A complete application in a minute — tailored resume and cover letter, ready to send.
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and embed security into the software development lifecycle across the organization. You will design shift-left controls, drive vulnerability reduction, and automate the security toolchain while partnering with engineers to enable secure AI-assisted development at enterprise scale.
This role emphasizes proactive threat prevention, code review, and governance to protect patient data and support
***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***
Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software - not bolted on after the fact.
This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle - from the first line of code to production deployment.
If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations - this role is for you.
Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.
Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards.
Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform.
Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization.
Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.
Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.
Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production.
Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.
Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.
Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.
Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal.
Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains.
Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times.
Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.
Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance.
Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.
Serve as a trusted, embedded security advisor to engineering teams, providing hands‑on guidance, code review support, AI security consultation, and practical remediation recommendations.
Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels.
Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.
Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams.
Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, mo