Senior Application Security Engineer- Security Architecture
athenahealthAbout the role
Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.
We are looking for a Security Engineer to help increase the security capabilities of our teams. You will work closely with scrum teams, product managers, security architecture and engineering leadership to improve the quality and adoption of automation and orchestration in athena’s Security Development Lifecycle practices and security practices. But enough about us; let’s talk about you!
You are a curious problem solver with a passion for security. You love improving the quality and adoption of Security Development Lifecycle practices and you thrive working in technical leadership roles with a high degree of independence.
The Team: Join a collaborative group that solves new and interesting application security problems at scale. Use your security, engineering, and communication skills to make a difference with the company that allows medical professionals to focus on what they do best - treat patients.
Job Responsibilities
- Responsible for socializing and driving the execution of key security best practices across the R&D organization
- Contribute to enterprise security catalog of best practices, techniques and patterns to enable secure implementation of features in products/product families
- Ensure organization effective use of application security tools (SAST, DAST, SCA, API active testing), including them into unified pipeline where relevant with the goal to prevent vulnerabilities from being introduced into the product features during the development lifecycle
- Identify and explain feature level design or architectural weaknesses which could result in security issues
- Partner with key stakeholders including enterprise security leadership to track and prioritize open issues and follow up on resolution
- Work with key stakeholders like DevOps, Infrastructure, et al to build security hardened tech stacks that are used for development and production
- Document, share, and help automate coverage for common abuse cases and attacks
Typical Qualifications
- Bachelor's degree in Computer Science, Computer Engineering, Cyber Security or similar or equivalent experience
- At least 3 years experience as a software developer and 3-5 years in a security focused development role in an agile development environment
- Experience in software and product design and architecture, product security, security issue prevention and mitigation strategies
- Strong knowledge of programming languages - Java, JavaScript (NodeJS), C#, Perl, Python, etc. In addition to the ability to understand code we need a demonstrated capability to understand security bugs in it.
- Practical experience with Docker and Terraform
- Knowledge of key security technologies like OAuth, SAML, K8 etc.
- Solid understanding of the web services world including RESTful services, Service Bus architectures, JSON etc
- Current knowledge of HIPAA, HITRUST, PCI-DSS requirements
About athenahealth
Our vision: In an industry that becomes more complex by the day, we stand for simplicity. We offer IT solutions and expert services that eliminate the daily hurdles preventing healthcare providers from focusing entirely on their patients — powered by our vision to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.
Our company culture:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s