Job Closed
This listing is no longer active.
We save lives through cell therapy.
Senior Information Security Engineer
Location
United States
Posted
115 days ago
Salary
0
Seniority
Senior
Job Description
Senior Information Security Engineer
NMDP
• The Sr Information Security Engineer is responsible for designing, implementing, and continuously improving the technical security controls that protect internally developed applications, including cloud systems, containerized, and serverless workloads. • This role is a hands-on application security specialist who performs deep secure code reviews, leads threat modeling, and drives remediation of complex vulnerabilities across the SDLC. • Collaborating with other technical teams, this role ensures secure application development, deployment, and operation by assessing maturity, defining security requirements and guardrails, and delivering prioritized recommendations to improve pipeline controls, tooling, and integrations within the DevSecOps pipeline. • Key responsibilities include conducting application security assessments, guiding secure software development practices, and advancing the maturity of application security capabilities. • The Information Security Engineer partners with development, operations, and security teams to embed security into development practices and responds as a subject matter expert during application-related security incidents.
Job Requirements
- Bachelor’s degree in computer science, management information systems, or related field.
- Four years work experience in the areas of information security, systems or network administration, programming, or systems analysis may be substituted for a degree.
- Seven (7) or more years of experience in information security, software engineering, DevSecOps, SRE/Platform Engineering, or a closely related field.
- At least four (4) years of direct application security experience, including hands-on secure code review and vulnerability remediation guidance.
- Secure software development practices, secure software architecture principles, and common vulnerability classes with demonstrated ability to translate findings into practical engineering fixes.
- Cloud-native, containerized, and serverless security concepts; particularly AWS IAM and event-driven architectures.
- Demonstrated understanding of secure application development, DevSecOps practices, and application security technologies (e.g., SAST, DAST, SCA, container security).
- AI/ML security concepts relevant to internal AI development (data governance, model/inference service security, and common AI threat scenarios).
- Demonstrate experience with one or more of the following: Application Vulnerability Management, Identity and Access Management, and Data Loss Prevention process development, technical analysis and supporting technologies.
- Demonstrate understanding in forensic investigations, data recovery and the handling of digital evidence.
- Develop, implement, and maintain new or maturing security systems, protocols, and processes within a complex organization.
- Conduct security reviews and identify potential vulnerabilities and improvements in security design.
- Demonstrate excellent interpersonal skills in areas such as collaborative co-development, teamwork, facilitation, and negotiation.
- Excellent planning and organizational skills. An attitude of positive determination and accountability.
- Demonstrate strong troubleshooting and analytical skills.
- Able to work both independently and collaboratively in a demanding environment.
- Maintain extreme confidentiality of sensitive information.
Benefits
- NMDP offers regular, full-time employees medical, dental, vision, life and disability, accident/critical illness/hospital, well-being, legal, identity theft and pet benefits.
- Retirement, paid time off/holidays, leave and incentive plans are also offered to eligible employees.
- Please reference this link for more information: NMDP Benefit Information
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Leading the planning, installation and integration of the Guardicore product in diverse infrastructure environments • Working with customers throughout a delivery project life cycle from project management and architecture design to installation, configuration and documentation • Deploying and implementing network segmentation policies using our state of the art segmentation platform • Delivering advanced professional services such as customizations / training / expansions / configurations / optimizations • Working closely with Support and Engineering teams to quickly resolve any client issues and drive customer post-sales satisfaction
• Joining Alan as a Security Software Engineer team means you're at the forefront of protecting sensitive health data and ensuring our systems are resilient against threats. • Tech Foundations enables product crews and creates the environment to thrive—combining world-class infrastructure, intuitive developer experience, exquisite operational excellence, and built-in security to make shipping exceptional products effortless. • Infrastructure enablement for product crews (e.g. hosting improvements, CI/CD, scalability, multi-cloud architecture) • Security and compliance facilitation (e.g. authentication, encryption, threat protection) • Developer productivity enhancements (e.g. local environment setup, monorepo tooling, observability, tech stack evolution) • Design and development unification (e.g. design system, accessibility) • AI-assisted engineering enablement (e.g. agentic development, code assistants, MCP servers)
• Help people live in good health to 100 while helping employers feel proud, turning health benefits from a cost centre into their most valuable investment. • Connect all aspects of care (private, public, and direct to consumer) to create the most member-centric healthcare experience, reducing claims costs while generating new monetization opportunities. • Build the infrastructure, interfaces, and applications to provide first-class service to members, health professionals, and even themselves! • Engage in security to protect sensitive health data and ensure systems are resilient against threats. • Participate in designing and developing unification (e.g. design system, accessibility) and enhancements for developer productivity. • Contribute to a revisited multi-cloud strategy as the team grows significantly and elevate the security stack and posture with enhanced tools and processes.
• Drive the generation services and technologies business to meet or exceed quarterly and annual quota objectives in partnership with the account and domain teams. • Follows the Optiv Standardize Sales Operating Processes (SOPs) to achieve consistent success. • Understand and maintain knowledge of the client’s security environment, business operations, security needs, and risk appetite. • Identify a their security concerns and how they correlate to Optiv’s strategic solutions across the assigned domain and holistic cyber security programs. • Identify cross-sell and upsell opportunities across clients and Optiv's partner relationships. • Qualify lead and partner with internal colleagues to determine scope, proposal management, and follow through to closure. • Participate in sales opportunities across Optiv's entire portfolio. • Clearly articulate how the necessary elements of the Optiv technology and services portfolio meet the specific needs of the client stakeholders at the leadership level. • Stay abreast of industry trends, news, and maintain a broad understanding of the security landscape to facilitate thought leadership, support, analysis, and guidance to clients and internal Optiv groups. • Collaborate with service delivery to ensure the team has necessary supporting domain specialty materials that presents a consistent and comprehensive approach. • Effectively work with multiple client personas across the security team, as well as other relevant personas to develop security strategy and define roadmaps to execute on security strategy aligned business goals, budgetary spend, and metrics based on return of investment. • Maintain advisory relationships with key stakeholders at clients by facilitating thought leadership, support, information, and guidance in conjunction with sales partners. • Maintain strong working relationships with relevant Optiv technology partners, based on client spend, and Optiv focus. • Design and solution complete security programs to meet client objectives across technology and services including; facilitating new discussions by leveraging peer and industry network contacts performing requirements gathering analysis, and technology selection criteria coordinating demonstrations and security technology evaluations. • Interface and partner with the internal Optiv teams, particularly service delivery liaisons, to align client expectations with the entire Optiv solution portfolio to ensure service delivery excellence and client satisfaction. • Listen for client feedback and continually share with internal teams to evaluate and cultivate continuous improvement. • Participate in account planning, forecasting, and pipeline management activities. • Participate in managing and prioritizing the proposal process to create business proposals, contracts, and respond to RFI/RFP’s. • Actively pursue personal development by maintaining and obtaining technical capabilities, soft skills, and security specific knowledge through formal education, certification, and other avenues. • Proficient sales techniques; makes connections, facilitates meetings, reads the room, asks probing questions, overcomes objections, gains trust, maintains composure under pressure, positions solutions, and assist in finalization of sale.



