Application Security Engineer - Hybrid
Blue Cross Blue Shield of ArizonaAbout the role
Awarded a Healthiest Employer, Blue Cross Blue Shield of Arizona aims to fulfill its mission to inspire health and make it easy. AZ Blue offers a variety of health insurance products and services to meet the diverse needs of individuals, families, and small and large businesses as well as providing information and tools to help individuals make better health decisions.
We are hiring for a future start date of 1/1/2025.
This position is hybrid within the state of AZ only. This hybrid work opportunity requires residency, and work to be performed, within the State of Arizona.
PURPOSE OF THE JOB
- Performs ongoing security vulnerability assessments and application pen tests, including identifying, assessing, and driving remediation of application vulnerabilities. Develops security improvements for the company’s websites and backend applications and serve as a SME on website and application-related projects. Researches and recommends emerging security technologies/tools to address current and future threats and creates and maintains documentation as it relates to security designs/configuration, processes, and requirements. Participate in security incident response processes. Mentors' development teams on use of secure coding practices and evangelize secure software development practices and processes throughout the SDLC.
REQUIRED QUALIFICATIONS
Required Work Experience
- 8 years of experience with application design and development.
- 3 years as application security engineer analyzing the application modules for enhancing the application security.
Required Education
- Bachelor’s degree in business, information technology, computer systems, or related field
Required Licenses
- N/A
Required Certifications
- N/A
PREFERRED QUALIFICATIONS
Preferred Work Experience
- 10 years of experience with application design and development.
- 5 years as application security engineer analyzing the application modules for enhancing the application security.
- Proven experience with web pen testing and application vulnerability assessments
Preferred Education
- Master’s degree in business, computer science or related field
Preferred Licenses
- CISSP, CEH and/or CSSLP Certifications
Preferred Certifications
- Technical certifications in software and systems design and development
ESSENTIAL JOB FUNCTIONS AND RESPONSIBILITIES
Application security
- Participate in the building, automation, and operation automated security review capabilities across multiple technology stacks and languages throughout the SDLC
- Coordinate security code reviews, application vulnerability testing, and penetration testing, and train engineering team on best practices in application security throughout the SDLC.
- Drive assessment of applications to identify and prioritize risks, driving prioritization and remediation across application development teams.
- Be an expert on vulnerabilities and attack vectors that have the potential to impact to BCBSAZ systems
- Proactively identify and implement products and tools to ensure security of our applications, collaborating with all areas of IT to harden our environment
Strategy
- Participate in developing technical strategy; apply and promote security technology that optimizes the portfolio of technologies, tools, products, and applications.
- Work IT leaders and subject matter experts to use technology to improve overall corporate security posture.
- Deliver assessment services, develop business cases, design solution architecture, and recommend multi-phased, complex migration programs that address application security.
Project Management
- Develop timelines, work estimates, cost projections, and manage projects related to application security initiative to approved guidelines; review and consult on design and technical approach of projects to ensure consistency.
OTHER
- The position requires a full-time work schedule. Full-time is defined as working at least 40 hours per week, plus any additional hours as requested or as needed to meet business requirements.
- Position may require evening, weekend, or on-call schedules, depending on project requirements and/or system status.
- Perform all other duties as assigned.
REQUIRED COMPETENCIES
Re
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s