Application Security Engineer

Baylor Miraca Genetics Laboratories, LLC

Georgia

Hybrid

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Baylor Genetics is seeking an Application Security Engineer to mature our security program across web, API, and data pipelines. You will embed Security by Design and Privacy by Design across the SDLC and partner with engineering to remediate findings.

You will drive secure coding practices, perform tests and audits, and report on risk to technical and executive audiences, ensuring HIPAA compliance and risk reduction across the organization.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field.
  • 3–5 years of experience in application security, DevSecOps, or security-focused software engineering.
  • Hands-on experience with SonarQube for static code analysis and security gating.
  • Experience with SAST, DAST, SCA, and IAST tooling in CI/CD pipelines.
  • Knowledge of OWASP Top 10, attack vectors, and secure coding in Java, C#/.NET, Python, JavaScript.
  • Familiarity with HIPAA, NIST, and GDPR compliance.

Responsibilities

  • Implement and manage static and dynamic code analysis tools (SonarQube, BURP) in CI/CD; triage and remediate findings.
  • Perform penetration tests and vulnerability assessments across web, API, and pipeline apps; drive remediation.
  • Develop and maintain a remediation program to address findings quickly and prioritise risk.
  • Evolve SDLC into a Secure SDLC by embedding Security by Design and Privacy by Design.
  • Guide secure coding, threat modeling, and secure architecture reviews for new features.
  • Generate reports on application security status, vulnerability management, and risk assessments for technical and executive audiences.
  • Collaborate with auditors during internal/external audits; draft security policies and procedures as needed.
  • Partner with IT, Privacy, Compliance, and business units to drive risk reduction.

Skills

Security testing
CI/CD security
SonarQube
Burp Suite
OWASP Top 10
Healthcare compliance

Education

Bachelor's degree in CS/Info Security

Tools

SonarQube
Burp Suite
SAST
DAST
SCA
IAST

Job description

JOB SUMMARY

Baylor Genetics is seeking an Application Security Engineer to build and mature our application security program, embedding security across the software development lifecycle (SDLC) and champion Security by Design principles. As a leader in clinical genetic testing, we handle highly sensitive patient data across our web, API, and pipeline applications, and this role is central to protecting that data and reducing risk.


The engineer will implement and manage static and dynamic code analysis tooling - including SonarQube and BURP - partner closely with engineering to remediate findings, and help close audit-identified gaps in secure coding, software composition analysis, and code review coverage. This role directly supports HIPAA compliance and organizational risk reduction. Scope may evolve as organizational needs change.


KEY RESPONSIBILITIES


  • Implement and manage static and dynamic code analysis, integrating SonarQube (and complementary SAST/DAST/SCA tools) into CI/CD pipelines and check-in scans, and partnering with engineering to triage and remediate findings.

  • Perform penetration tests and vulnerability assessments across web, API, and pipeline applications, and lead consistent, timely remediation of identified findings.

  • Develop and maintain a structured remediation program that addresses and resolves security findings quickly, consistently, and in priority order.

  • Evolve Baylor Genetics' SDLC into a Secure SDLC (SSDLC) by embedding Security by Design and Privacy by Design principles at every stage.

  • Integrate secure coding practices with development teams, providing guidance, threat modeling, and secure architecture reviews for new features and releases.

  • Generate regular reports on the status of application security initiatives, vulnerability management, and risk assessments for technical and executive audiences.

  • Collaborate with auditors during internal and external audits, providing explanations, evidence, and documentation, and drafting security policies and procedures as needed.

  • Partner cross-functionally with IT, Privacy, Compliance, and business units to support initiatives and drive measurable risk reduction.


QUALIFICATIONS

Required


  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field - or an equivalent combination of education and experience.

  • Minimum of 3-5 years of experience in application security, DevSecOps, or software engineering with a security focus.

  • Hands-on experience with SonarQube for static code analysis and code quality/security gating.

  • Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines.

  • Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript.

  • Familiarity with penetration testing, code review, and vulnerability management processes.

  • Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR.


Preferred


  • Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent.

  • Experience securing web applications, APIs, and cloud-native/containerized workloads.

  • Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect).

  • Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.


COMPETENCIES


  • Excellent written and verbal communication skills; ability to collaborate cross-functionally and present findings to varying audiences. Strong analytical and problem-solving skills with a risk-based mindset.

  • Effective written and verbal communication, able to translate technical risk for non-technical stakeholders.

  • Collaborative, cross-functional approach with the ability to influence engineering teams.

  • Detail-oriented, self-directed, and able to prioritize in a fast-moving environment.


PHYSICAL DEMANDS AND WORK ENVIRONMENT


  • Onsite/Hybrid role based in Houston, TX; primarily an office/laboratory-adjacent setting.

  • Frequently required to sit and use hand and finger dexterity for prolonged periods.

  • Occasional travel for meetings, conferences, or audits.


EEO STATEMENT

Baylor Genetics is proud to be an equal opportunity employer committed to fostering an inclusive and diverse workplace. We welcome and encourage applicants from all backgrounds to apply. We do not discriminate on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, pregnancy, childbirth, or any other status protected by applicable federal, state, or local law. If you need an accommodation during the application process, please contact our Human Resources team.


Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Baylor Genetics • United States

Hybrid
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Baylor Genetics • Houston (TX), Northern (KY)

Hybrid
USD 125,000 - 150,000
Sr Information Security Engineer
Sr Information Security Engineer

Baylor Genetics • Northern (KY)

Hybrid
USD 140,000 - 180,000
Sr. Software Engineer
Sr. Software Engineer

Baylor Genetics • Houston (TX)

Hybrid
USD 120,000 - 180,000
Sr Director Software Engineer
Sr Director Software Engineer

Baylor Genetics • Northern (KY)

Hybrid
USD 180,000 - 230,000
Sr. Software Engineer
Sr. Software Engineer

Baylorgenetics • Houston (TX)

Hybrid
USD 120,000 - 160,000
Head of Lab Technology Platforms
Head of Lab Technology Platforms

Baylor Genetics • Houston (TX), Northern (KY)

On-site
USD 180,000 - 240,000
Principal Software Engineer
Principal Software Engineer

Baylor Genetics • Houston (TX), Northern (KY)

On-site
USD 160,000 - 230,000
Clinical Development Coordinator
Clinical Development Coordinator

Baylor Miraca Genetics Laboratories LLC • United States

On-site
USD 65,000 - 88,000
Sr Bioinformatics Software Engineer
Sr Bioinformatics Software Engineer

Baylor Genetics • Northern (KY)

Hybrid
USD 140,000 - 180,000