Turn this role into an interview — a resume and cover letter built around what this employer wants.
enGen is seeking a Senior Security Engineer to join our Enterprise Application Security team. You will embed security into every stage of the software development lifecycle, from code to deployment, focusing on shift-left practices and proactive vulnerability prevention.
This high-impact role emphasizes security engineering, architecture, and automation to enable developers while reducing security risk across the enterprise stack.
enGen
CANDIDATE MUST BE US Citizen (due to contractual/access requirements)
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact.
This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment.
If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.
Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.
Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards.
Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform.
Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization.
Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.
Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.
Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production.
Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.
Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.
Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.
Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal.
Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains.
Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times.
Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance.
Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.
Serve as a trusted, embedded security advisor to engineering teams, providing hands-on guidance, code review support, AI security consultation, and practical remediation recommendations.
Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels.
Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.
Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams.
Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications.
Partner with development, architecture, and platform teams to embed secure-by-default AI development practices throughout the SDLC.
Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement.
Establish and report on AI security metrics such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings.
Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership.
Support audit, risk, and compliance activities by ensuring security controls, AI governance requirements , and secure development standards are documented, measurable, and consistently enforced.
Benchmark program maturity against industry frameworks such as OWASP SAMM, BSIMM, OWASP Top 10 for LLM Applications , and emerging AI security best practices, driving year-over-year improvement.
Continuously assess emerging threats, vulnerabilities, and attack techniques affecting modern software delivery pipelines, software supply chains, and AI-enabled applications.
Assist with security reviews and threat modeling for AI-enabled applications, LLM integrations, AI agents, and AI-assisted development platforms.
Collaborate with Security Architecture to recommend and establish technical controls and guardrails supporting enterprise AI governance requirements.
Evaluate security risks associated with AI models, prompts, training data, model supply chains, MCP integrations, and agentic workflows.
Partner with Architecture, ISRM, and Software Delivery Enablement teams to define secure AI development standards and implementation patterns across the enterprise.
None
0% - 25%
Office-Based
Teaches/Trains others regularly
Occasionally
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.
This position adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies
As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.
$102,700.00
$164,600.00
Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets.
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J285561