Senior Application Security Engineer
Role details
Job location
Tech stack
Job description
The Senior Application Security Engineer is responsible for embedding security throughout the software development lifecycle across Dell Medical School's cloud, platform, and enterprise application environments, including Microsoft Azure and Adobe Experience Cloud. This role partners with development, infrastructure, cybersecurity, clinical, research, and operational teams to strengthen application security, support secure software delivery, and reduce organizational risk while enabling innovation across academic, research, and healthcare environments., The Senior Application Security Engineer is responsible for integrating security into the software development lifecycle across cloud, platform, and enterprise application environments. This role leads secure code review, application security testing, vulnerability management, cloud security assessments, and secure development initiatives while partnering with development teams to ensure compliance with HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 requirements. The position supports applications used across academic, research, and clinical environments, including biomedical systems operating within healthcare settings.
Responsibilities
Secure Development and Code Review
- Develop, implement, and maintain Secure Software Development Lifecycle (SSDLC) standards supporting Azure-hosted applications, Adobe Experience Cloud, and internally managed platforms
- Support secure software development for academic, research, and clinical applications
- Perform manual and automated secure code reviews for internally developed applications, identifying vulnerabilities aligned with the OWASP Top 10 and CWE Top 25
- Integrate Static Application Security Testing (SAST) and Software Composition Analysis (SCA) into CI/CD pipelines
- Partner with development teams to remediate vulnerabilities and promote secure coding practices through guidance and education
Security Testing and Vulnerability Management
- Configure and operate Burp Suite Professional/Enterprise for Dynamic Application Security Testing (DAST) and authorized penetration testing
- Utilize OWASP ZAP for automated and on-demand application security scanning
- Perform controlled validation testing using Metasploit during authorized penetration testing engagements
- Triage, prioritize, and track remediation efforts through a risk-based vulnerability management process
- Coordinate security testing schedules with application owners to minimize operational disruption
- Support QA and automated testing initiatives validating application security controls throughout deployment pipelines
Cloud and Platform Security
- Assess Microsoft Azure environments for security posture, including identity and access management, network segmentation, and resource-level security controls
- Review Adobe Experience Cloud and SaaS/PaaS integrations to ensure secure configuration and appropriate data protection
- Support secure API design, authentication, authorization, and data validation practices
- Recommend improvements that strengthen cloud and application security architecture
AI, Robotics, and Biomedical Systems Security
- Assess the security of AI/ML models, data pipelines, and AI-enabled applications
- Review secure integration of generative AI tools, chatbots, and AI-driven APIs supporting institutional applications
- Evaluate security controls for robotics programming, automation platforms, and robotic process automation (RPA) solutions
- Support security assessments of biomedical systems and connected medical devices operating within clinical environments
- Collaborate with research, innovation, and clinical teams to embed secure development practices throughout AI and robotics initiatives
Governance, Risk, and Compliance
- Align application security practices with HIPAA, HITRUST CSF, NIST CSF 2.0, TAC 202, and UTS 165 requirements
- Support third-party risk assessments and application security reviews
- Participate in audit activities, including HITRUST readiness assessments
- Develop and maintain application security policies, standards, and procedures
Cross-Functional Collaboration
- Partner with Cybersecurity Analysts to perform threat modeling and application architecture reviews
- Collaborate with the Information Security Office (ISO) to support application security standards, vulnerability management, and incident response
- Work closely with Infrastructure, Development, and Platform Engineering teams to integrate security throughout project lifecycles
- Communicate technical findings, security risks, and recommendations to both technical and executive audiences
Marginal or Periodic Functions
- Adhere to internal controls and reporting structure
- Perform related duties as assigned
Knowledge, Skills, and Abilities
Tech Savvy
- Maintain current knowledge of secure software development, cloud security, application security testing, and emerging cybersecurity technologies
- Evaluate new tools and technologies that strengthen enterprise application security
- Apply modern security practices across cloud and software development environments
Decision Quality
- Make sound security decisions balancing organizational risk, operational needs, and regulatory requirements
- Evaluate vulnerabilities and recommend practical remediation strategies
- Prioritize security initiatives using risk-based methodologies
Manages Complexity
- Navigate complex cloud, application, and healthcare technology environments
- Balance multiple priorities across development, security, and operational initiatives
- Integrate security controls into rapidly evolving technology ecosystems
Collaborates
- Build productive working relationships with development, infrastructure, cybersecurity, clinical, research, and operational teams
- Promote security awareness and secure development practices throughout the organization
- Facilitate collaboration across multidisciplinary technical teams
Action Oriented
- Take ownership of application security initiatives and vulnerability remediation efforts
- Drive continuous improvement of secure development practices
- Respond proactively to emerging application security risks
Ensures Accountability
- Maintain accountability for application security standards and vulnerability management activities
- Promote compliance with organizational security policies and regulatory requirements
- Support secure software delivery through consistent governance and oversight
Communicates Effectively
- Communicate technical concepts clearly to technical and non-technical audiences
- Present security findings, recommendations, and risk assessments effectively
- Develop documentation supporting secure development and application security best practices, * Repetitive use of a keyboard and computer
- Hybrid work environment with on-site collaboration as business needs require
- May participate in after-hours security testing, incident response, vulnerability remediation, or critical production support activities
- May be exposed to communicable diseases, blood borne pathogens, ionizing and non-ionizing radiation, hazardous medications, and disoriented or combative patients while supporting healthcare environments
Required Materials
- Resume/CV
- 3 work references with their contact information; at least one reference should be from a supervisor
- Letter of interest
Important for applicants who are NOT current university employees or contingent workers: You will be prompted to submit your resume the first time you apply, then you will be provided an option to upload a new resume for subsequent applications. Any additional Required Materials (letter of interest, references, etc.) will be uploaded in the Application Questions section, where you may upload multiple files. Before submitting your online job application, ensure that all Required Materials have been uploaded. Once your job application has been submitted, you cannot make changes., The retirement plan for this position is Teacher Retirement System of Texas (TRS), subject to the position being at least 20 hours per week and at least 135 days in length., Employees may be required to report violations of law under Title IX and the Jeanne Clery Disclosure of Campus Security Policy and Crime Statistics Act (Clery Act). If this position is identified a Campus Security Authority (Clery Act), you will be notified and provided resources for reporting. Responsible employees under Title IX are defined and outlined in HOP-3031.
Requirements
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field; or an equivalent combination of education and professional experience
- Experience in application security, secure code review, penetration testing, or secure software development
- Hands-on experience using application security testing tools such as Burp Suite, OWASP ZAP, and Metasploit
- Experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools such as Checkmarx, Veracode, SonarQube, or similar platforms
- Experience securing cloud environments, particularly Microsoft Azure
- Experience implementing secure coding practices across common programming languages and web application frameworks
- Knowledge of secure software development lifecycle (SSDLC) methodologies
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent verbal and written communication skills
- Ability to collaborate effectively with software developers, infrastructure teams, cybersecurity professionals, and business stakeholders
Relevant education and experience may be substituted as appropriate., * Experience supporting healthcare or higher education environments
- Knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 security frameworks
- Experience securing Microsoft Azure, Adobe Experience Cloud, and SaaS/PaaS environments
- Familiarity with AI/ML security concepts, including model security, data governance, prompt injection risks, and adversarial attacks
- Experience supporting robotics, automation, robotic process automation (RPA), or biomedical system security
- Experience integrating security testing into QA processes and CI/CD pipelines
- Experience performing application threat modeling and secure architecture reviews, * Offensive Security Certified Professional (OSCP)
- GIAC Web Application Penetration Tester (GWAPT)
- Certified Secure Software Lifecycle Professional (CSSLP)
- Certified Ethical Hacker (CEH)
- Microsoft Azure Security Engineer Associate (AZ-500), A criminal history background check will be required for finalist(s) under consideration for this position., * E-Verify Poster (English and Spanish) [PDF]
- Right to Work Poster (English) [PDF]
- Right to Work Poster (Spanish) [PDF]