Senior Security Engineer - Secure SDLC

Highmark HealthWashington, NV
$102,700 - $164,600Onsite

About The Position

Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team. This role is pivotal in shaping how security is built into our software, focusing on preventing vulnerabilities before they happen. The engineer will be at the forefront of the shift-left security strategy, working directly with engineering teams to embed security throughout the software development lifecycle, from coding to production deployment. This is a high-impact role for a security professional passionate about security engineering, architecture, developer enablement, collaboration, and automation, aiming to build secure systems at an enterprise scale within a leading health and insurance organization.

Requirements

  • US Citizen (due to contractual/access requirements)
  • 7 years with Information Security and Systems Analysis
  • 7 years with Information Security and/or Information Risk Management and/or Information Technology
  • 7 years with Operating Systems and Software Administration
  • 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
  • 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms
  • Bachelor's Degree in Computer Science, Information Systems, or closely related field
  • Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3
  • Familiarity with secure SDLC best practices
  • Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc.
  • Strong teamwork and inter-personal skills
  • Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins, or equivalent, including security policy enforcement and pipeline governance.
  • Proficiency in at least one scripting or programming language (Python, Go, Bash, or equivalent) for security automation, workflow development, and security tooling integrations.
  • Familiarity with container and cloud-native security concepts including Docker, Kubernetes, cloud provider security services, and modern platform engineering practices.
  • Ability to conduct focused secure code reviews and security architecture reviews across both human-authored and AI-generated code.
  • Experience evaluating security implications of AI coding assistants, AI agents, MCP-enabled tooling, and AI-powered developer platforms.
  • Understanding of secure AI development principles, including governance controls for AI-generated code, model consumption, prompt handling, data protection, and human review requirements.
  • Preparing and delivering regular security posture briefings to engineering and security leadership, including trend analysis, KPI performance, risk summaries, AI security metrics, and forward-looking recommendations.
  • Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, JFrog Xray, or equivalent) across multiple package ecosystems.
  • Generating, maintaining, and interpreting Software Bills of Materials (SBOMs) in CycloneDX or SPDX formats.
  • Applying container security best practices including minimal base images, non-root execution, read-only filesystems, image signing, and software supply chain verification.
  • Designing security gates that prevent non-compliant code, dependencies, containers, or deployment artifacts from advancing through the pipeline while minimizing developer friction (GitLab, JFrog Xray, or equivalent).
  • Experience implementing or supporting software supply chain security controls including artifact governance, package repository management, dependency trust validation, and build integrity protections.
  • Knowledge of industry frameworks and guidance related to AI and application security, including OWASP Top 10 for LLM Applications, OWASP SAMM, BSIMM, NIST Secure Software Development Framework (SSDF), and NIST AI Risk Management Framework (AI RMF).
  • Ability to partner with Architecture, Software Delivery Enablement, Engineering, and Risk Management teams to define and operationalize secure AI development standards and guardrails.

Nice To Haves

  • Experience with GitLab Ultimate security features including Vulnerability Reports, Security Policies, Compliance Frameworks, and security controls supporting AI-assisted development workflows.
  • Deep proficiency with application security scanning tools including SAST, DAST, SCA/Dependency Scanning, Container Scanning, Secret Detection, API Security Testing, and emerging AI application security assessment capabilities.
  • Deep proficiency with JFrog security and compliance tools such as Xray and Curation, including Policies, Watches, Impact Analysis, Software Supply Chain controls, and reporting.
  • Familiarity with threat modeling methodologies such as STRIDE, PASTA, and their application to AI-enabled systems, LLM integrations, and agentic workflows.
  • Working knowledge of common AI security risks including prompt injection, insecure output handling, excessive agency, retrieval risks, model poisoning, training data exposure, sensitive data leakage, and model supply chain threats.
  • Experience designing or reviewing security controls for AI-enabled applications, AI assistants, AI agents, or LLM integrations.
  • Knowledge of healthcare or financial services regulatory frameworks including HIPAA, PCI-DSS, SOC 2, NIST CSF, NIST AI RMF, or equivalent governance frameworks.
  • Industry certifications such as CSSLP, GWEB, GWAPT, OSCP, AI Security certifications, or equivalent.
  • Prior experience as a software developer.
  • Experience coordinating or conducting penetration testing, red team exercises, AI security assessments, and application threat modeling engagements.
  • Experience establishing security controls and governance requirements for AI-assisted software development platforms (e.g., GitLab Duo, GitHub Copilot, Claude Code, Cursor, MCP-based tooling, or equivalent) within a large enterprise environment.
  • Master's Degree in Computer Science, Information Security or related field
  • 10 years with Information Security and Systems Analysis
  • 7 years in IT / Information Security Risk advisory
  • 7 years in-depth understanding of network security architecture, network and networking protocols
  • 7 in Database Management, System Administration and Software Development Life-Cycle
  • 3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
  • Certified Information Systems Security Professional (CISSP), Security +

Responsibilities

  • Design and implement security guardrails to catch vulnerabilities early in the development process, including in AI-assisted development, IDEs, commit time, and CI/CD pipelines.
  • Configure and enforce enterprise-wide pipeline security gates to ensure code, AI-generated code, infrastructure-as-code, and deployment artifacts meet security standards before production.
  • Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, AI/LLM security assessment capabilities).
  • Develop security-as-code policies and enforcement rules for a large, distributed engineering organization.
  • Partner with Software Delivery Enablement teams to establish security controls, governance, and safe usage patterns for AI coding assistants, agents, and developer tooling.
  • Lead risk-based triage and prioritization of vulnerabilities using exploitability signals (EPSS, KEV, reachability, AI-specific risks).
  • Establish and track remediation SLAs aligned with vulnerability severity and business risk, focusing on eliminating Critical and High findings before production.
  • Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection, insecure agent behaviors, and sensitive data exposure to AI platforms.
  • Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.
  • Monitor and report on key security health metrics (MTTR, security debt, pre- vs. post-production detection rates, AI security risk reduction).
  • Architect and maintain the enterprise application security toolchain, ensuring integration, tuning, and high-fidelity signal delivery.
  • Evaluate, onboard, and operationalize emerging security technologies for AI-assisted development and software supply chains.
  • Build automation workflows for vulnerability triage, escalation, assignment, and reporting.
  • Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
  • Develop dashboards and reporting pipelines for real-time visibility into application security posture, AI security adoption, and policy compliance.
  • Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic workflows.
  • Serve as an embedded security advisor to engineering teams, providing guidance, code review support, AI security consultation, and remediation recommendations.
  • Design and deliver security training, workshops, and materials on secure coding, secure AI development, and responsible AI usage.
  • Build and grow a Security Champions program to extend AppSec program reach.
  • Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries.
  • Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled applications.
  • Partner with development, architecture, and platform teams to embed secure-by-default AI development practices.
  • Define, track, and report on AppSec KPIs to demonstrate program effectiveness and drive continuous improvement.
  • Establish and report on AI security metrics (AI tooling adoption, policy compliance, AI risk assessments, AI-generated code review coverage, AI-related findings).
  • Conduct regular security posture reviews and present findings, trends, and recommendations to leadership.
  • Support audit, risk, and compliance activities by documenting, measuring, and enforcing security controls, AI governance, and secure development standards.
  • Benchmark program maturity against industry frameworks (OWASP SAMM, BSIMM, OWASP Top 10 for LLM Applications) and drive improvement.
  • Continuously assess emerging threats, vulnerabilities, and attack techniques affecting modern software delivery, supply chains, and AI-enabled applications.
  • Assist with security reviews and threat modeling for AI-enabled applications, LLM integrations, AI agents, and AI-assisted development platforms.
  • Collaborate with Security Architecture to recommend and establish technical controls and guardrails for enterprise AI governance.
  • Evaluate security risks associated with AI models, prompts, training data, model supply chains, MCP integrations, and agentic workflows.
  • Partner with Architecture, ISRM, and Software Delivery Enablement teams to define secure AI development standards and implementation patterns.
  • Lead teams in defining requirements, deliverables, and timeframes; escalate issues and make recommendations.
  • Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
  • Develop and/or deliver technical training in complex technical areas and mentor less senior staff.
  • Complete project tasks for on-time, within-budget, and in-scope delivery of ISRM Infrastructure projects.
  • Implement, monitor, configure, and maintain security systems.
  • Assure compliance with required standards, procedures, guidelines, and processes.
  • Other duties as assigned or requested.

Benefits

  • Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service