Cyber Security Engineer – Application Security

🔥 0 minutes ago

🔔 Pennsylvania – Remote

infoinfo

💵 $110k - $150k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

💻 Application Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of TherapyNotes, LLC

TherapyNotes, LLC

51 - 200 employees

Founded 2010

💼 Consulting

⚖️ Legal

🏥 Healthcare

Consulting • Legal • Healthcare

TherapyNotes, LLC is a comprehensive practice management system designed specifically for behavioral health professionals, including psychologists, therapists, psychiatrists, and social workers. The platform offers an array of features such as scheduling, telehealth, electronic health records (EHR), billing, and a client portal, all integrated into a secure and user-friendly software solution. TherapyNotes aims to streamline clinical workflows, enhance patient care, and reduce administrative burdens for mental health practices, supporting them with dedicated customer service and continuous innovation based on user feedback.

📋 Description

• Own application security across the software development lifecycle and CI/CD pipeline. • Collaborate with development teams to continuously integrate security into the SDLC and CI/CD pipeline. • Enforce secure coding standards and best practices to protect customer data confidentiality, integrity, and availability. • Perform security assessments, code reviews, and threat modeling to identify vulnerabilities and risks. • Operate GitHub Advanced Security, triaging code, secret, and dependency-scanning findings and improving scanning coverage, configuration, and workflows. • Secure CI/CD pipelines and GitHub Actions, including identities, runners, permissions, and secrets. • Reduce software supply-chain risk through third-party action review, dependency controls, action pinning, and artifact provenance. • Review Terraform and other infrastructure-as-code for security issues and partner with IT platform teams on secure deployment practices. • Align application security measures with HIPAA, HITRUST, and HITECH and support regular audits. • Collaborate with developers on vulnerability remediation and effective patching or mitigation. • Develop, deploy, and manage SAST, DAST, vulnerability-management, and other security tools. • Support application-security incident response, root-cause identification, and resolution strategies. • Contribute to security-awareness programs focused on secure coding and proactive security measures. • Contribute to broader security engineering efforts including vulnerability management, incident response, and identity and access security.

🎯 Requirements

• Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered. • 5+ years in application security or security engineering. • Demonstrated experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST, code/secret/dependency-scanning triage, runner and workflow-permission security, and third-party action/supply-chain risk. • Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations. • Working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage. • Understanding of Zero Trust architecture principles and application to application and identity access. • Strong understanding of HIPAA, HITECH, and HITRUST and their impact on application security. • Experience with API security, particularly integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred. • Prior experience securing cloud environments; Azure preferred and AWS a plus. • Willingness to participate in an incident response on-call rotation. • Industry certifications such as GWAPT, OSWE, GPEN, or an Azure/AWS cloud security certification are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience. • Commitment to continuous learning and professional development. • Ability to adapt quickly to new challenges. • Strong work ethic and ownership of projects through completion. • Strong collaboration skills with cross-functional teams.

🏖️ Benefits

• Employer sponsored health, dental, vision, life, and disability insurance • Retirement plan with company contribution • Annual company profit sharing • Personal development/training budget • Open, collaborative work environment • Extensive 2-week onboarding plan • Comprehensive mentorship program

Apply Now

Similar Jobs

🔥 4 hours ago

Eos Energy Enterprises, Inc.

201 - 500

⚡ Energy

🏭 Manufacturing

Applications Engineer translating customer requirements into battery energy storage system designs and proposals. Supporting Eos sales, integrations, RFQs, and contract development.

🔥 4 hours ago

Lightserve Corp

51 - 200

🏗️ Construction

📦 Logistics

⚡ Energy

Applications engineering manager leading EPC projects for distributed energy, BESS, generation, microgrids, and electrical infrastructure. Guiding technical design, proposals, interconnections, procurement, and execution support.

Flash

🔥 10 hours ago

Agilent Technologies

10,000+ employees

🍽️ Food & Beverage

🏥 Healthcare

💼 Consulting

Field Application Engineer supporting Agilent ICP-OES and ICP-MS hardware and software. Delivering customer training, consulting, troubleshooting, and application solutions across the US and Canada.

🔥 13 hours ago

CVS Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

Distinguished Engineer shaping CVS Health’s enterprise application security architecture. Securing healthcare software, CI/CD platforms, and AI-assisted development across cloud and on-premise environments.

🔥 21 hours ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Senior ColdFusion engineer modernizing and sustaining secure mission applications. Supporting Koniag’s federal government customers through platform engineering, integrations, troubleshooting, and security hardening.