organization provides behavioral health Practice Management and EHR software designed to streamline scheduling, billing, documentation, and telehealth for clinicians.
It addresses the challenge of managing administrative tasks in behavioral health practices, enabling clinicians to focus on patient care.
2.
About the Opportunity:
The Cyber Security Engineer (Application Security) is responsible for securing the software development lifecycle and continuous integration/deployment pipelines.
This role enhances application security, reduces vulnerabilities, and ensures compliance with healthcare regulations, contributing to the protection of sensitive health data.
3.
Responsibilities:
Collaborate with development teams to integrate security into the SDLC and CI/CD pipeline.Enforce secure coding standards to protect data confidentiality, integrity, and availability.Conduct security assessments, code reviews, and threat modeling.Manage and operate GitHub Advanced Security tools for code and dependency scanning.Secure CI/CD pipelines, GitHub Actions, and mitigate software supply chain risks.Review infrastructure-as-code for security misconfigurations.Ensure compliance with HIPAA, HITRUST, and HITECH standards.Assist developers in vulnerability remediation.Develop and manage security testing tools and automation.Support incident response activities related to application security.Promote security awareness and best practices among development teams.
4.
Requirements:
Bachelor''s degree in information security, computer science, or related field preferred.Minimum 5 years of experience in application security or security engineering.Proven experience securing CI/CD pipelines and GitHub Actions including SAST/DAST and dependency scanning.Familiarity with Terraform or similar infrastructure-as-code security reviews.Knowledge of SIEM, EDR/XDR, and DLP platforms.Understanding of Zero Trust principles for application and identity access.Strong knowledge of healthcare security regulations (HIPAA, HITECH, HITRUST).Experience with API security and healthcare data standards such as HL7.Prior experience securing cloud environments, preferably Azure.Willingness to participate in incident response on-call rotation.Relevant industry certifications are advantageous but not a substitute for hands-on experience.
5.
Pay Range and Compensation Package:
Competitive salary range: $110,000-$150,000
6.
Benefits & Perks:
Employer-sponsored health, dental, vision, life, and disability insuranceRetirement plan with company contributionAnnual company profit sharingPersonal development and training budgetOpen and collaborative work environmentExtensive onboarding and mentorship programs
Equal Opportunity Statement:
Equal Opportunity Statement: Our client is an equal opportunity employer.
They celebrate diversity and are committed to creating an inclusive environment for all employees.
All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin.
Note:
TalentHop is a recruitment partner of this role.
Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.