Lead Application Security Engineer- DevSecOps

Athena LLC.
Boston, MA, United States
24 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$127,300.0 - $165,500.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Cloud Computing Collaborative Software Cyber Security Computer Engineering Continuous Integration DevOps Identity and Access Management JSON Key Management OAuth PCI Data Security Standards
+18 more
Scrum Methodology Systems Development Life Cycle Openid Connect JSON Web Token Security Assertion Markup Language (SAML) Software Engineering Software Vulnerability Management Web Services Software Security Infrastructure Automation Frameworks Information Technology Api Gateway Restful APIs Terraform Devsecops Docker Static Application Security Testing Dynamic Application Security Testing

Job description

Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security. This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes. About the Team This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment. Core Responsibilities Security strategy and SDLC adoption Socialize and drive execution of key security best practices across the R&D organization. Contribute to the enterprise security catalog of best practices, techniques, and patterns. Improve the quality and adoption of Security Development Lifecycle practices. Application security capability ownership Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities. Support SAST, SCA, DAST, API security testing, and vulnerability management workflows. Document, share, and help automate coverage for common abuse cases and attacks. API security program leadership Lead the API security testing program. Manage API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness. Identify and explain feature-level design or architectural weaknesses that could create security issues. Cross-functional partnership and issue management Partner with enterprise security leadership to track and prioritize open issues and follow through on resolution. Work with DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to design and operate security-hardened platforms., The base salary range shown reflects the full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates. Base pay is only one part of our competitive Total Rewards package - depending on role eligibility, we offer both short and long-term incentives by way of an annual discretionary bonus plan, variable compensation plan, and equity plans. About athenahealth Our vision: In an industry that becomes more complex by the day, we stand for simplicity. We offer IT solutions and expert services that eliminate the daily hurdles preventing healthcare providers from focusing entirely on their patients - powered by our vision to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. Our company culture: Our talented employees - or athenistas, as we call ourselves - spark the innovation and passion needed to accomplish our vision. We are a diverse group of dreamers and do-ers with unique knowledge, expertise, backgrounds, and perspectives. We unite as mission-driven problem-solvers with a deep desire to achieve our vision and make our time here count. Our award-winning culture is built around shared values of inclusiveness, accountability, and support. Our DEI commitment: Our vision of accessible, high-quality, and sustainable healthcare for all requires addressing the inequities that stand in the way. That’s one reason we prioritize diversity, equity, and inclusion in every aspect of our business, from attracting and sustaining a diverse workforce to maintaining an inclusive environment for athenistas, our partners, customers and the communities where we work and serve. What we can do for you: Along with health and financial benefits, athenistas enjoy perks specific to each location, including commuter support, employee assistance programs, tuition assistance, employee resource groups, and collaborative workspaces - some offices even welcome dogs. We also encourage a better work-life balance for athenistas with our flexibility. While we know in-office collaboration is critical to our vision, we recognize that not all work needs to be done within an office environment, full-time. With consistent communication and digital collaboration tools, athenahealth enables employees to find a balance that feels fulfilling and productive for each individual situation. In addition to our traditional benefits and perks, we sponsor events throughout the year, including book clubs, external speakers, and hackathons. We provide athenistas with a company culture based on learning, the support of an engaged team, and an inclusive environment where all employees are valued. Learn more about our culture and benefits here: athenahealth.com/careers, Job Description: Saab Inc., Autonomous and Undersea Systems division is seeking an innovative and experienced Senior Staff Electrical Engineer to support our growing team working…

  • 7 days ago, Job Description: Saab Inc., Autonomous and Undersea Systems division is seeking an innovative and experienced Senior Staff Electrical Engineer to support our growing team working…
  • 7 days ago +

Requirements

Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or similar, or equivalent experience. At least 3 years of experience as a software developer and 3-5 years in a security-focused development role in an agile environment. Experience in software and product design and architecture, product security, and security issue prevention and mitigation. Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages. Practical experience with Docker and Terraform. Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication. Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts. Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls. Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD. Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus. Why This Role Matters This role is central to strengthening secure software delivery across athenahealth. It combines technical depth, security leadership, and cross-functional influence to improve how security is built into products from the start. Expected Compensation $143,000 - $243,000

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · World Congress 2025

Videos

See all

Related articles

See all