Senior Security Engineer – Secure SDLC
Listed on 2026-08-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Company :
enGen
Job Description :JOB SUMMARY
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.
This is a high-impact, hands‑on engineering role for a security professional who is passionate about preventing vulnerabilities before they happen . You will be at the forefront of our shift-left security strategy, working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.
If you thrive at the intersection of security engineering, developer collaboration, and automation , and you want to build something that matters at enterprise scale in one of the nation’s leading health and insurance organizations — this role is for you.
What You’ll DoBuild & Enforce Shift-Left Security Controls- Design and implement security guardrails to catch vulnerabilities as early as possible in development (IDE, commit time, CI/CD pipelines).
- Configure and enforce enterprise-wide pipeline security gates, ensuring code meets security standards before reaching production.
- Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST) across our Git Lab-based development platform.
- Develop scalable security-as-code policies and enforcement rules for a large, distributed engineering organization.
- Lead risk-based triage and prioritization of detected vulnerabilities, using exploitability signals like EPSS scores, Known Exploited Vulnerability (KEV) status, and reachability analysis.
- Establish and track remediation SLAs based on vulnerability severity and business risk, focusing on eliminating Critical and High findings pre-production.
- Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, and developer education.
- Monitor and report on key security health metrics, including Mean Time to Remediate (MTTR), security debt trends, and pre‑vs. post‑production detection rates.
- Architect and maintain the enterprise application security toolchain, ensuring proper integration, tuning, and delivery of high‑fidelity, actionable signals.
- Build automation workflows for vulnerability triage, escalation, assignment, and reporting to reduce manual overhead and accelerate response times.
- Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
- Develop dashboards and reporting pipelines to provide engineering and security leadership with real‑time visibility into the organization’s security posture.
- Serve as a trusted, embedded security advisor to engineering teams, offering hands‑on guidance, code review support, and practical remediation recommendations.
- Design and deliver security training, workshops, and reference materials that make secure coding accessible and actionable for all developers.
- Build and grow a Security Champions program, embedding security advocates within engineering teams to extend the App Sec program’s reach.
- Create and maintain secure coding standards, design patterns, and reusable security libraries to reduce the security burden on individual developers.
- Define, track, and report on App Sec KPIs that demonstrate program effectiveness and drive continuous improvement.
- Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
- Support audit and compliance activities by ensuring security controls are documented, measurable, and consistently enforced.
- Benchmark program maturity against industry frameworks like OWASP SAMM and BSIMM, and drive year‑over‑year improvement.
- Experience with Git Lab Ultimate security features including Vulnerability Reports, Security Policies, and Compliance Frameworks
- Deep proficiency with application security scanning tools — SAST, DAST,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).