Alignment Healthcare-posted 8 days ago
Full-time • Mid Level
Orange, CA
1,001-5,000 employees

Alignment Health is breaking the mold in conventional health care, committed to serving seniors and those who need it most: the chronically ill and frail. It takes an entire team of passionate and caring people, united in our mission to put the senior first. We have built a team of talented and experienced people who are passionate about transforming the lives of the seniors we serve. In this fast-growing company, you will find ample room for growth and innovation alongside the Alignment Health community. Working at Alignment Health provides an opportunity to do work that really matters, not only changing lives but saving them. Together. This position is responsible for identifying, analyzing, and helping with remediate security vulnerabilities within our applications. This role requires a strong understanding of application security principles, hands-on experience with various security testing methodologies, and excellent communication skills to collaborate effectively with development teams and other stakeholders.

  • Conduct static application security testing (SAST), dynamic application security testing (DAST), and interactive application security testing (IAST) on a continuous basis.
  • Identify , triage, and validate security vulnerabilities using both automated tools and manual review.
  • Work closely with software development and DevOps teams to provide clear, actionable guidance on how to fix vulnerabilities and implement secure coding practices.
  • Help integrate security controls and checks into the software development lifecycle (SDLC) and CI/CD pipelines.
  • Drive and support application security reviews and threat modeling.
  • Manage and configure a suite of application security tools, ensuring their effective use and reporting.
  • Stay up-to-date with the latest security threats, trends, and technologies, and conduct research on new vulnerabilities and attack vectors.
  • Contribute to the creation and maintenance of application security policies, standards, and procedures to guide development teams and ensure compliance.
  • Develop and deliver security awareness and secure coding training to engineering teams.
  • Support and lead third-party penetration testing.
  • 5-7+ years of progressive experience in information security, with a strong focus on application security testing and vulnerability management.
  • Proven track record of working directly with developers and engineering teams to identify and remediate security vulnerabilities in a fast-paced environment.
  • Experience in a large-scale enterprise environment with complex application portfolios.
  • Bachelor's degree or equivalent work experience in Computer Science, Information Security, or a r elated technical discipline
  • Experience with general threat hunting techniques and tools
  • Experience with one or more programming languages (i.e., C#, Scala, Python).
  • Experience in healthcare or another highly regulated field.
  • Relevant professional certifications such as Offensive Security Certified Professional (OSCP) , GIAC Web Application Penetration Tester ( GWAPT ), or Certified Secure Software Lifecycle Professional ( CSSLP ) are highly desirable.
  • ISC2 Certified Information Systems Security Professional (CISSP)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service