Senior Security Engineer Secure SDLC
Allendale County, SC - USA
Job Summary
JOB SUMMARY
***CANDIDATE MUST BEUS Citizen (due to contractual/access requirements)***
Highmark Health is seeking aSenior Security Engineerto join our Enterprise Application Security team and play apivotal rolein shaping how security is built into our software not bolted on after the fact.
This is ahigh-impact engineering rolefor a security professional who ispassionate about preventing vulnerabilities before they happen.You will be at the forefront of ourshift-left security strategy working directly alongside our engineering teams toembed security into every stage of the software development lifecycle from the first line of code to production deployment.
If you thrive at the intersection ofsecurity engineering & architecturedeveloper enablement & collaboration andautomation and you want tobuild something that matters at enterprise scalein one of the nations leading health and insurance organizations this role is for you.
Build & Enforce Shift-Left Security Controls
- Design and implement security guardrailsthat catch vulnerabilities at the earliest possible point in the development process including withinAI-assisted development workflows IDEs at commit time and within CI/CD pipelines.
- Configure and enforce pipeline security gatesacross the enterprise ensuring code AI-generated code infrastructure-as-code and deployment artifactscannot advance to production without meeting defined security standards.
- Deploy and manage application security scanners includingSAST Dependency Scanning Container Scanning Secret Detection DAST API Security Testing and emerging AI/LLM security assessment capabilitiesacross the enterprise development platform.
- Develop security-as-code policies and enforcement rulesthat scale across a large distributed engineering organization.
- Partner with Software Delivery Enablement teamsto establish security controls governance requirements and safe usage patterns forAI coding assistants AI agents and AI-enabled developer tooling.
Drive Vulnerability Risk Reduction
- Lead risk-based triage and prioritization of detected vulnerabilities leveraging exploitability signals such asEPSS scores Known Exploited Vulnerability (KEV) status reachability analysis and emerging AI-specific risk indicators.
- Establish and track remediation SLAsaligned to vulnerability severity and business risk with a focus oneliminating Critical and High findings before they reach production.
- Identify and remediate security risks associated with AI-generated code AI-enabled applications model integrations prompt injection vulnerabilities insecure agent behaviors and exposure of sensitive data to AI platforms.
- Conduct root cause analysison recurring vulnerability patterns and drivesystemic improvementsthrough tooling standards secure development practices and developer education.
- Monitor and report on key security health metricsincludingMean Time to Remediate (MTTR) security debt trends pre- versus post-production detection rates andAI security risk reduction metrics.
Automate & Optimize the Security Toolchain
- Architect and maintain the enterprise application security toolchain ensuring tools are properly integrated tuned and deliveringhigh-fidelity actionable signal.
- Evaluate onboard and operationalize emerging security technologiesthat improve visibility and governance overAI-assisted software development and software supply chains.
- Build automation workflowsfor vulnerability triage escalation assignment and reportingreducing manual overhead and accelerating response times.
- Continuously optimize scanner configurationsto minimize false positives and maximize detection accuracy.
- Develop dashboards and reporting pipelinesthat give engineering and security leadershipreal-time visibilityinto application security postureAI security adoption and policy compliance.
- Integrate security controls and monitoringinto approved AI development platforms coding assistants model gateways and agentic development workflows.
Enable & Empower Developers
- Serve as a trusted embedded security advisorto engineering teams providinghands-on guidance code review support AI security consultation and practical remediation recommendations.
- Design and deliver security training workshops and reference materialsthat makesecure coding secure AI development and responsible use of AI coding assistants accessible and actionablefor developers at all levels.
- Build and grow a Security Champions program embedding security advocates within engineering teams to extend the AppSec programs reach across the organization.
- Create and maintain secure coding standards secure AI development standards design patterns and reusable security librariesthat reduce security burden on development teams.
- Develop guidance and reference architecturesfor secure implementation ofLLMs AI copilots agentic workflows model integrations and AI-enabled business applications.
- Partner with development architecture and platform teamsto embedsecure-by-default AI development practicesthroughout the SDLC.
Measure Report & Continuously Improve
- Define track and report on AppSec KPIsthat demonstrate program effectiveness and drive continuous improvement.
- Establish and report on AI security metricssuch as AI tooling adoption policy compliance AI risk assessments completed AI-generated code review coverage and identified AI-related security findings.
- Conduct regular security posture reviewsand present findings trends and recommendations to engineering and security leadership.
- Support audit risk and compliance activitiesby ensuring security controlsAI governance requirements and secure development standards are documented measurable and consistently enforced.
- Benchmark program maturityagainst industry frameworks such asOWASP SAMM BSIMM OWASP Top 10 for LLM Applications and emerging AI security best practices driving year-over-year improvement.
- Continuously assess emerging threats vulnerabilities and attack techniquesaffecting modern software delivery pipelines software supply chains andAI-enabled applications.
Assist in AI Application Security & Governance
- Assist with security reviews and threat modelingforAI-enabled applications LLM integrations AI agents and AI-assisted development platforms.
- Collaborate with Security Architectureto recommend and establish technical controls and guardrails supportingenterprise AI governance requirements.
- Evaluate security risks associated with AI models prompts training data model supply chains MCP integrations and agentic workflows.
- Partner with Architecture ISRM and Software Delivery Enablement teamsto definesecure AI development standards and implementation patternsacross the enterprise.
Preferred Qualifications
- Experience withGitLab Ultimate security featuresincluding Vulnerability Reports Security Policies Compliance Frameworks and security controls supporting AI-assisted development workflows.
- Deep proficiency with application security scanning toolsincludingSAST DAST SCA/Dependency Scanning Container Scanning Secret Detection API Security Testing and emergingAI application security assessment capabilities.
- Deep proficiency with JFrog security and compliance toolssuch asXray and Curation including Policies Watches Impact Analysis Software Supply Chain controls and reporting.
- Familiarity withthreat modeling methodologiessuch asSTRIDE PASTA and their application toAI-enabled systems LLM integrations and agentic workflows.
- Working knowledge of commonAI security risksincludingprompt injection insecure output handling excessive agency retrieval risks model poisoning training data exposure sensitive data leakage and model supply chain threats.
- Experience designing or reviewingsecurity controls for AI-enabled applications AI assistants AI agents or LLM integrations.
- Knowledge of healthcare or financial services regulatory frameworks includingHIPAA PCI-DSS SOC 2 NIST CSF NIST AI RMF or equivalent governance frameworks.
- Industry certifications such asCSSLP GWEB GWAPT OSCP AI Security certifications or equivalent.
- Prior experience as a software developer.We strongly value candidates who understand what its like to be on the other side of a security finding and can balance security delivery and developer experience.
- Experience coordinating or conductingpenetration testing red team exercises AI security assessments and application threat modeling engagements.
- Experience establishing security controls and governance requirements forAI-assisted software development platforms(e.g. GitLab Duo GitHub Copilot Claude Code Cursor MCP-based tooling or equivalent) within a large enterprise environment.
ESSENTIAL RESPONSIBILITIES
Lead teams in clearly defining requirements deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience.
Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure.
Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties.
Complete project tasks to enable the on time within budget and scope delivery of ISRM Infrastructure projects.
Implement monitor configure and maintain security systems.
Assure compliance to required standards procedures guidelines and processes.
Other duties as assigned or requested.
REQUIRED EDUCATION
- Bachelors Degree in Computer Science Information Systems or closely related field
Substitutions
- None
PREFERRED EDUCATION
- Masters Degree in Computer Science Information Security or related field
EXPERIENCE
Required
7 years with Information Security and Systems Analysis
7 years with Information Security and/or Information Risk Management and/or Information Technology
7 years with Operating Systems and Software Administration
7 years developing communicating and presenting Information Security and Risk Management concepts to varying audiences
7 years with technologies such as Intrusion Prevention Systems (IPS) firewalls endpoint protection web/email filtering Data Loss Prevention (DLP) digital rights management encryption Security Event and Incident Management (SEIM) and virtualization platforms
Preferred:
10 years with Information Security and Systems Analysis
7 years in IT / Information Security Risk advisory
7 years in-depth understanding of network security architecture network and networking protocols
7 in Database Management System Administration and Software Development Life-Cycle
3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF) or the NIST 800-83 cyber security framework
SKILLS
Knowledge of HITRUST CSF NIST 800-83 cyber security framework PCI HIPAA HITECH COBIT ISO 27001/2 and ITIL 3
Familiarity with secure SDLC best practices
Knowledge of Microsoft Apps and Suites Windows server SharePoint etc.
Strong teamwork and inter-personal skills
Additional Skills:
Hands-on experience with CI/CD platforms such as GitLab GitHub Actions Jenkins or equivalent including security policy enforcement and pipeline governance.
- Proficiency in at least one scripting or programming language (Python Go Bash or equivalent) for security automation workflow development and security tooling integrations.
- Familiarity with container and cloud-native security concepts including Docker Kubernetes cloud provider security services and modern platform engineering practices.
- Ability to conduct focused secure code reviews and security architecture reviews across both human-authored and AI-generated code.
- Experience evaluating security implications of AI coding assistants AI agents MCP-enabled tooling and AI-powered developer platforms.
- Understanding of secure AI development principles including governance controls for AI-generated code model consumption prompt handling data protection and human review requirements.
- Preparing and delivering regular security posture briefings to engineering and security leadership including trend analysis KPI performance risk summaries AI security metrics and forward-looking recommendations.
- Configuring and managing SCA tools (GitLab Dependency Scanning OWASP Dependency-Check JFrog Xray or equivalent) across multiple package ecosystems.
- Generating maintaining and interpreting Software Bills of Materials (SBOMs) in CycloneDX or SPDX formats.
- Applying container security best practices including minimal base images non-root execution read-only filesystems image signing and software supply chain verification.
- Designing security gates that prevent non-compliant code dependencies containers or deployment artifacts from advancing through the pipeline while minimizing developer friction (GitLab JFrog Xray or equivalent).
- Experience implementing or supporting software supply chain security controls including artifact governance package repository management dependency trust validation and build integrity protections.
- Knowledge of industry frameworks and guidance related to AI and application security including OWASP Top 10 for LLM Applications OWASP SAMM BSIMM NIST Secure Software Development Framework (SSDF) and NIST AI Risk Management Framework (AI RMF).
- Ability to partner with Architecture Software Delivery Enablement Engineering and Risk Management teams to define and operationalize secure AI development standards and guardrails.
LICENSES or CERTIFICATIONS
Required
- None
PREFERRED
- Certified Information Systems Security Professional (CISSP) Security
LANGUAGE REQUIREMENT (other than English)
None
TRAVEL REQUIREMENT:
0% - 25%
PHYSICAL MENTAL DEMANDS AND WORKING CONDITIONS
Position Type:
Office-Based
Office-Based Positions
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties responsibilities and qualifications required of employees to do this job.
Compliance Requirement: This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities employees may have access to covered information cardholder data or other confidential customer information that must be protected at all connection with this all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Companys Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore it is every employees responsibility to comply with the companys Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws rules and regulations as well as company policies and training requirements.
Pay Range Minimum:
$102700.00Pay Range Maximum:
$164600.00Base pay is determined by a variety of factors including a candidates qualifications experience and expected contributions as well as internal peer equity market and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal state or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process please contact the email below.
For accommodation requests please contact HR Services Online at
California Consumer Privacy Act Employees Contractors and Applicants Notice
Required Experience:
Senior IC