Enabling better, smarter, safer healthcare to improve lives.
Application Security Engineer
Location
United States
Posted
3 days ago
Salary
$125.6K - $172.7K / year
Seniority
Mid Level
Job Description
Application Security Engineer
Solventum
Role Description As an Application Security Engineer at Solventum, you will: - Join a team of cybersecurity professionals motivated to secure Solventum's healthcare information systems and the personal health information of our clients and their patients. - Operate and enhance application security tool environments. - Author automation scripts for recurring tasks (Python preferred). - Setup and execute authenticated and unauthenticated dynamic application security testing (DAST) scans against web applications and APIs using approved tools. - Manage scan scheduling, configuration, and coverage across application security tool environments. - Tune scanning profiles to reduce false positives and improve detection accuracy. - Ensure DAST scanning aligns with release cycles and risk-based scanning requirements. - Validate DAST findings to confirm exploitability and business impact. - Categorize vulnerabilities using industry standards (e.g., OWASP Top 10). - Prioritize findings based on risk, application criticality, and exposure. - Eliminate false positives and duplicate findings prior to developer handoff. - Partner with development and platform teams to explain DAST findings and remediation expectations. - Track remediation progress and verify fixes through re-scanning or targeted validation. - Maintain accurate vulnerability records in enterprise tracking systems. - Escalate overdue or high-risk vulnerabilities in accordance with policy. - Work with application teams to validate that software applications meet security guidelines and compliance standards such as HIPAA, SOC II, GDPR, NIST 800-53, FedRAMP, etc. - Build solutions that collect and present vulnerability and compliance data to Solventum’s leadership. Qualifications - Bachelor’s Degree & 7 years of experience in application security. - 3 years' experience administering, running, and analyzing DAST tools. - Knowledgeable with AWS or Azure cloud environments. - Familiarity with best practice software security requirements in industry standard compliance programs (NIST, HITRUST, FedRAMP, etc.). - Experience developing or testing RESTful APIs with an understanding of Postman and/or Swagger files. - Ability to obtain and maintain a Public Trust clearance. Requirements - Experience administering Qualys or Tenable vulnerability management and application security modules. - Experience in working across multiple teams and disciplines. - Strong attention to detail and analytical skills. - Risk-based prioritization and sound judgment. Benefits - Competitive pay and benefits. - Medical, Dental & Vision coverage. - Health Savings Accounts. - Health Care & Dependent Care Flexible Spending Accounts. - Disability Benefits. - Life Insurance. - Voluntary Benefits. - Paid Absences. - Retirement Benefits.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Executive, Data Security – Majors
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
• Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the data security product portfolio • Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals • Own the regional quota and territory achievement by building and implementing account-based strategies to land and expand data security solutions • Collaborate synergistically with primary sales teams and leadership to ensure a unified and effective Zscaler presence in the market • Engage stakeholders across the organization, selling effectively to both C-suite executives and technical practitioners
• Monitor and triage security alerts from SIEM, EDR, and other tools; escalate and respond as needed. • Investigate security incidents, determine root cause, document findings, and develop IOCs to prevent recurrence. • Support escalations from internal employees or customers with security-related concerns. • Assist with security reviews related to infrastructure and system changes. • Build, enhance, and maintain internal security tooling and scripting repositories. • Contribute to the development of detection content, alert tuning, and automation pipelines. • Drive annual security team goals and cross-functional initiatives. • Author and maintain clear, actionable documentation and knowledge bases. • Mentor junior team members and share expertise across the organization. • Participate in a rotating on-call schedule for security operations support.
• Design and implement security solutions to enable customers to securely deploy and govern Claude Enterprise • Assess existing security, identity, data, cloud and SaaS architectures and advise on best-in-class solutions for securing enterprise AI tooling across customers in a wide range of industries • Conduct comprehensive evaluations of AI tools (e.g. Claude, Claude Enterprise), platform configurations, data access patterns, connector usage, security controls, processes and personnel to deliver informed recommendations leveraging your expertise in security engineering and AI governance • Design and implement security controls for enterprise AI platforms, including SSO, SCIM, RBAC, MFA, conditional access, admin roles, user lifecycle management, retention policies, audit logging, workspace controls, DLP, and acceptable-use enforcement • Assess and govern AI platform features such as file uploads, custom assistants, projects, GPTs, connectors, browsing, code execution, data analysis, plugins, agents, API access, and external sharing • Review and secure AI integrations with enterprise repositories and collaboration platforms, including Google Drive, SharePoint, OneDrive, Slack, Teams, GitHub, GitLab, Jira, Confluence, Salesforce, Snowflake, Databricks, and BI platforms • Manage and lead end-to-end AI Security Implementation efforts as part of a project team; including activities such as identity integration, access control design, data protection controls, AI platform configurations, connector governance, monitoring / logging and incident response workflows
Developer Intern, Data Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Be partially responsible for the underlying cryptography across our products. • Help build cryptographic libraries and implement the latest algorithms directly into our client applications with security, performance and usability in mind. • Develop proof-of-concepts and implement new industry specifications into code. • Conduct code and design reviews to ensure good cryptographic hygiene and standards across our codebase.




