We believe no one should navigate healthcare alone.
Application Security Principal
Location
Ohio
Posted
22 days ago
Salary
0
Seniority
Senior
Job Description
Application Security Principal
Quantum Health
Title: Application Security Principal Location: Dublin, Ohio Department: Information Technology Job Description: Description Who we are Founded in 1999 and headquartered in Central Ohio, we’re a privately-owned, independent healthcare navigation organization. We believe that no one should have to navigate the cost and complexity of healthcare alone, and we’re on a mission to make healthcare simpler and more effective for our millions of members. Our big-hearted, tech-savvy team fights to ensure that our members get the care they need, when they need it, at the most affordable cost – that’s why we call ourselves Healthcare Warriors®. We’re committed to building diverse and inclusive teams – more than 2,000 of us and counting – so if you’re excited about this position, we encourage you to apply – even if your experience doesn’t match every requirement. About the role The Application Security Principal is a senior, hands-on security leader who reports directly to the Chief Information Security Officer (CISO) and is responsible for building, operating, and continuously improving the enterprise Application Security (AppSec) program. The role is deeply embedded within software engineering initiatives, working side-by-side with development teams to enable secure-by-design and secure-by-default software delivery. This leader focuses on teaching, mentoring, and influencing engineers to write secure code and to effectively use modern AppSec tools and automation to reduce risk while maintaining delivery velocity. The role operates in a regulated healthcare environment and ensures alignment with HIPAA and HITRUST requirements. Location: This position is located at our Dublin, OH campus or may work remotely anywhere in the United States of America. What you’ll do (Essential Responsibilities) - Create, own, and drive the enterprise Application Security program, including vision, strategy, roadmap, and operating model. - Embed within software engineering projects to provide hands-on guidance for secure design, coding, testing, and deployment practices. - Teach, mentor, and lead software engineers to improve secure coding skills and security decision-making throughout the SDLC. - Define and operationalize a secure SDLC, including threat modeling, secure design reviews, automated security testing, and release controls. - Own and optimize application security tooling and workflows, including Snyk, SonarCloud, GitHub Advanced Security, GitHub Copilot, Palisade, and related CI/CD integrations. - Establish developer-friendly remediation workflows, including prioritized findings, fix guidance, and automation where possible. - Partner with Engineering and Product leadership to align application security priorities with business objectives and delivery timelines. - Lead threat modeling and architectural risk assessments for new applications, APIs, and major enhancements. - Develop and track AppSec metrics and KPIs that demonstrate risk reduction, coverage, and program effectiveness. - Ensure application security controls and practices meet HIPAA Security Rule and HITRUST CSF requirements and support audit readiness. - Collaborate with infrastructure, cloud, and enterprise security teams on identity, secrets management, and secure platform patterns. - Support security incident response activities related to application vulnerabilities and contribute to root-cause analysis and long-term remediation. - Build and lead an application security champions or guild program to scale secure development practices across teams. - All other duties as assigned. What you’ll bring (Qualifications) - Experience: Extensive experience designing and leading application security programs within complex enterprise environments. - Strong background in software engineering with the ability to read, review, and reason about code for security issues. - Hands-on experience integrating and operating modern AppSec tools such as Snyk, SonarCloud, GitHub Advanced Security, and CI/CD pipelines. - Experience guiding developers in the effective and responsible use of AI-assisted development tools such as GitHub Copilot. - Deep understanding of secure SDLC principles, threat modeling methodologies, and common application vulnerability classes. - Experience securing cloud-native, API-driven, and microservices-based architectures. - Strong knowledge of healthcare regulatory requirements, including HIPAA and HITRUST, and their application to software development. - Proven ability to influence without authority and to build strong partnerships with engineering and product teams. - Excellent communication and teaching skills, with the ability to translate security concepts into practical developer guidance. - Demonstrated leadership, program management, and strategic planning capabilities. - A high degree of personal accountability and trustworthiness, a commitment to working within Quantum Health’s policies, values and ethics, and protecting the sensitive data entrusted to us. -- #LI-AK1 #LI-Hybrid #LI-Remote What’s in it for you - Compensation: Competitive base and incentive compensation - Coverage: Health, vision and dental featuring our best-in-class healthcare navigation services, along with life insurance, legal and identity protection, adoption assistance, EAP, Teladoc services and more. - Retirement: 401(k) plan with up to 4% employer match and full vesting on day one. - Balance: Paid Time Off (PTO), 7 paid holidays, parental leave, volunteer days, paid sabbaticals, and more. - Development: Tuition reimbursement up to $5,250 annually, certification/continuing education reimbursement, discounted higher education partnerships, paid trainings and leadership development. - Culture: Recognition as a Best Place to Work for 15+ years, dedication to diversity, philanthropy and sustainability, and people-first values that drive every decision. - Environment: A modern workplace with a casual dress code, open floor plans, full-service dining, free snacks and drinks, complimentary 24/7 fitness center with group classes, outdoor walking paths, game room, notary and dry-cleaning services and more! What you should know - Internal Associates: Already a Healthcare Warrior? Apply internally through Jobvite. - Process: Application > Phone Screen > Online Assessment(s) > Interview(s) > Offer > Background Check. - Diversity, Equity and Inclusion: Quantum Health welcomes everyone. We value our diverse team and suppliers, we’re committed to empowering our ERGs, and we’re proud to be an equal opportunity employer . - Tobacco-Free Campus: To further enable the health and wellbeing of our associates and community, Quantum Health maintains a tobacco-free environment. The use of all types of tobacco products is prohibited in all company facilities and on all company grounds. - Compensation Ranges: Compensation details published by job boards are estimates and not verified by Quantum Health. Details surrounding compensation will be disclosed throughout the interview process. Compensation offered is based on the candidate’s unique combination of experience and qualifications related to the position. - Sponsorship: Applicants must be legally authorized to work in the United States on a permanent and ongoing future basis without requiring sponsorship. - Agencies: Quantum Health does not accept unsolicited resumes or outreach from third-parties. Absent a signed MSA and request/approval from Talent Acquisition to submit candidates for a specific requisition, we will not approve payment to any third party. Recruiting Scams: Unfortunately, scams targeting job seekers are common. To protect our candidates, we want to remind you that authorized representatives of Quantum Health will only contact you from an email address ending in @quantum-health.com. Quantum Health will never ask for personally identifiable information such as Date of Birth (DOB), Social Security Number (SSN), banking/direct/tax details, etc. via email or any other non-secure system, nor will we instruct you to make any purchases related to your employment. If you believe you’ve encountered a recruiting scam, report it to the Federal Trade Commission and your state’s Attorney General.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Supervisor - Cyber Security
FleishmanHillardFleishmanHillard is an international, full-service communications firm offering brand marketing, crisis management, digital, social, media relations, public aff
Title: Account Supervisor - Cyber Security Location: New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United States; Washington, District of Columbia, United States Overview FleishmanHillard is the world’s most complete global communications firm, specializing in public relations, public affairs, marketing, paid media, and transmedia and social content. FleishmanHillard delivers on The power of true, reflecting the firm’s high values and unique ability to guide clients through a world demanding unprecedented authenticity and transparency. The San Francisco, DC, NY and Seattle offices have an immediate opening for an Account Supervisor to join us in a hybrid role in our rapidly expanding technology advisory practice. This position is ideal for someone who is energized by helping enterprise technology and cyber security companies differentiate not just through product hype, but through authentic storytelling that builds belief with key stakeholder audiences: investors, employees, policymakers, talent markets, and society. In this position, you'll lead the development and execution of media-first but not media-only communications programs that help reposition clients as strategic leaders rather than product vendors. Working collaboratively with senior team members and mentoring junior team members, you'll execute integrated communications campaigns that drive results. You’ll combine hands-on execution with the opportunity to shape how your clients lead authentically. FleishmanHillard values the importance of impact and inclusion to strengthen the bonds between us, grow our people and create spaces for everyone to thrive. We stay true to our commitment to our people and the communities in which we live and work. As part of our ongoing effort to be the world’s most inclusive agency, we are committed to seeking candidates who possess and demonstrate a profound interest in furthering our impact and inclusion goals. Responsibilities - Partner with senior team members to develop and execute communications strategies for mid-market and enterprise technology and cyber security clients, helping them build stakeholder confidence and differentiate competitively through authentic positioning. - Build and maintain media relationships by identifying appropriate media contacts, conducting regular outreach, scheduling interviews, and fostering strong connections with journalists in technology and business media. - Collaborate with senior team members and peers to develop strategic messaging frameworks and storytelling angles that translate complex technical innovation into clear, differentiated positioning for target audiences. - Manage day-to-day client relationships, synthesizing research and market intelligence to guide clients toward effective communication strategies. Take ownership of account execution while escalating strategic considerations to senior team members. - Develop messaging strategies and pitch angles that help clients understand and communicate the "why" behind their positioning with clarity and authenticity. - Lead the execution of integrated communications campaigns across PR, digital, social media, and employee communications channels, ensuring alignment with core narrative and coordinating across team members. - Research and analyze market trends and competitive dynamics to identify positioning opportunities and help clients understand their market positioning; recommend communications strategies to address competitive challenges. - Support account growth by identifying opportunities where integrated communications can strengthen client relationships and business outcomes—including product launches, hiring initiatives, and stakeholder engagement. Qualifications - 4-6 years of PR or communications agency experience with strong knowledge of technology and business fundamentals and demonstrated analytical and creative thinking capabilities. - Proven passion for media relations with a strong track record of building relationships with journalists in technology, cyber security, and business, in top tier and trade media. Consistent success in securing meaningful media coverage and understanding how to work with reporters to shape narratives. - Great project management and collaborative skills, including the ability to coordinate multiple work streams, mentor junior team members, and maintain quality and composure under tight deadlines in a fast-paced environment. - Solid experience executing integrated communications campaigns across multiple channels including earned media, owned media, social, and digital. Understanding of how to create cohesive campaigns that drive consistent messaging and results. - Ability to use research and data to inform strategic recommendations. Experience working with research and insights to interpret trends and metrics that shape client strategy and positioning decisions. - Strong written and verbal communication skills with ability to craft compelling client communications, strategic plans, talking points, and bylined content. Comfortable presenting ideas and recommendations in client meetings and internal settings. - Self-motivated and resourceful problem solver. Takes ownership of client success while maintaining focus on both day-to-day delivery and strategic opportunity. Our Story FleishmanHillard specializes in public relations, reputation management, public affairs, brand marketing, digital strategy, social engagement and content strategy. FleishmanHillard was named 2020, 2021 and 2022 Campaign Global PR Agency of the Year; 2023 ICCO Large Agency of the Year – The Americas; 2022 and 2023 PRWeek U.S. Agency of the Year; 2022 and 2023 PRWeek U.S. Outstanding Extra-Large Agency of the Year; 2023 Campaign US PR Agency of the Year; 2021 PRovoke APAC Consultancy of the Year; and 2021 PRWeek UK Large Consultancy of the Year. FleishmanHillard is part of Omnicom PR Group and has nearly 80 offices in more than 30 countries, plus affiliates in 45 countries. FleishmanHillard offers a hybrid work model, and seeks employees who are comfortable working in the office for a portion of their workweek. We value the collaboration and camaraderie that in-person interactions provide, but also understand the importance of flexibility and balance in our employees' lives. As such, we are open to discuss various work arrangements that accommodate individual needs and circumstances, including flexible scheduling and alternative work arrangements. Our goal is to foster a productive and inclusive work environment where all employees can thrive, both in and out of the office. FleishmanHillard is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sex stereotyping, pregnancy (which includes pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), gender, gender identity, gender expression, national origin, age, mental or physical disability, ancestry, medical condition, marital status, military or veteran status, alienage, citizenship status, sexual orientation, genetic information, or any other protected class under federal, state or local laws. Please do not contact the office directly to apply – only resumes submitted through this website will be considered. If you need assistance reviewing career opportunities or completing an application, please email our careers team or call 314-982-1700 and ask to be connected to Talent Development. The anticipated salary range for the Account Supervisor level is $61,000- $94,000. Salary is based on a range of factors that include relevant experience, knowledge, skills, other job-related qualifications and geography. A range of medical, dental, vision, 401(k) matching, paid time off and/or other benefits also are available.
Cybersecurity Lab Engineer
VectraVectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers.
Role Description We are looking for a Cybersecurity Lab Engineer to own the design, build, and operations of hands-on lab environments that power Vectra AI customer training and enablement programs. You will create realistic, production-like environments that simulate attacker behaviors and showcase how Vectra AI detects and prioritizes threats across networks, identities, and cloud workloads. This role is critical in helping customers move from learning to real-world application. Key Responsibilities - Design and build Vectra AI-focused lab environments that simulate real-world enterprise networks and attack scenarios - Deploy and configure Vectra AI platform components within lab environments - Create end-to-end attack simulations (lateral movement, credential abuse, C2 activity, etc.) aligned to MITRE ATT&CK - Build scalable, repeatable lab environments across cloud platforms (AWS, Azure, GCP) and/or virtualized setups - Automate lab provisioning and teardown using Infrastructure-as-Code (Terraform, scripts, etc.) - Ensure labs are stable, performant, and easily resettable for multiple concurrent users - Partner with Customer Enablement, Product, and Sales Engineering teams to align labs with key use cases and customer journeys - Troubleshoot issues during live training sessions and ensure a seamless customer experience - Document lab architectures, deployment processes, and playbooks - Continuously evolve labs to reflect new Vectra AI capabilities and emerging threat scenarios Qualifications - 3–6 years of experience in cybersecurity engineering, cloud engineering, or DevOps - Strong understanding of network security and threat detection concepts (NDR, lateral movement, identity-based attacks, etc.) - Hands-on experience with AWS, Azure, or GCP - Experience building lab, sandbox, or demo environments - Solid understanding of networking fundamentals (VPCs, traffic mirroring/SPAN, subnets, routing, DNS) - Experience with automation tools (Terraform, Ansible, Python, Bash) - Ability to independently troubleshoot complex infrastructure and security scenarios - Strong documentation and communication skills Preferred Qualifications - Experience with NDR, SIEM, EDR, or similar security platforms - Familiarity with Vectra AI or similar threat detection technologies - Experience simulating adversary behaviors using MITRE ATT&CK framework - Exposure to packet analysis, network telemetry, or detection engineering - Experience supporting customer training, workshops, or demos - Familiarity with containerized environments (Docker, Kubernetes) What Success Looks Like - Customers can seamlessly engage in hands-on labs that mirror real-world attack scenarios - Lab environments reliably demonstrate the value of Vectra AI across key use cases - Labs are scalable, automated, and require minimal manual intervention - Fast turnaround for new lab builds aligned to product releases and customer needs Benefits - Comprehensive total rewards package supporting financial, physical, mental, and overall health of employees and their families - Competitive base pay, incentive plan eligibility, and participation in the employee equity plan (stock options) - Health care insurance - Income protection/life insurance - Access to retirement savings plans - Behavioral & emotional wellness services - Generous time away from work - Comprehensive employee recognition program Company Description Vectra AI is the leader in AI-driven threat detection and response for hybrid and multi-cloud environments. Our platform empowers security teams to detect, investigate, and respond to advanced cyberattacks in real time.
• Define and govern enterprise cyber security architecture across IT, cloud, OT, and emerging technologies. • Shape forward-looking cyber security strategy and maintain architectural principles and standards. • Develop and maintain capability maps and application portfolio management for cyber security. • Create sub-strategies and thought leadership across domains such as AI identity, exposure management, OT security, and micro segmentation. • Provide expert advisory to programmes and stakeholders on strategic and tactical technology decisions. • Define and maintain cyber security reference architectures and design patterns. • Review and approve architecture decisions through governance boards and design authorities. • Drive cloud security improvements aligned to posture assessments. • Conduct architectural risk assessments and provide trade-off decisions balancing security, cost, and delivery. • Act as a cyber architecture authority in design and investment forums. • Lead and contribute to enterprise architecture initiatives and governance activities. • Produce white papers and contribute to thought leadership within the organization. • Engage with cross-functional teams across business, IT, and OT domains. • Collaborate with internal stakeholders and external vendors to shape strategic roadmaps. • Support security community initiatives, mentoring, and awareness programs.
Italian-Speaking Cybersecurity Customer Experts
Mercier Consultancy GroupA fast-growing, operator-led GTM consultancy building AI-powered revenue systems for modern sales teams. The business was founded by experienced CROs who have carried quota, and specializes in engineering end-to-end revenue infrastructure that converts market signals into qualified pipeline — at speed and scale. The company is AI-native and increasingly code-first in its approach, using a sophisticated internal tech stack including custom AI agent orchestration, workflow automation, signal detection and enrichment, multi-channel outreach delivery, and operational intelligence tooling. AI systems are embedded throughout the entire execution layer. They serve growth-stage B2B companies scaling between $1M and $100M+ ARR who need systematic, automation-driven competitive advantages — built on infrastructure, not headcount.
Role Description Mercier Consultancy MD is looking for Italian-Speaking Cybersecurity Customer Experts to join our expanding team in Greece. In this role, you will provide exceptional cybersecurity customer support to Italian-speaking clients, helping them secure their digital environments. This is an excellent opportunity to develop your career in cybersecurity within a supportive and innovative workplace. - Offer expert customer support to Italian-speaking clients regarding cybersecurity products and services via multiple communication channels including phone, email, and chat. - Diagnose and resolve security-related issues effectively and efficiently. - Advise customers on cybersecurity best practices and the optimal use of security solutions. - Maintain detailed records of all customer interactions and technical issues in CRM systems. - Work with internal teams to escalate complex problems and contribute to their resolution. - Keep up-to-date with the latest developments in cybersecurity to provide informed support. Qualifications - Fluency in Italian (both written and spoken) is required; proficiency in English is a plus. - Previous experience in customer support or a similar role, preferably in the cybersecurity or IT security fields. - Strong understanding of cybersecurity concepts and technologies. - Excellent communication skills and analytical abilities to solve client issues effectively. - Capability to multitask and work efficiently under pressure in a fast-paced environment. - Experience with CRM tools and customer support software. - Passion for cybersecurity and eagerness to continuously learn and adapt. Benefits - Competitive Monthly Salary - Fully Paid Training - Fully Paid Relocation Package - Monthly Performance Bonus - Health Insurance - 2 Extra Salaries Per Year - And Much More...

