Senior Application Security Engineer

| Chicago
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

We all depend on healthcare throughout our lifetimes, for ourselves, and our families and friends, but it is notoriously difficult to navigate and understand. As an industry that comprises 20% of the US economy we think healthcare should work better for all of us. At Collective Health we believe it’s time for a new day in healthcare where as members we are informed and empowered to make the right care choices when the decisions are urgent and critical. 

You’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security and architectural challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.

This role will focus on security architecture, design and engineering subject areas while being able to layout product security maturity, identify program and tool gaps and recommend solutions. Building positive relationships with Engineering, Product, Risk and customer facing teams is a core tenant of the role and the team. You will help in building an enterprise testing and assessment framework by introducing and integrating security tools, processes & responsibilities with developer ecosystem -- Tools include but not limited to, Dynamic Analysis, Static Analysis, Real time Application Self-Protection, Web application Firewall and Software Composition Analysis. While the Primary set of responsibilities include architecture and design scalability and optimization, other duties such as Application Penetration testing, design reviews and following up on identified risks are also a part of this job when and where vital.

What you’ll do:
  • Architect, build and drive implementations of DAST/SAST/SCA/WAF/RASP/IAST solutions in an enterprise environment
  • Perform code audits on internal and open source libraries for inclusion in our products and/or for employee consumption
  • Perform Application threat modeling exercises and attack simulation exercises both in the context of internal assessments and while assisting 3rd party application penetration testing/gray box testing
  • Provide detailed explanations of the security issues found and ensure that those responsible for fixing them have a firm grasp of the fixes that needs to be implemented
  • Design and implement enhancements to our Continuous Integration and Continuous Deployment (CI/CD) pipeline/s to include security controls and appropriate guardrails to help build secure code and scale security processes
  • Perform, and assist other team members, in application penetration testing and able to effectively translate the technical requirements and findings to appropriate user groups and partners
  • Be responsible for and collaborate with team members, understand their processes and workflows, prioritize their ideas and innovations and develop improvements to ensure successful execution.
  • Provide technical leadership and mentorship on security topics to both security and non-security user groups
Your skills include:
  • Strong Experience with architecting and/or operating application security tooling such as DAST/SAST/SCA/WAF/RASP/IAST in an enterprise environment
  • Strong Experience with socializing and building partnership on security programs and user expectations
  • Strong Experience with training and mentoring the entire company on security practices and other awareness related exercises
  • Moderate hands-on experience conducting web application security reviews, application and network-based penetration testing, and threat modeling
  • Moderate to basic experience in leading technical security specialists in the augmentation of Continuous Integration (CI) pipeline to include security testing; collaborate with partners on overall CI/CD vision and implementation strategy.
  • Moderate to basic experience with common attack scenarios in various common layers within our infrastructure (cloud-based issues, code quality, insider threat, etc.,)
  • Basic programming in one or more of the following languages: Python, JS, Go, ROR or Java
  • Basic experience working with Cloud hosting platform (AWS, GCP, DO, AZURE)
  • Basic understanding of container-based/micro-service infrastructure orchestration (e.g. Docker, Kubernetes, Meso)

Collective Health is a technology company simplifying employer healthcare to make health insurance work for everyone. With more than a quarter million members and over 60 enterprise clients—including Pinterest, Red Bull, Restoration Hardware, Box, Activision Blizzard, and more—our technical and customer experience teams are reinventing the healthcare experience for forward-thinking employers and their people across the U.S.

Collective Health is headquartered in San Mateo, CA, with additional offices in Chicago, IL, and Lehi, UT. Founded in 2013, Collective Health is backed by the SoftBank Vision Fund, DFJ Growth, PSP Investments, NEA, GV, G Squared, Founders Fund, Maverick Ventures, Mubadala Ventures, Sun Life, HCSC and other leading investors. For more information, visit us at https://www.collectivehealth.com.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Collective Health is committed to providing support to candidates who require reasonable accommodation during the interview process. If you need assistance, please contact [email protected]

Read Full Job Description
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

Technology we use

  • Engineering
  • Product
    • GolangLanguages
    • JavaLanguages
    • PythonLanguages
    • ReactLibraries
    • AngularJSFrameworks
    • Node.jsFrameworks
    • SpringFrameworks
    • PostgreSQLDatabases
    • Google AnalyticsAnalytics
    • PiwikAnalytics
    • SketchDesign
    • ConfluenceManagement
    • JIRAManagement

Location

Located right in the heart of River North by the Red, Brown, and Purple CTA lines, with countless nearby restaurants and entertainment options.

An Insider's view of Collective Health

What’s the vibe like in the office?

The vibe here in the Chicago office is one of chill focus. For the most part, you'll hear the tapping of keys and some soft conversation, with the occasional bubbling over of laughter. We like to get our work done here, but we love getting to know one-another. We're always happy to step away for a chat over coffee or a game of foosball.

Marc

Software Engineer

What does your typical day look like?

Daily work as an SRE includes anything that increases the reliability and stability of the Collective Health platform to make sure our customers have the best experience possible. Everything from huge cross-team initiatives like migrating to Kubernetes to really deep dives troubleshooting issues is possible - and I choose projects that interest me!

Katie

Site Reliability Engineer

How does the company support your career growth?

People here really root for each other’s growth professionally and personally, and they show it by working alongside you to help you do more than you thought you could. We make sure there is space to learn as you work and try new things, and when you do well with them, you get concretely recognized for it.

Hannah

Software Engineer

How do you empower your team to be more creative?

We strive to foster a psychologically safe culture in order to feel free to share all our ideas, allowing even crazy whims and hunches to be molded and shaped by in-depth discussion and collaboration until they reach their full potential. No question is a stupid one, and we all have valuable input.

Matt

Software Engineer

What are some social events your company does?

From the vaguely familiar whirlyball to the always-embarrassing karaoke happy hour, we like to keep things fun and not take ourselves too seriously. We’ve even subjected ourselves to a hot sauce eating challenge, just for fun. Our team also has a regular “game night” where we play anything from Settlers of Catan to Mario Kart.

Patrick

Senior Product Manager

What are Collective Health Perks + Benefits

Collective Health Benefits Overview

We pay 100% of employee premiums for medical, dental, and vision plans. We also offer a wellness stipend, flexible time off, help with your commute, life insurance, a retirement plan, and plenty of perks to keep you happy, healthy, and engaged.

Culture
Volunteer in local community
Friends outside of work
Eat lunch together
Daily sync
Team owned deliverables
Team based strategic planning
Group brainstorming sessions
Pair programming
Open office floor plan
Diversity
Documented equal pay policy
Diversity Employee Resource Groups
Hiring Practices that Promote Diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Dental Benefits
Vision Benefits
Health Insurance Benefits
Life Insurance
Wellness Programs
Retirement & Stock Options Benefits
401(K)
Company Equity
Child Care & Parental Leave Benefits
Generous Parental Leave
Flexible Work Schedule
Family Medical Leave
Company sponsored family events
Vacation & Time Off Benefits
Unlimited Vacation Policy
Paid Holidays
Paid Sick Days
Perks & Discounts
Casual Dress
Commuter Benefits
Company Outings
Free Daily Meals
Game Room
Stocked Kitchen
Happy Hours
Relocation Assistance
Fitness Subsidies
Professional Development Benefits
Diversity Program
Lunch and learns
Cross functional training encouraged
Promote from within
Mentorship program
More Jobs at Collective Health34 open jobs
All Jobs
Data + Analytics
Design + UX
Dev + Engineer
HR + Recruiting
Internships
Legal
Marketing
Operations
Product
Project Mgmt
Data + Analytics
new
Chicago
Internships
new
Chicago
Data + Analytics
new
Chicago
Developer
new
Chicago
HR + Recruiting
new
Chicago
Developer
new
Chicago
Developer
new
Chicago
Data + Analytics
new
Chicago
Product
new
Chicago
Marketing
new
Chicago
Data + Analytics
new
Chicago
Design + UX
new
Chicago
Operations
new
Chicago
Data + Analytics
new
Chicago
Project Mgmt
new
Chicago
Developer
new
Chicago
Operations
new
Chicago
Data + Analytics
new
Chicago
Developer
new
Chicago
Developer
new
Chicago
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.
Save jobView Collective Health's full profileSee more Collective Health jobs