Application Security Engineer
Tempus Inc
Chicago, IL, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$130,000.0 - $180,000.0
Working hours
Regular working hours
Job source
Tech stack
Testing (Software)
JavaScript (Programming Language)
Application Programming Interfaces (APIs)
Amazon Web Services
Business Logic
Software System Penetration Testing
Microsoft Azure
Burp Suite
Cloud Computing Security
Dicom
Python (Programming Language)
Open Web Application Security
+10 more
Windows PowerShell
Reverse Engineering
Mobile Security
TypeScript
Web Applications
Scripting
Google Cloud
GWAPT
Health Level Seven International
Graphql
Job description
- Execute advanced black-box and grey-box penetration tests on web applications, APIs (REST/GraphQL), and internal systems.
- Perform deep-dive mobile security assessments on iOS and Android, including reverse engineering and bypassing client-side controls like root detection and certificate pinning.
- Lead specialized security testing and threat modeling for FDA-regulated medical device software, ensuring compliance with HIPAA, GDPR, and FDA cybersecurity guidelines.
- Develop high-quality technical reports detailing exploit chains and business logic flaws, providing engineering teams with hands-on remediation guidance.
- Automate security testing by developing custom tools and scripts in languages such as Python, Go, or PowerShell.
- Communicate complex security risks and business impacts to executive leadership and cross-functional stakeholders.
- Mentor junior team members and provide security training to development teams to foster a robust culture of security awareness.
Requirements
- 5+ years of experience in penetration testing, ideally within healthcare or highly regulated environments.
- Expert knowledge of web/API vulnerabilities (OWASP Top 10) and mobile testing frameworks (Frida, Burp Suite, MobSF, Ghidra).
- Understanding of medical protocols (DICOM, HL7) and cloud security practices (AWS, Azure, or Google Cloud Platform).
- Proficiency in scripting languages (Python, JavaScript/TypeScript, Go) and secure SDLC practices.
- Excellent analytical, problem-solving, and interpersonal communication skills.
Preferred Certifications
- Offensive Security: OSCP, OSCE, or OSWE.
- Mobile Security: eCMAP or GMOB.
- General/Regulated: CEH, CSSLP, GPEN, GWAPT, or UL 2900 training.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago