ForgeApply · Job listing
Senior Security Engineer - Secure SDLC
Highmark Health
See all 501 open roles at Highmark Health →
Tailor your resume for this Highmark Health job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Highmark Health's site. Free trial, no card required.
About this role
Company : enGen Job Description : JOB SUMMARY
***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)*** Highmark Health is seeking a Senior Security Engineer to join our Enterprise Application Security team and play a pivotal role in shaping how security is built into our software — not bolted on after the fact. This is a high-impact, engineering role for a security professional who is passionate about preventing vulnerabilities before they happen. You will be at the forefront of our shift-left security strategy , working directly alongside our engineering teams to embed security into every stage of the software development lifecycle — from the first line of code to production deployment. If you thrive at the intersection of security engineering & architecture , developer enablement & collaboration , and automation , and you want to build something that matters at enterprise scale in one of the nation's leading health and insurance organizations — this role is for you.
Build & Enforce Shift-Left Security Controls • Design and implement security guardrails that catch vulnerabilities at the earliest possible point in the development process, including within AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines. • Configure and enforce pipeline security gates across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts cannot advance to production without meeting defined security standards. • Deploy and manage application security scanners , including SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities across the enterprise development platform. • Develop security-as-code policies and enforcement rules that scale across a large, distributed engineering organization. • Partner with Software Delivery Enablement teams to establish security controls, governance requirements, and safe usage patterns for AI coding assistants, AI agents, and AI-enabled developer tooling.
Drive Vulnerability Risk Reduction • Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators. • Establish and track remediation SLAs aligned to vulnerability severity and business risk, with a focus on eliminating Critical and High findings before they reach production. • Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms. • Conduct root cause analysis on recurring vulnerability patterns and drive systemic improvements through tooling, standards, secure development practices, and developer education. • Monitor and report on key security health metrics including Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and AI security risk reduction metrics.
Automate & Optimize the Security Toolchain • Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering high-fidelity, actionable signal. • Evaluate, onboard, and operationalize emerging security technologies that improve visibility and governance over AI-assisted software development and software supply chains. • Build automation workflows for vulnerability triage, escalation, assignment, and reporting, reducing manual overhead and accelerating response times. • Continuously optimize scanner configurations to minimize false positives and maximize detection accuracy. • Develop dashboards and reporting pipelines that give engineering and security leadership real-time visibility into application security posture, AI security adoption , and policy compliance. • Integrate security controls and monitoring into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.
Enable & Empower Developers • Serve as a trusted, embedded security advisor to engineering teams, providing hands-on guidance, code review support, AI security consultation, and practical remediation recommendations. • Design and deliver security training, workshops, and reference materials that make secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable for developers at all levels. • Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization. • Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries that reduce security burden on development teams. • Develop guidance and reference architectures for secure implementation of LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications. • Partner with development, architecture, and platform teams to embed secure-by-default AI development practices throughout the SDLC.
Measure, Report & Continuously Improve • Define, track, and report on AppSec KPIs that demonstrate program effectiveness and drive continuous improvement. • Establish and report on AI security metrics such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings. • Conduct regular security posture reviews and present findings, trends, and recommendations to engineering and security leadership. • Support audit, risk, and compliance activities by ensuring security controls, AI governance requirements , and secure development standards are d
Salary insight
This posting doesn't disclose pay. Across 1,936 Washington DC jobs with disclosed salaries on ForgeApply, the median is $132k.
See full Security Engineer salary data for Washington DC →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Highmark Health role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Engineer — Zip · San Francisco
- Senior Security Engineer — Abnormalsecurity · Remote
- Senior Security Engineer — Vectranetworks · Chicago, US
- Senior Security Engineer — Decagon · San Francisco
- Senior Security Engineer — Karbon · Austin, TX, United States; Chicago, IL, United States; Dallas, TX, United States; Denver, CO, United States; Los Angeles, CA, United States; San Diego, CA, United States; San Francisco, CA, United States
- Senior Security Engineer — Plaud · San Francisco, CA
- Senior Security Engineer — Stratacareers · Chicago, IL
- Senior Security Engineer — Smarterdx · Remote
More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Washington DC · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview