Application Security Engineer at Collective Health
We all depend on healthcare throughout our lifetimes, for ourselves, and our families and friends, but it is notoriously difficult to navigate and understand. As an industry that comprises 20% of the US economy we think healthcare should work better for all of us. At Collective Health we believe it’s time for a new day in healthcare where as members we are informed and empowered to make the right care choices when the decisions are urgent and critical.
You’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and relevant security and architectural challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will also be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.
This role will focus on security architecture, design and engineering subject areas while being able to layout product security maturity, identify program and tool gaps and recommend solutions. Building positive relationships with Engineering, Product, Risk and customer facing teams is a core tenant of the role and the team. You will help in building an enterprise testing and assessment framework by introducing and integrating security tools, processes & responsibilities with developer ecosystem -- Tools include but not limited to, Dynamic Analysis, Static Analysis, Real time Application Self-Protection, Web application Firewall and Software Composition Analysis. While the Primary set of responsibilities include architecture and design scalability and optimization, other duties such as Application Penetration testing, design reviews and following up on identified risks are also a part of this job when and where vital.What you’ll do:
- Build and drive implementations of DAST/SAST/SCA/WAF/RASP/IAST solutions in an enterprise environment
- Perform code audits on internal and open source libraries for inclusion in our products and/or for employee consumption
- Perform Application threat modeling exercises and attack simulation exercises both in the context of internal assessments and while assisting 3rd party application penetration testing/gray box testing
- Provide detailed explanations of the security issues found and ensure that those responsible for fixing them have a firm grasp of the fixes that needs to be implemented
- Design and implement enhancements to our Continuous Integration and Continuous Deployment (CI/CD) pipeline/s to include security controls and appropriate guardrails to help build secure code and scale security processes
- Perform, and assist other team members, in application penetration testing and able to optimally translate the technical requirements and findings to appropriate user groups and partners
- Responsible for and collaborate with team members, understand their processes and workflows, prioritize their ideas and innovations and develop improvements to ensure successful execution.
- Provide technical leadership and mentorship on security topics to both security and non-security user groups
- Strong experience with socializing and building partnership on security programs and user expectations
- Moderate experience with architecting and/or operating application security tooling such as DAST/SAST/SCA/WAF/RASP/IAST in an enterprise environment
- Moderate hands-on experience conducting web application security reviews, application and network-based penetration testing, and threat modeling
- Experience with common attack scenarios in various common layers within our infrastructure (cloud-based issues, code quality, insider threat, etc.)
- Experience with training and mentoring the entire company on security practices and other awareness related exercises
- Basic experience in leading technical security specialists in the augmentation of Continuous Integration (CI) pipeline to include security testing; collaborate with partners on overall CI/CD vision and implementation strategy.
- Basic programming experience in one or more of the following languages: Python, JS, Go, ROR or Java
- Basic experience working with Cloud hosting platform (AWS, GCP, DO, AZURE)
- Basic understanding of container-based/microservice infrastructure orchestration (e.g. Docker, Kubernetes, Meso)
Founded in 2013, Collective Health has created an ecosystem of innovative partners across care and benefits delivery, as well as built a powerful and flexible infrastructure to better enable employees and their families to understand, navigate, and pay for healthcare. By reducing the administrative lift of delivering health benefits, providing an intuitive member experience, and improving health outcomes, the company guides employees toward healthier lives and companies toward healthier bottom lines. Collective Health is headquartered in San Mateo, CA with locations in Chicago, IL, and Lehi, UT. For more information, please visit collectivehealth.com.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Collective Health is committed to providing support to candidates who require reasonable accommodation during the interview process. If you need assistance, please contact [email protected]
Please note that Collective Health requires all employees to verify receipt of a COVID-19 vaccination or to apply for an exemption from the vaccination requirement based on medical need, a sincerely held religious belief, or a local legal exemption. Candidates are not required to furnish such a verification or to seek an exemption from the verification requirement during the application process but would be asked to do so if they accept an offer.