> Markdown version of [/jobs/ext/615505-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/615505-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Tempus Inc - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $130,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Testing (Software), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing Security, Dicom, Python (Programming Language), Open Web Application Security, Windows PowerShell, Reverse Engineering, Mobile Security, TypeScript, Web Applications, Scripting, Google Cloud, GWAPT, Health Level Seven International, Graphql - **Published:** June 23, 2026 - **Apply:** https://www.dice.com/job-detail/23b7b9f8-15dc-4e9b-86c0-7d4871704c3c ## About the Role * 5+ years of experience in penetration testing, ideally within healthcare or highly regulated environments. * Expert knowledge of web/API vulnerabilities (OWASP Top 10) and mobile testing frameworks (Frida, Burp Suite, MobSF, Ghidra). * Understanding of medical protocols (DICOM, HL7) and cloud security practices (AWS, Azure, or Google Cloud Platform). * Proficiency in scripting languages (Python, JavaScript/TypeScript, Go) and secure SDLC practices. * Excellent analytical, problem-solving, and interpersonal communication skills. Preferred Certifications * Offensive Security: OSCP, OSCE, or OSWE. * Mobile Security: eCMAP or GMOB. * General/Regulated: CEH, CSSLP, GPEN, GWAPT, or UL 2900 training. ## Description * Execute advanced black-box and grey-box penetration tests on web applications, APIs (REST/GraphQL), and internal systems. * Perform deep-dive mobile security assessments on iOS and Android, including reverse engineering and bypassing client-side controls like root detection and certificate pinning. * Lead specialized security testing and threat modeling for FDA-regulated medical device software, ensuring compliance with HIPAA, GDPR, and FDA cybersecurity guidelines. * Develop high-quality technical reports detailing exploit chains and business logic flaws, providing engineering teams with hands-on remediation guidance. * Automate security testing by developing custom tools and scripts in languages such as Python, Go, or PowerShell. * Communicate complex security risks and business impacts to executive leadership and cross-functional stakeholders. * Mentor junior team members and provide security training to development teams to foster a robust culture of security awareness. ## Related Videos - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [GraphQL + Apollo + Next.js: A Lovely Trio](https://www.wearedevelopers.com/videos/311-graphql-apollo-next-js-a-lovely-trio) - [Event based cache invalidation in GraphQL](https://www.wearedevelopers.com/videos/433-event-based-cache-invalidation-in-graphql) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)