Platform Engineer - GitHub Advanced Security

Wellmark, Inc.Des Moines, IA
1dHybrid

About The Position

As a Platform/Staff Security Engineer, your role is to bridge the gap between security standards, developer velocity, and the emerging world of AI-assisted engineering. By championing the GitHub Advanced Security (GHAS) ecosystem and Copilot’s autonomous agent capabilities, you will empower our engineering community to deliver resilient software through seamless automation, custom AI guardrails, and collaborative mentorship.

Requirements

  • Bachelor's Degree or direct and applicable work experience
  • Minimum 7 years of experience to include any combination of the following:
  • Development Experience: (Ex: Angular 2 (or newer), NodeJS (or newer), TypeScript, C#, .NET, Java, SQL)
  • Providing innovative solutions to complex issues
  • Minimum 4 years of experience in IT infrastructure, architecture design, operations
  • Proven ability to adapt when experiencing major changes in work tasks or work environment.
  • Informal leadership experience typically gained through leading projects.
  • Demonstrated experience coaching/mentoring others by providing guidance and feedback to help an employee or groups of employees strengthen their knowledge and skills to accomplish a task or solve a problem
  • Proven experience with designing technical architecture and keeping abreast of existing and emerging technologies.
  • Experiencing consulting with stakeholders to understand needs with the intention of providing advice and counsel. Also interacting appropriately with others to guide individuals or groups to accomplish work, reach consensus or take action.
  • Demonstrated experience in problem solving/troubleshooting skills (conceptual, technical, IT) - Breaks down problems and identifies all of their facets, including hidden or tricky aspects, to find root-cause of problems. Generates a range of solutions and courses of action with benefits, costs, and risks associated with each. Probes appropriate sources for answers, and thinks ‘outside the box’ to find options. Tests proposed solutions against the reality of likely effects before going forward.
  • Demonstrated communication skills: verbal and written - Articulate; Communicates information/concepts clearly and concisely to individuals or groups; delivers presentations suited to the characteristics and needs of the stakeholders/audience. Clearly and concisely conveys written information orally or in writing to individuals or groups to ensure that they understand the information and the message. Listens and responds appropriately to others.

Nice To Haves

  • Technical Mastery: Proven expertise in the GitHub Advanced Security (GHAS) suite (CodeQL, Secret Scanning, Dependabot).
  • Automation Fluency: Deep experience building CI/CD pipelines (GitHub Actions) with a focus on automated security gates and agentic task delegation
  • Influence: Demonstrated ability to drive security and AI adoption across multiple teams through influence and collaboration rather than direct authority.
  • AI Implementation: Hands-on experience configuring and scaling GitHub Copilot at an enterprise level, including experience with Copilot Chat, Edits, or Agent mode.

Responsibilities

  • Ecosystem Optimization: Lead the strategic evolution of the GitHub Advanced Security environment and GitHub Copilot configuration, ensuring AI and security tools are tuned for maximum accuracy and minimal developer friction.
  • Secure AI Orchestration: Design and govern the use of Copilot autonomous agents (e.g., Copilot coding agents), ensuring that AI-generated code and pull requests meet enterprise security and quality standards before they reach human review.
  • Seamless Guardrails: Design and deploy automated scanning (CodeQL, Secrets, and Dependencies) that integrates natively into CI/CD workflows, leveraging AI-driven autofix capabilities to accelerate remediation.
  • Technical Advocacy: Act as a high-level partner for development teams, helping them navigate complex security findings and providing the technical clarity needed to securely adopt agentic workflows.
  • Pattern Recognition & AI Guidance: Identify recurring security trends and develop custom repository instructions to guide Copilot agents toward Wellmark’s specific coding standards and security patterns.
  • Risk Intelligence: Establish the metrics required to move our security posture from reactive to proactive, monitoring the impact of AI-assisted development on code quality and security debt.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service