Application Security Engineer

Tempus Inc
Chicago, IL, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Testing (Software) JavaScript (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Business Logic Software System Penetration Testing Microsoft Azure Burp Suite Cloud Computing Security Dicom Python (Programming Language) Open Web Application Security
+10 more
Windows PowerShell Reverse Engineering Mobile Security TypeScript Web Applications Scripting Google Cloud GWAPT Health Level Seven International Graphql

Job description

  • Execute advanced black-box and grey-box penetration tests on web applications, APIs (REST/GraphQL), and internal systems.
  • Perform deep-dive mobile security assessments on iOS and Android, including reverse engineering and bypassing client-side controls like root detection and certificate pinning.
  • Lead specialized security testing and threat modeling for FDA-regulated medical device software, ensuring compliance with HIPAA, GDPR, and FDA cybersecurity guidelines.
  • Develop high-quality technical reports detailing exploit chains and business logic flaws, providing engineering teams with hands-on remediation guidance.
  • Automate security testing by developing custom tools and scripts in languages such as Python, Go, or PowerShell.
  • Communicate complex security risks and business impacts to executive leadership and cross-functional stakeholders.
  • Mentor junior team members and provide security training to development teams to foster a robust culture of security awareness.

Requirements

  • 5+ years of experience in penetration testing, ideally within healthcare or highly regulated environments.
  • Expert knowledge of web/API vulnerabilities (OWASP Top 10) and mobile testing frameworks (Frida, Burp Suite, MobSF, Ghidra).
  • Understanding of medical protocols (DICOM, HL7) and cloud security practices (AWS, Azure, or Google Cloud Platform).
  • Proficiency in scripting languages (Python, JavaScript/TypeScript, Go) and secure SDLC practices.
  • Excellent analytical, problem-solving, and interpersonal communication skills.

Preferred Certifications

  • Offensive Security: OSCP, OSCE, or OSWE.
  • Mobile Security: eCMAP or GMOB.
  • General/Regulated: CEH, CSSLP, GPEN, GWAPT, or UL 2900 training.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:30 min

Scaling agile frameworks and data interoperability in healthcare

Leo Lindhorst · World Congress 2022

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

4:33 min

Overview of the GraphQL API query language

William Lyon · LIVE

2:24 min

Comparing Neo4j and GraphQL conceptual models

William Lyon · LIVE

Videos

See all

Related articles

See all