> Markdown version of [/jobs/ext/2532275-senior-security-engineer-secure-sdlc](https://www.wearedevelopers.com/jobs/ext/2532275-senior-security-engineer-secure-sdlc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - Secure SDLC - **Company:** Highmark Inc. - **Location:** Raleigh, NC, United States - **Experience:** Expert - **Salary:** $102,700.0 - $164,600.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Build Automation, Bash Shell, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Code Review, Cyber Security, Information Systems, System Configuration, Continuous Integration, Information Leak Prevention, Software Design Patterns, Email Filtering, Github, Systems Analysis, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Windows Servers, Network Protocols, Open Web Application Security, PCI Data Security Standards, Performance Tuning, Systems Development Life Cycle, Red Team (Cyber Security), Secure Coding, Server Administration, Microsoft SharePoint, Software Deployment, Software Engineering, Toolchain, Virtualization Technology, Enterprise Software Applications, Software Security, Mttr, Firewalls (Computer Science), Gitlab, GWAPT, Kubernetes, Information Technology, Tenable Nessus, Docker, Jenkins, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** August 20, 2026 - **Apply:** https://www.juju.com/job/00000000go2s9j ## About the Role + Experience with **GitLab Ultimate** security features including Vulnerability Reports, Security Policies, and Compliance Frameworks + Deep proficiency with application security scanning tools - SAST, DAST, SCA/Dependency Scanning, Container Scanning, and Secret Detection + Deep proficiency with JFrog security and compliance tools such as Xray and Curation -- Policies, Watches, Impact Analysis and Reports + Familiarity with threat modeling methodologies such as STRIDE or PASTA + Knowledge of healthcare or financial services regulatory frameworks including **HIPAA, PCI-DSS, SOC 2, or NIST CSF** + Industry certifications such as **CSSLP, GWEB, GWAPT, OSCP** , or equivalent + Prior experience as a software developer - we strongly value candidates who understand what it's like to be on the other side of a security finding + Experience coordinating or conducting penetration testing and red team exercises, + Bachelor's Degree in Computer Science, Information Systems, or closely related field, + Master's Degree in Computer Science, Information Security or related field EXPERIENCE Required + 7 years with Information Security and Systems Analysis + 7 years with Information Security and/or Information Risk Management and/or Information Technology + 7 years with Operating Systems and Software Administration + 7 years developing, communicating and presenting Information Security and Risk Management concepts to varying audiences + 7 years with technologies such as Intrusion Prevention Systems (IPS), firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), and virtualization platforms _Preferred:_ + 10 years with Information Security and Systems Analysis + 7 years in IT / Information Security Risk advisory + 7 years in-depth understanding of network security architecture, network and networking protocols + 7 in Database Management, System Administration and Software Development Life-Cycle + 3 years working within an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework SKILLS + Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 + Familiarity with secure SDLC best practices + Knowledge of Microsoft Apps and Suites, Windows server, SharePoint, etc. + Strong teamwork and inter-personal skills Additional Skills: + Hands-on experience with CI/CD platforms such as GitLab, GitHub Actions, Jenkins, or equivalent + Proficiency in at least one scripting or programming language (Python, Go, Bash, or equivalent) for security automation + Familiarity with container and cloud-native security concepts (Docker, Kubernetes, cloud provider security services) + Ability to conduct focused secure code reviews and analysis + Familiarity with AI Security + Preparing and delivering regular security posture briefings to engineering and security leadership - including trend analysis, KPI performance, and forward-looking recommendations + Configuring and managing SCA tools (GitLab Dependency Scanning, OWASP Dependency-Check, or equivalent) across multiple package ecosystems + Generating, maintaining, and interpreting Software Bills of Materials in CycloneDX or SPDX formats + Applying container security best practices - minimal base images, non-root execution, read-only filesystems, and image signing + Designing security gates that block non-compliant code from advancing through the pipeline while minimizing developer friction (Gitlab, JFrog XRay), + Certified Information Systems Security Professional (CISSP), Security **LANGUAGE REQUIREMENT (** **_other than English_** **)?**, Lifting: up to 10 pounds Constantly Lifting: 10 to 25 pounds Occasionally Lifting: 25 to 50 pounds ## Description Highmark Health is seeking a **Senior Security Engineer** to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software - not bolted on after the fact. This is a high-impact, hands-on engineering role for a security professional who is passionate about **preventing vulnerabilities before they happen** . You will be at the forefront of our shift-left security strategy, working directly alongside our engineering teams to embed security into every stage of the software development lifecycle - from the first line of code to production deployment. If you thrive at the intersection of **security engineering, developer collaboration, and automation** , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations - this role is for you. What You'll Do Build & Enforce Shift-Left Security Controls + Design and implement security guardrails to catch vulnerabilities as early as possible in development (IDE, commit time, CI/CD pipelines). + Configure and enforce enterprise-wide pipeline security gates, ensuring code meets security standards before reaching production. + Deploy and manage application security scanners (SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST) across our GitLab-based development platform. + Develop scalable security-as-code policies and enforcement rules for a large, distributed engineering organization. Drive Vulnerability Risk Reduction + Lead risk-based triage and prioritization of detected vulnerabilities, using exploitability signals like EPSS scores, Known Exploited Vulnerability (KEV) status, and reachability analysis. + Establish and track remediation SLAs based on vulnerability severity and business risk, focusing on eliminating Critical and High findings pre-production. + Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, and developer education. + Monitor and report on key security health metrics, including Mean Time to Remediate (MTTR), security debt trends, and pre- vs. post-production detection rates. Automate & Optimize the Security Toolchain + Architect and maintain the enterprise application security toolchain, ensuring proper integration, tuning, and delivery of high-fidelity, actionable signals. + Build automation workflows for vulnerability triage, escalation, assignment, and reporting to reduce manual overhead and accelerate response times. + Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy. + Develop dashboards and reporting pipelines to provide engineering and security leadership with real-time visibility into the organization's security posture. Enable & Empower Developers + Serve as a trusted, embedded security advisor to engineering teams, offering hands-on guidance, code review support, and practical remediation recommendations. + Design and deliver security training, workshops, and reference materials that make secure coding accessible and actionable for all developers. + Build and grow a Security Champions program, embedding security advocates within engineering teams to extend the AppSec program's reach. + Create and maintain secure coding standards, design patterns, and reusable security libraries to reduce the security burden on individual developers. Measure, Report & Continuously Improve + Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement. + Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership. + Support audit and compliance activities by ensuring security controls are documented, measurable, and consistently enforced. + Benchmark program maturity against industry frameworks like OWASP SAMM and BSIMM, and drive year-over-year improvement., + Lead teams in clearly defining requirements, deliverables and timeframes. Escalate issues and make recommendations to resolve them to the appropriate audience. + Conduct root cause analysis to identify and resolve complex problems impacting ISRM Infrastructure. + Develop and/or deliver technical training in complex technical areas. Mentor less senior staff in the execution of their duties. + Complete project tasks to enable the on time, within budget and scope delivery of ISRM Infrastructure projects. + Implement, monitor, configure, and maintain security systems. + Assure compliance to required standards, procedures, guidelines and processes. + Other duties as assigned or requested. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)