> Markdown version of [/jobs/ext/2737029-security-engineer-ii-application-security](https://www.wearedevelopers.com/jobs/ext/2737029-security-engineer-ii-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II - Application Security - **Company:** Aledade, Inc. - **Location:** Bethesda, MD, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), C++ (Programming Language), Clinical Data Repository, Software as a Service, Code Review, Cyber Security, Distributed Systems, R (Programming Language), Integrated Development Environments, Python (Programming Language), Machine Learning, Open Web Application Security, Scala (Programming Language), Security Software, Software Deployment, Web Applications, Cloud Platform System, Large Language Models, Software Security, Electronic Medical Records, Cloudformation, Information Technology, Web Technologies, Terraform, Devsecops, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-ii-application-security-aledade-9851841 ## About the Role We are flexible with respect to geographic location, and the ideal candidate will be comfortable working remotely/work from home within the U.S. or from our headquarters office in Bethesda, MD., * BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, 10 years security domain experience without degree * 6+ years of experience in securing and deploying applications within Cloud Native environments * 3+ years of experience in a dedicated application security role with focus on establishing secure SDLC and DevSecOps processes, * Knowledge of health-tech systems, like Electronic Health Records, Clinical data, PHI, etc, direct experience preferred. * Experience architecting, developing, and deploying large-scale distributed systems at scale. * Extensive experience identifying, evaluating and triaging vulnerabilities with Static/Dynamic Application Security Testing (SAST/DAST) methodologies and tools. * Proven experience conducting code reviews, and threat modeling. * Extensive experience with developing automated security testing and validation systems using Terraform, Cloudformation, Python, etc. * Proficient in coding languages such as Python, R, C++, Javascript. * Extensive experience working in AWS/Azure/GCP software development environment.. * Proven experience with implementing security controls for web-based SaaS applications such as API Security, WAF, etc. * In-depth knowledge of AI/LLM and machine learning architectures and best practices for securing them. * In-depth knowledge of OWASP Top 10 vulnerabilities along with containment and remediation best practices. * Strong familiarity with server-side web technologies (eg: Java, Python, Scala, C#, C++, Go). * 4+ years of experience acting as a trusted technical decision-maker in a team setting, solving for short-term and long-term business value * Experience with health-tech systems, like Electronic Health Records, Clinical data, etc preferred. ## Description The Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and know how to actively employ these ingredients at scale. Beyond the technical expertise, we value individuals who can partner cross-functionally across various teams, driving impactful outcomes and further securing our digital landscape., * Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities * Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders * Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues * Helping craft and refine security documentation pertinent to our Security Program, such as policies, standards, baselines, and standard operating procedures * Mentoring and coaching more junior engineers or analysts ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)