CareerMoonshot

Senior Security Engineer - Secure SDLC

Western Pennsylvania Hospital School of Nursing · Pennsylvania

📍 PA, Working at Home - Pennsylvaniavia workdayFirst listed here 2026-09-24
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Western Pennsylvania Hospital School of Nursing.
Company : enGen Job Description :  JOB SUMMARY ***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)*** Highmark Health is seeking a   Senior Security Engineer   to join our Enterprise Application Security team and play a   pivotal role   in shaping how security is built into our software —   not bolted on after the fact. This is a   high-impact, engineering role   for a security professional who is   passionate about preventing vulnerabilities before they happen.   You will be at the forefront of our   shift-left security strategy , working directly alongside our engineering teams to   embed security into every stage of the software development lifecycle   — from the first line of code to production deployment. If you thrive at the intersection of   security engineering & architecture ,   developer enablement & collaboration , and   automation , and you want to   build something that matters at enterprise scale   in one of the nation's leading health and insurance organizations —   this role is for you. Build & Enforce Shift-Left Security Controls Design and implement security guardrails   that catch vulnerabilities at the earliest possible point in the development process, including within   AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines. Configure and enforce pipeline security gates   across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts   cannot advance to production without meeting defined security standards. Deploy and manage application security scanners , including   SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities   across the enterprise development platform. Develop security-as-code policies and enforcement rules   that scale across a large, distributed engineering organization. Partner with Software Delivery Enablement teams   to establish security controls, governance requirements, and safe usage patterns for   AI coding assistants, AI agents, and AI-enabled developer tooling. Drive Vulnerability Risk Reduction Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as   EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators. Establish and track remediation SLAs   aligned to vulnerability severity and business risk, with a focus on   eliminating Critical and High findings before they reach production. Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms. Conduct root cause analysis   on recurring vulnerability patterns and drive   systemic improvements   through tooling, standards, secure development practices, and developer education. Monitor and report on key security health metrics   including   Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and   AI security risk reduction metrics. Automate & Optimize the Security Toolchain Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering   high-fidelity, actionable signal. Evaluate, onboard, and operationalize emerging security technologies   that improve visibility and governance over   AI-assisted software development and software supply chains. Build automation workflows   for vulnerability triage, escalation, assignment, and reporting,   reducing manual overhead and accelerating response times. Continuously optimize scanner configurations   to minimize false positives and maximize detection accuracy. Develop dashboards and reporting pipelines   that give engineering and security leadership   real-time visibility   into application security posture,   AI security adoption , and policy compliance. Integrate security controls and monitoring   into approved AI development platforms, coding assistants, model gateways, and agentic development workflows. Enable & Empower Developers Serve as a trusted, embedded security advisor   to engineering teams, providing   hands-on guidance, code review support, AI security consultation, and practical remediation recommendations. Design and deliver security training, workshops, and reference materials   that make   secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable   for developers at all levels. Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization. Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries   that reduce security burden on development teams. Develop guidance and reference architectures   for secure implementation of   LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications. Partner with development, architecture, and platform teams   to embed   secure-by-default AI development practices   throughout the SDLC. Measure, Report & Continuously Improve Define, track, and report on AppSec KPIs   that demonstrate program effectiveness and drive continuous improvement. Establish and report on AI security metrics   such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings. Conduct regular security posture reviews   and present findings, trends, and recommendations to engineering and security leadership. Support audit, risk, and compliance activities   by ensuring security controls,   AI governance requirements , and secure development standards a

More Pennsylvania jobs

Pennsylvania jobs · Browse all locations