Outseer logo
Outseer

More Signal. Less Noise.™

Principal Application Security Engineer

Application EngineerApplication EngineerFull TimeRemoteLeadTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

India

Posted

67 days ago

Salary

0

Seniority

Lead

Job Description

Principal Application Security Engineer

Outseer

• Drive the development and implementation of advanced security practices, policies, and frameworks to ensure the integrity and confidentiality of our applications. • Provide principal leadership to the application security program, helping set the strategic direction, goals, and objectives to enhance the overall security posture of our applications. • Develop and implement advanced application security practices, including secure coding standards, threat modeling methodologies, and secure software development lifecycle (SDLC) processes. • Conduct in-depth application security assessments, including code reviews, architecture reviews, and penetration testing, to identify and remediate complex security vulnerabilities and risks. • Collaborate closely with development teams, architects, and stakeholders to provide expert guidance on secure coding practices, security design principles, and the selection and implementation of security controls. • Define and maintain application security policies, standards, and guidelines, ensuring alignment with regulatory requirements and industry best practices. • Drive the integration of security into the CI/CD pipeline and automated security testing tools and processes to enable secure and efficient application development and deployment. • Evaluate and recommend emerging technologies, frameworks, and security tools to enhance application security capabilities, scalability, and efficiency. • Lead incident response efforts for application security incidents, working with cross-functional teams to investigate, contain, and remediate security breaches or vulnerabilities. • Stay current with the latest application security threats, vulnerabilities, and attack vectors, and provide strategic recommendations and guidance to mitigate emerging risks. • Serve as a subject matter expert and thought leader on application security, representing the organization in external forums, conferences, and industry working groups.

Job Requirements

  • Bachelor’s degree in computer science, Information Security, or a related field - or equivalent work experience
  • 10+ years of progressive experience in application security, with a focus on securing complex web and mobile applications
  • Extensive expertise in application security principles, secure coding practices, secure architecture design, and vulnerability assessment techniques
  • Strong knowledge of web and mobile application frameworks, languages, and technologies (e.g., Java, .NET, JavaScript, Python, Android, iOS)
  • Proven experience conducting advanced application security assessments, including code reviews, architecture reviews, and penetration testing
  • Deep understanding of web application security vulnerabilities (OWASP Top Ten), advanced attack techniques, and mitigation strategies
  • Demonstrated ability to develop and implement secure software development lifecycle (SDLC) processes and integrate security into DevOps and CI/CD practices
  • Expertise in cloud security concepts and practices, with hands-on experience in cloud-native environments (e.g., AWS, Azure, GCP)
  • Strong scripting or programming skills for automation and tooling (e.g., Python, Bash, PowerShell)
  • Professional certifications in application security (e.g., CSSLP, GWAPT, CISSP) and active participation in industry forums or associations are highly desirable.

Benefits

  • Equal employment opportunity for all employees
  • Work environment free of discrimination and harassment

Related Categories

Related Job Pages

More Application Engineer Jobs

Full TimeRemoteTeam 51-200Since 1991H1B No Sponsor

• Conduct international trainings for our primtech software solution (online, in-house or on-site) • Provide technical consulting by analyzing customer workflows and customizing/configuring our software • Present our software solution to customers and at trade shows • Support our primtech support team • Estimate effort and manage projects

Germany
RSA Security logo

Application Support Engineer

RSA Security

Identity-first solutions for security-first leaders.

Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Act as the primary technical liaison between customers and other departments to resolve application issues • Execute application sanity tests to ensure application health • Partner with technical teams to perform application patches and upgrades • Lead support case resolution efforts for prescribed customer cases • Collaborate with Customer Support, Escalation Engineering, and Cloud Operations to identify high priority application issues

India
Full TimeRemoteTeam 501-1,000Since 2018H1B No Sponsor

• Serve as the primary security resource for engineering teams in direct close coordination with information security teams, advising on design decisions, authentication patterns, and API security as features are built rather than after the fact • Conduct lightweight, developer-friendly threat modeling for new features and services, right-sized to the actual audience and risk profile (internal vs. public-facing) • Lead collaboration between engineering and information security teams through architecture and code reviews with actionable, specific guidance that helps teams ship, not slow down • Responsible for remediation and enforcement of security standards as set forth by the information security team • Define and maintain a tiered security standard that distinguishes expectations for internal tooling vs. production SaaS vs. public-facing products • Engage constructively with the enterprise security organization, translating between compliance and governance language and the engineering team's operational reality • Responsible for adherence to GitHub Advanced Security (GHAS) configuration and security standards through ongoing tuning across code scanning, secret scanning, Dependabot, and security campaigns within GitHub Enterprise • Integrate security tooling into CI/CD pipelines as policy-as-code feedback loops, not manual gates • Develop and maintain GitHub Actions workflows with reusable, security-enforcing components • Drive remediation velocity metrics and coverage reporting across engineering teams • Collaborate with information security teams to assess and secure workloads across both Cloudflare and Azure, including Cloudflare Workers, Access policies, WAF, and Zero Trust for public-facing infrastructure, and Azure security controls (Managed Identities, Key Vault, Defender, IAM) for internal and opco-facing services • Apply platform-appropriate security controls as our architecture spans both environments, calibrating to the risk profile of each workload • Evaluate and harden authentication flows, API security patterns, and service-to-service trust boundaries across Cloudflare and Azure environments • Contribute to container and cloud workload security as infrastructure patterns evolve • Contribute to internal security tooling, automation, and integrations using Python and/or Go • Build security utilities such as vulnerability aggregation pipelines, policy enforcement tooling, or developer-facing security dashboards • Collaborate with information security and engineering teams on secure service design patterns, OAuth 2.0/OIDC flows, and API security controls • Support SOC 2 readiness as the product matures toward public customers, mapping application security controls to Trust Services Criteria • Triage and prioritize vulnerability findings based on actual business risk rather than CVSS scores alone, distinguishing real issues from noise in a SaaS-native environment • Partner with GRC and the enterprise security organization on evidence collection and audit preparation, without allowing compliance prep to dominate engineering time

Colorado + 3 moreAll locations: Colorado | Montana | Vermont | Wyoming
BJC HealthCare logo

EHR Application II Analyst

BJC HealthCare

BJC HealthCare is one of the largest healthcare organizations in the U.S. focused on delivering "the world's best medicine," made better by its 30,000+ clinical

Additional Information About the Role BJC is hiring for an EHR Application II Analyst. Applicant must Professional Billing certified. We are looking for analyst experience. Knowledge of GL and AR is preferred. Remote position, but must be located in MO or IL. Overview BJC HealthCare is one of the largest nonprofit health care organizations in the United States, delivering services to residents primarily in the greater St. Louis, southern Illinois and southeast Missouri regions. With net revenues of $6.3 billion and more than 30,000 employees, BJC serves patients and their families in urban, suburban and rural communities through its 14 hospitals and multiple community health locations. Services include inpatient and outpatient care, primary care, community health and wellness, workplace health, home health, community mental health, rehabilitation, long-term care and hospice. BJC is the largest provider of charity care, unreimbursed care and community benefits in the state of Missouri. BJC and its hospitals and health service organizations provide $785.9 million annually in community benefit. That includes $410.6 million in charity care and other financial assistance to patients to ensure medical care regardless of their ability to pay. In addition, BJC provides additional community benefits through commitments to research, emergency preparedness, regional health care safety net services, health literacy, community outreach and community health programs and regional economic development. BJC’s patients have access to the latest advances in medical science and technology through a formal affiliation between Barnes-Jewish Hospital and St. Louis Children’s Hospital with the renowned Washington University School of Medicine, which consistently ranks among the top medical schools in the country. Preferred Qualifications Role Purpose Under moderate direction, the EHR Application Analyst II is responsible for configuring, modifying, testing, and maintaining Epic & other Clinical applications. Builds collaborative relationships with hospital leadership, clinical department users, technology and other corporate departments to facilitate usage and acceptance of the system. May be assigned to more complex build and configuration tasks and resolve advance issues. Provides second-tier support to end users to ensure reliable application system availability and performance. May be responsible for system integrity. Provides solutions or resolves end-user system issues. Epic or applicable certifications will be required within 6 months of hire. Responsibilities - Designs, verifies, documents, amends and refactors complex software configurations for deployment. Contributes to the selection of the software configuration methods, tools and techniques. Applies agreed standards and tools, to achieve well-engineered outcomes. Participates in reviews of own work and leads reviews of colleagues' work. - Investigates and resolves issues relating to applications. Follows agreed procedures to identify and resolve issues with applications. Uses application management software and tools to collect agreed performance statistics. Carries out agreed applications maintenance tasks. - Develops and executes test plans and test cases. Collaborates across parties involved in product, systems or service design and development to enable comprehensive test coverage. Analyses and reports on test activities, results, issues and risks, including the work of others. - Evaluates design options and prototypes to obtain user feedback on requirements of developing systems, products, services or devices. Selects appropriate tools and techniques to evaluate user experiences of systems, products, services or devices. - Ensures that incidents are handled according to agreed procedures.Prioritizes and diagnoses incidents. Investigates causes of incidents and seeks resolution. Escalates unresolved incidents.Documents and closes resolved incidents.Contributes to testing and improving incident management procedures. - May be part of an after-hours on-call rotation. Minimum Requirements Education - High School Diploma or GED Experience - 2-5 years Supervisor Experience - No Experience Preferred Requirements Education - Bachelor's Degree Experience - 5-10 years Benefits and Legal Statement BJC Total Rewards At BJC we’re committed to providing you and your family with benefits and resources to help you manage your physical, emotional, social and financial well-being. - Comprehensive medical, dental, vison, life insurance, and legal services available first day of the month after hire date - Disability insurance* paid for by BJC - Annual 4% BJC Automatic Retirement Contribution - 401(k) plan with BJC match - Tuition Assistance available on first day - BJC Institute for Learning and Development - Health Care and Dependent Care Flexible Spending Accounts - Paid Time Off benefit combines vacation, sick days, holidays and personal time - Adoption assistance To learn more, go to our Benefits Summary *Not all benefits apply to all jobs The above information on this description has been designed to indicate the general nature and level of work performed by employees in this position. It is not designed to contain or be interpreted as an exhaustive list of all responsibilities, duties and qualifications required of employees assigned to this job. Equal Opportunity Employer

United States