Lead Application Security Engineer- DevSecOps
AI summary of the role
Lead Security Engineer owning application security capabilities and the API security testing program at a healthcare SaaS company.
What you’ll do
- Own technical direction, implementation, and operation of application security capabilities including SAST, SCA, DAST, and API security testing.
- Lead the API security testing program: discovery, authenticated/unauthenticated testing, scanner attribution, onboarding, findings routing, and operational readiness.
- Drive adoption of Security Development Lifecycle best practices across the R&D organization.
- Partner with DevOps, Infrastructure, IAM, API Gateway, NOC, and Enterprise Security to design and operate security-hardened platforms.
What you’ll bring
- Bachelor's degree in CS, Computer Engineering, Cyber Security, or equivalent experience.
- At least 3 years as a software developer and 3–5 years in a security-focused development role in an agile environment.
- Strong software engineering background with ability to develop, review, and troubleshoot code in one or more languages.
- Practical experience with Docker and Terraform.
Technologies
SAST · SCA · DAST · API security · OAuth 2.0 · OpenID Connect · JWT · SAML · Docker · Terraform · CI/CD · IAM
About Athena Health
Cloud healthcare software and services for ambulatory practices, combining EHR, revenue cycle, patient engagement, epocrates, and embedded services on a large provider network.
Acquired · 5000+ people
Source and classification
Internal deployment & tooling · Evidence for this classification:
Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security. This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes. About the Team This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering,
More from the job description
Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security. This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes. About the Team This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment. Core Responsibilities Security strategy and SDLC adoption Socialize and drive execution of key security best practices across the R&D organization. Contribute to the enterprise security catalog of best practices, techniques, and patterns. Improve the quality and adoption of Security Development Lifecycle practices. Application security capability ownership Own the evaluat [... source excerpt omitted ...] full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates. Base pay is only one part of our competitive Total Rewards package - depending on role eligibility, we offer both short and long-term incentives by way of an annual discretionary bonus plan, variable compensation plan, and equity plans. About athenahealth Our vision: In an industry that becomes more complex by the day, we stand for simplicity. We offer IT solutions and expert services that eliminate the daily hurdles preventin [... source excerpt omitted ...] ty, equity, and inclusion in every aspect of our business, from attracting and sustaining a diverse workforce to maintaining an inclusive environment for athenistas, our partners, customers and the communities where we work and serve. What we can do for you: Along with health and financial benefits, athenistas enjoy perks specific to each location, including commuter support, employee assistance programs, tuition assistance, employee resource groups, and collaborative workspaces — some offices even welcome dogs. We also encourage a better work-life balance for athenistas with our flexibility. While we know in-office collaboration is critical to our vision, we recognize that
Employer postings · Data from · Sources