Senior Security Engineer - Secure SDLC

Senior
CompanyHighmark Health
LocationPA, Working at Home - Pennsylvania, MD, Working at Home - Maryland, WA, Working at Home - Washington, NC, Working at Home - N Carolina, LA, Working at Home - Louisiana, KY, Working at Home - Kentucky, KS, Working at Home - Kansas, IN, Working at Home - Indiana, IL, Working at Home - Illinois, GA, Working at Home - Georgia, IA, Working at Home - Iowa, FL, Working at Home - Florida, CO, Working at Home - Colorado, CA, Working at Home - California, DE, Working at Home - Delaware, CT, Working at Home - Conneticut, AR, Working at Home - Arkansas, AZ, Working at Home - Arizona, AL, Working at Home - Alabama, AK, Working at Home - Alaska, NV, Working at Home - Nevada, VT, Working at Home - Vermont, TN, Working at Home -Tennessee, ID, Working at Home - Idaho, OK, Working at Home - Oklahoma, HI, Working at Home - Hawaii, MS, Working at Home - Mississippi, UT, Working at Home - Utah, NH, Working at Home - New Hampshire, NM, Working at Home - New Mexico, WY, Working at Home - Wyoming, ND, Working at Home - North Dakota, SD, Working at Home-South Dakota, RI, Working at Home - Rhode Island, WV, Working at Home - W Virginia, MO, Working at Home - Montana, TX, Working at Home - Texas, DC, Working at Home - Dist of Col, OH, Working at Home - Ohio, NJ, Working at Home - New Jersey, OR, Working at Home - Oregon, SC, Working at Home-South Carolina, MO, Working at Home - Missouri, VA, Working at Home - Virginia, MA, Working at Home -Massachusetts, NE, Working at Home - Nebraska, MN, Working at Home - Minnesota, MI, Working at Home - Michigan, WI, Working at Home - Wisconsin, NY, Working at Home - New York, ME, Working at Home - Maine
CategorySecurity
SenioritySenior
Workplace-
Posted2026-09-16
Estimated salary$12K - $20K (a market estimate, not the employer's figure)
Viaworkday

Description

Company

enGen

Job Description

JOB SUMMARY

***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***

Highmark Health is seeking a   Senior Security Engineer   to join our Enterprise Application Security team and play a   pivotal role   in shaping how security is built into our software —   not bolted on after the fact.

This is a   high-impact, engineering role   for a security professional who is   passionate about preventing vulnerabilities before they happen.   You will be at the forefront of our   shift-left security strategy , working directly alongside our engineering teams to   embed security into every stage of the software development lifecycle   — from the first line of code to production deployment.

If you thrive at the intersection of   security engineering & architecture ,   developer enablement & collaboration , and   automation , and you want to   build something that matters at enterprise scale   in one of the nation's leading health and insurance organizations —   this role is for you.

Build & Enforce Shift-Left Security Controls

  • Design and implement security guardrails   that catch vulnerabilities at the earliest possible point in the development process, including within   AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines.
  • Configure and enforce pipeline security gates   across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts   cannot advance to production without meeting defined security standards.
  • Deploy and manage application security scanners , including   SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities   across the enterprise development platform.
  • Develop security-as-code policies and enforcement rules   that scale across a large, distributed engineering organization.
  • Partner with Software Delivery Enablement teams   to establish security controls, governance requirements, and safe usage patterns for   AI coding assistants, AI agents, and AI-enabled developer tooling.

Drive Vulnerability Risk Reduction

  • Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as   EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators.
  • Establish and track remediation SLAs   aligned to vulnerability severity and business risk, with a focus on   eliminating Critical and High findings before they reach production.
  • Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms.
  • Conduct root cause analysis   on recurring vulnerability patterns and drive   systemic improvements   through tooling, standards, secure development practices, and developer education.
  • Monitor and report on key security health metrics   including   Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and   AI security risk reduction metrics.

Automate & Optimize the Security Toolchain

  • Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering   high-fidelity, actionable signal.
  • Evaluate, onboard, and operationalize emerging security technologies   that improve visibility and governance over   AI-assisted software development and software supply chains.
  • Build automation workflows   for vulnerability triage, escalation, assignment, and reporting,   reducing manual overhead and accelerating response times.
  • Continuously optimize scanner configurations   to minimize false positives and maximize detection accuracy.
  • Develop dashboards and reporting pipelines   that give engineering and security leadership   real-time visibility   into application security posture,   AI security adoption , and policy compliance.
  • Integrate security controls and monitoring   into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.

Enable & Empower Developers

  • Serve as a trusted, embedded security advisor   to engineering teams, providing   hands-on guidance, code review support, AI security consultation, and practical remediation recommendations.
  • Design and deliver security training, workshops, and reference materials   that make   secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable   for developers at all levels.
  • Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization.
  • Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries   that reduce security burden on development teams.
  • Develop guidance and reference architectures   for secure implementation of   LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications.
  • Partner with development, architecture, and platform teams   to embed   secure-by-default AI development practices   throughout the SDLC.

Measure, Report & Continuously Improve

  • Define, track, and report on AppSec KPIs   that demonstrate program effectiveness and drive continuous improvement.
  • Establish and report on AI security metrics   such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings.
  • Conduct regular security posture reviews   and present findings, trends, and recommendations to engineering and security leadership.
  • Support audit, risk, and compliance activities   by ensuring security controls,   AI governance requirements , and secure development standards are documented, measurable, and consistently enforced.
  • Benchmark program maturity   against industry frameworks such as   OWASP SAMM, BSIMM, OWASP Top 10 for LLM Applications , and emerging AI security best practices, driving year-over-year improvement.
  • Continuously assess emerging threats, vulnerabilities, and attack techniques   affecting modern software delivery pipelines, software supply chains, and   AI-enabled applications.

Assist in AI Application Security & Governance

  • Assist with security reviews and threat modeling   for   AI-enabled applications, LLM integrations, AI agents, and AI-assisted development platforms.
  • Collaborate with Security Architecture   to recommend and establish technical controls and guardrails supporting   enterprise AI governance requirements.
  • Evaluate security risks associated with AI models, prompts, training data, model supply chains, MCP integrations, and agentic workflows.
  • Partner with Architecture, ISRM, and Software Delivery Enablement teams   to define   secure AI development standards and implementation patterns   across the enterprise.

Preferred Qualifications

  • Experience with   GitLab Ultimate security features   including Vulnerability Reports, Security Policies, Compliance Frameworks, and security controls supporting AI-assisted development workflows.
  • Deep proficiency with application security scanning tools   including   SAST, DAST, SCA/Dependency Scanning, Container Scanning, Secret Detection, API Security Testing , and emerging   AI application security assessment capabilities.
  • Deep proficiency with JFrog security and compliance tools   such as   Xray and Curation , including Policies, Watches, Impact Analysis, Software Supply Chain controls, and reporting.
  • Familiarity with   threat modeling methodologies   such as   STRIDE, PASTA , and their application to   AI-enabled systems, LLM integrations, and agentic workflows.
  • Working kno