> Markdown version of [/jobs/ext/3207711-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3207711-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Baylor Genetics - **Location:** Houston, TX, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Software System Penetration Testing, User Authentication, Bioinformatics, C Sharp (Programming Language), Cloud Engineering, Static Program Analysis, Software Quality, Code Review, Cyber Security, Python (Programming Language), OAuth, Open Web Application Security, Systems Development Life Cycle, Openid Connect, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Web Applications, Privacy Controls, Software Security, GWAPT, Containerization, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://www.builtincolorado.com/job/application-security-engineer/11084843?handler=ApplyRedirect ## About the Role Required * Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field - or an equivalent combination of education and experience. * Minimum of 3-5 years of experience in application security, DevSecOps, or software engineering with a security focus. * Hands-on experience with SonarQube for static code analysis and code quality/security gating. * Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines. * Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript. * Familiarity with penetration testing, code review, and vulnerability management processes. * Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR. Preferred * Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent. * Experience securing web applications, APIs, and cloud-native/containerized workloads. * Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect). * Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment. COMPETENCIES * Excellent written and verbal communication skills; ability to collaborate cross-functionally and present findings to varying audiences. Strong analytical and problem-solving skills with a risk-based mindset. * Effective written and verbal communication, able to translate technical risk for non-technical stakeholders. * Collaborative, cross-functional approach with the ability to influence engineering teams. * Detail-oriented, self-directed, and able to prioritize in a fast-moving environment. PHYSICAL DEMANDS AND WORK ENVIRONMENT * Onsite/Hybrid role based in Houston, TX; primarily an office/laboratory-adjacent setting. * Frequently required to sit and use hand and finger dexterity for prolonged periods. * Occasional travel for meetings, conferences, or audits. ## Description Be an Early Applicant Remote Hiring Remotely in United States Mid level Remote Hiring Remotely in United States Mid level Build and mature the application security program across the SDLC. Manage SAST, DAST, SCA, and IAST tooling; conduct penetration tests and vulnerability assessments; drive remediation; and embed Secure by Design practices. Partner with engineering on threat modeling, secure coding, architecture reviews, and CI/CD integration. Support HIPAA, NIST, and GDPR compliance through audits, reporting, documentation, policies, and cross-functional risk reduction initiatives. The summary above was generated by AI, Baylor Genetics is seeking an Application Security Engineer to build and mature our application security program, embedding security across the software development lifecycle (SDLC) and champion Security by Design principles. As a leader in clinical genetic testing, we handle highly sensitive patient data across our web, API, and pipeline applications, and this role is central to protecting that data and reducing risk. The engineer will implement and manage static and dynamic code analysis tooling - including SonarQube and BURP - partner closely with engineering to remediate findings, and help close audit-identified gaps in secure coding, software composition analysis, and code review coverage. This role directly supports HIPAA compliance and organizational risk reduction. Scope may evolve as organizational needs change. KEY RESPONSIBILITIES * Implement and manage static and dynamic code analysis, integrating SonarQube (and complementary SAST/DAST/SCA tools) into CI/CD pipelines and check-in scans, and partnering with engineering to triage and remediate findings. * Perform penetration tests and vulnerability assessments across web, API, and pipeline applications, and lead consistent, timely remediation of identified findings. * Develop and maintain a structured remediation program that addresses and resolves security findings quickly, consistently, and in priority order. * Evolve Baylor Genetics' SDLC into a Secure SDLC (SSDLC) by embedding Security by Design and Privacy by Design principles at every stage. * Integrate secure coding practices with development teams, providing guidance, threat modeling, and secure architecture reviews for new features and releases. * Generate regular reports on the status of application security initiatives, vulnerability management, and risk assessments for technical and executive audiences. * Collaborate with auditors during internal and external audits, providing explanations, evidence, and documentation, and drafting security policies and procedures as needed. * Partner cross-functionally with IT, Privacy, Compliance, and business units to support initiatives and drive measurable risk reduction. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)