Senior Security Engineer - Secure SDLC

highmarkhealth

Pennsylvania

Hybrid

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and embed security into the software development lifecycle across the organization. You will design shift-left controls, drive vulnerability reduction, and automate the security toolchain while partnering with engineers to enable secure AI-assisted development at enterprise scale.

This role emphasizes proactive threat prevention, code review, and governance to protect patient data and support

Qualifications

  • Experience embedding security into the software development lifecycle.
  • Ability to design and enforce security guardrails across CI/CD.
  • Familiarity with AI-assisted development workflows.

Responsibilities

  • Design and implement shift-left security controls across development pipelines.
  • Lead vulnerability risk reduction through triage and remediation tracking.
  • Automate and optimize security toolchain and dashboards.
  • Serve as embedded security advisor to engineering teams.
  • Develop security training and reference architectures.

Skills

Security engineering
Shift-left security
DevSecOps collaboration
Threat modeling

Tools

SAST
DAST
Container scanning
Secret detection
AI/LLM security assessment

Job description

Company :
enGen Job Description :
JOB SUMMARY

***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***

Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software - not bolted on after the fact.

This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle - from the first line of code to production deployment.

If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations - this role is for you.

Build & Enforce Shift-Left Security Controls

Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.

Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards.

Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform.

Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization.

Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.

Drive Vulnerability Risk Reduction

Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.

Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production.

Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.

Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education.

Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.

Automate & Optimize the Security Toolchain

Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal.

Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains.

Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times.

Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy.

Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance.

Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.

Enable & Empower Developers

Serve as a trusted, embedded security advisor to engineering teams, providing hands‑on guidance, code review support, AI security consultation, and practical remediation recommendations.

Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels.

Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.

Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams.

Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, mo

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Shift-Left & AI Security
Senior Security Engineer - Shift-Left & AI Security

highmarkhealth • Pennsylvania

Hybrid
USD 140,000 - 190,000
Senior Security Engineer: Shift-Left SDLC & AppSec
Senior Security Engineer: Shift-Left SDLC & AppSec

Highmark Health • Jackson (MS)

On-site
USD 103,000 - 165,000
Senior Security Engineer: Shift-Left & Secure SDLC
Senior Security Engineer: Shift-Left & Secure SDLC

Highmark Health • Nashville (TN)

On-site
USD 103,000 - 165,000
Principal Security Engineer
Principal Security Engineer

Valley National Bank • Morristown (NJ)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Arizona

On-site
USD 120,000 - 190,000
Application Security Engineer
Application Security Engineer

Unisys • Rockville (MD)

On-site
USD 100,000 - 130,000
Senior AI Security Engineer
Senior AI Security Engineer

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

RedStream Technology • Charlotte (NC)

On-site
USD 120,000 - 150,000
Principal Application & AI Security Engineer
Principal Application & AI Security Engineer

DNV GL USA, INC. • Oakland (CA)

Hybrid
USD 180,000 - 240,000