AVP Cybersecurity

Ensemble Health Partners

Kentucky

On-site

USD 180,000 - 240,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ensemble Health Partners seeks an AVP, Application Security (DevSecOps) to build, run, and mature the organization's AppSec program while remaining an active technical contributor.

You will own secure SDLC strategy, DevSecOps tooling, vulnerability management, and mentor engineers, performing architecture reviews and threat modeling as needed. You’ll partner with engineering, product, and infrastructure leaders to embed security across the software lifecycle and report risk posture to leadership.

Qualifications

  • Experience building and maturing an application security program.
  • Hands-on security leadership experience in SDLC, DevSecOps, and vulnerability triage.
  • Ability to mentor security engineers and collaborate with cross-functional teams.
  • Experience performing security architecture reviews and threat modeling.

Responsibilities

  • Build, lead, and mature the AppSec/DevSecOps program across secure SDLC, SAST/DAST/SCA, container and cloud security, and API security.
  • Perform hands-on secure code reviews, threat modeling, architecture reviews, and remediation guidance with engineers.
  • Mentor and develop AppSec engineers and security champions.
  • Design, implement, and tune the AppSec toolchain and integrate security gates into CI/CD pipelines.
  • Own the vulnerability management program, triage, prioritize, and drive remediation of critical findings.
  • Partner with engineering, product, and architecture to embed security requirements early in design (shift-left).
  • Develop and maintain AppSec policies, secure coding standards, and DevSecOps playbooks; train staff accordingly.
  • Manage third-party and open-source risk including SBOMs and remediation of vulnerable dependencies.
  • Report on AppSec risk posture and program metrics to leadership.

Skills

Valuing Differences
Collaboration
Accountability
Time Management
Developing Trust
Takes Initiative

Job description

Thank you for considering a career at Ensemble!

Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.

Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference!

O.N.E Purpose:
  • Customer Obsession: Consistently provide exceptional experiences for our clients, patients, and colleagues by understanding their needs and exceeding their expectations.

  • Embracing New Ideas: Continuously innovate by embracing emerging technology and fostering a culture of creativity and experimentation.

  • Striving for Excellence: Execute at a high level by demonstrating our “Best in KLAS” Ensemble Difference Principles and consistently delivering outstanding results.

The Opportunity:

The AVP, Application Security (DevSecOps) is a working, hands-on leader who builds, runs, and matures the organization's application security program while remaining an active technical contributor. This role owns secure software development lifecycle (SDLC) strategy, DevSecOps tooling and automation, and application-layer vulnerability management, while also mentoring engineers and security team members and personally performing security architecture reviews, threat modeling, and critical vulnerability triage when needed. The Director partners closely with engineering, product, and infrastructure leaders to embed security into every stage of the software development lifecycle and reports on application risk posture to executive leadership.

Job Competencies
  • Valuing Differences - Works effectively with individuals of diverse cultures, interpersonal styles, abilities, motivations, or backgrounds; seeks out and uses unique abilities, insights, and ideas. Considers the collective.
  • Collaboration - Works cooperatively within teams and partners with others, both internally and externally as needed, to achieve success; focuses on the results of the team, not the achievements of one person. It’s “All for One and One for All”
  • Accountability - Accepts personal responsibility and/or consequences of failure and successes, delivering on commitments and refocusing effort when needed. Someone who is willing to step up and own it.
  • Time Management - Effectively manages personal time and resources to ensure that work is completed efficiently.
  • Developing Trust - Gains others’ confidence by acting with integrity and following through on commitments; treats others and their ideas with respect and supports them in the face of challenges
  • Takes Initiative - Takes prompt action to accomplish goals and achieve results beyond what is required; is proactive and pursues relentlessly.
Essential Job Functions
  • Build, lead, and continuously mature a comprehensive application security (AppSec) and DevSecOps program spanning secure SDLC, SAST/DAST/SCA, container and cloud-native security, and API security.
  • Serve as a working, hands‑on member of the team: perform secure code reviews, threat modeling, security architecture reviews, and hands‑on remediation guidance alongside individual contributors, not just through delegation.
  • Mentor and develop application security engineers and embedded security champions, providing technical guidance, pairing on complex issues, and building the team's long-term technical capability.
  • Design, implement, and tune the AppSec toolchain (e.g., SAST, DAST, SCA, container scanning, secrets detection) and integrate security gates into CI/CD pipelines in partnership with engineering teams.
  • Own the application vulnerability management program, including triage, prioritization, remediation SLAs, and escalation of critical findings, personally leading response on high‑severity issues.
  • Partner with engineering, product, and architecture teams to embed security requirements and threat modeling into the design phase of new products and features (“shift‑left”).
  • Develop and maintain application security policies, secure coding standards, and DevSecOps playbooks, and train engineering staff on secure development practices.
  • Manage third‑party and open‑source software risk, including software composition analysis and remediation of vulnerable dependencies.
  • Report on application security risk posture, program metrics
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, Application Security & DevSecOps
Senior Director, Application Security & DevSecOps

Ensemble Health Partners • Kentucky

On-site
USD 180,000 - 240,000
Senior Analyst, Cybersecurity
Senior Analyst, Cybersecurity

Ensemble Health Partners • Cincinnati (OH)

On-site
USD 90,000 - 130,000
Director, IT Security
Director, IT Security

Talanto • Northern (KY)

Hybrid
USD 141,000 - 223,000
Senior Application Security Engineer
Senior Application Security Engineer

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Staff Engineer, Application Security
Staff Engineer, Application Security

BetterCloud • Buffalo (NY)

On-site
USD 110,000 - 170,000
AVP Cybersecurity
AVP Cybersecurity

Triwill Group • Northern (KY)

Hybrid
USD 180,000 - 240,000
Application Security Manager
Application Security Manager

Alter Domus • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Flexible arrangements
Generous holidays
Employee Share Plan
DevOps Engineer I
DevOps Engineer I

Talanto • Northern (KY)

Hybrid
USD 75,000 - 115,000
Bonus plan
Benefits package
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Senior Application Security Engineer
Senior Application Security Engineer

Compunnel, Inc. • Dallas (TX)

On-site
USD 100,000 - 130,000