Included Health is hiring a
Application Security Engineer

Logo of Included Health

Included Health

πŸ’΅ $120k-$202k
πŸ“Remote - Worldwide

Summary

Included Health is seeking an Application Security Engineer to help mitigate risk within their engineering environment by implementing strategic security measures. The role involves integrating security practices into the software development lifecycle, developing and maintaining automated security tools, performing code reviews, collaborating with engineering teams, responding to security incidents, creating documentation, and acting as a security consultant.

Requirements

  • A bachelor’s degree in a related discipline or equivalent professional experience
  • At least 4 years acting in an Application Security Engineer role with progressive responsibility
  • Strong experience integrating and managing DAST, SAST or IAST, and SCA tools and how these feed into Vulnerability Management initiatives
  • Understanding of how scanning tools, penetration tests, and post-deploy scanning tools work together in the application security lifecycle
  • Deep, hands-on experience implementing AppSec tools into a DevOps pipeline
  • Solid understanding of application security issues, risks, and mitigation strategies
  • Experience developing and refining Secure SDLC documents and processes
  • Experience building and leading Information Security training focused on developers and based on OWASP principles
  • Experience assessing and securing open-sourced software components
  • Strong interpersonal verbal and written communications skills with proven experience of collaboration across different engineering areas
  • Deep knowledge of containers and orchestrators, and hands-on experience with securing and monitoring CI/CD pipelines
  • Understanding of Go, Python, Java, Javascript code, and their common security flaws

Responsibilities

  • Embed security practices into the software development lifecycle
  • Develop and maintain automated security tools and scripts
  • Perform security code reviews and static/dynamic analysis
  • Work closely with Engineering and IT teams to promote security best practices
  • Assist in the investigation and response to security incidents and vulnerabilities
  • Stay up-to-date with the latest security trends, vulnerabilities, and tools
  • Create and maintain comprehensive security documentation
  • Act as a security consultant on secure software development practices

Preferred Qualifications

  • Hands-on experience with Terraform is a plus
  • Experience with low-code automation tools (XSOAR, Tines, etc.) is a plus
  • Professional certification is a plus (OSCP, SANS, CISSP or similar)

Benefits

  • Remote-first culture
  • 401(k) savings plan through Fidelity
  • Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
  • Full suite of Included Health telemedicine (e.g. behavioral health, urgent care, etc.) and health care navigation products and services offered at no cost for employees and dependents
  • Generous Paid Time Off ("PTO") and Discretionary Time Off ("DTO")
  • 12 weeks of 100% Paid Parental leave
  • Up to $25,000 Fertility and Family Building Benefit Compassionate Leave (paid leave for employees who experience a failed pregnancy, surrogacy, adoption or fertility treatment)
  • 11 Holidays Paid with one Floating Paid Holiday
  • Work-From-Home reimbursement to support team collaboration and effective home office work
  • 24 hours of Paid Volunteer Time Off ("VTO") Per Year To Volunteer with Charitable Organizations

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Jobs

Please let Included Health know you found this job on JobsCollider. Thanks! πŸ™