ForgeApply
Try it free

ForgeApply · Job listing

Senior Security Engineer - Secure SDLC

Highmark Health

Remote · Working at Home - Pennsylvania, PA | Working at Home - Maryland, US

See all 501 open roles at Highmark Health

Tailor your resume for this Highmark Health job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Highmark Health's site. Free trial, no card required.

About this role

Company : enGen Job Description :  JOB SUMMARY

***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)*** Highmark Health is seeking a   Senior Security Engineer   to join our Enterprise Application Security team and play a   pivotal role   in shaping how security is built into our software —   not bolted on after the fact. This is a   high-impact, engineering role   for a security professional who is   passionate about preventing vulnerabilities before they happen.   You will be at the forefront of our   shift-left security strategy , working directly alongside our engineering teams to   embed security into every stage of the software development lifecycle   — from the first line of code to production deployment. If you thrive at the intersection of   security engineering & architecture ,   developer enablement & collaboration , and   automation , and you want to   build something that matters at enterprise scale   in one of the nation's leading health and insurance organizations —   this role is for you.

Build & Enforce Shift-Left Security Controls • Design and implement security guardrails   that catch vulnerabilities at the earliest possible point in the development process, including within   AI-assisted development workflows, IDEs, at commit time, and within CI/CD pipelines. • Configure and enforce pipeline security gates   across the enterprise, ensuring code, AI-generated code, infrastructure-as-code, and deployment artifacts   cannot advance to production without meeting defined security standards. • Deploy and manage application security scanners , including   SAST, Dependency Scanning, Container Scanning, Secret Detection, DAST, API Security Testing, and emerging AI/LLM security assessment capabilities   across the enterprise development platform. • Develop security-as-code policies and enforcement rules   that scale across a large, distributed engineering organization. • Partner with Software Delivery Enablement teams   to establish security controls, governance requirements, and safe usage patterns for   AI coding assistants, AI agents, and AI-enabled developer tooling.

Drive Vulnerability Risk Reduction • Lead risk-based triage and prioritization of detected vulnerabilities , leveraging exploitability signals such as   EPSS scores, Known Exploited Vulnerability (KEV) status, reachability analysis, and emerging AI-specific risk indicators. • Establish and track remediation SLAs   aligned to vulnerability severity and business risk, with a focus on   eliminating Critical and High findings before they reach production. • Identify and remediate security risks associated with AI-generated code, AI-enabled applications, model integrations, prompt injection vulnerabilities, insecure agent behaviors, and exposure of sensitive data to AI platforms. • Conduct root cause analysis   on recurring vulnerability patterns and drive   systemic improvements   through tooling, standards, secure development practices, and developer education. • Monitor and report on key security health metrics   including   Mean Time to Remediate (MTTR) , security debt trends, pre- versus post-production detection rates, and   AI security risk reduction metrics.

Automate & Optimize the Security Toolchain • Architect and maintain the enterprise application security toolchain , ensuring tools are properly integrated, tuned, and delivering   high-fidelity, actionable signal. • Evaluate, onboard, and operationalize emerging security technologies   that improve visibility and governance over   AI-assisted software development and software supply chains. • Build automation workflows   for vulnerability triage, escalation, assignment, and reporting,   reducing manual overhead and accelerating response times. • Continuously optimize scanner configurations   to minimize false positives and maximize detection accuracy. • Develop dashboards and reporting pipelines   that give engineering and security leadership   real-time visibility   into application security posture,   AI security adoption , and policy compliance. • Integrate security controls and monitoring   into approved AI development platforms, coding assistants, model gateways, and agentic development workflows.

Enable & Empower Developers • Serve as a trusted, embedded security advisor   to engineering teams, providing   hands-on guidance, code review support, AI security consultation, and practical remediation recommendations. • Design and deliver security training, workshops, and reference materials   that make   secure coding, secure AI development, and responsible use of AI coding assistants accessible and actionable   for developers at all levels. • Build and grow a Security Champions program , embedding security advocates within engineering teams to extend the AppSec program's reach across the organization. • Create and maintain secure coding standards, secure AI development standards, design patterns, and reusable security libraries   that reduce security burden on development teams. • Develop guidance and reference architectures   for secure implementation of   LLMs, AI copilots, agentic workflows, model integrations, and AI-enabled business applications. • Partner with development, architecture, and platform teams   to embed   secure-by-default AI development practices   throughout the SDLC.

Measure, Report & Continuously Improve • Define, track, and report on AppSec KPIs   that demonstrate program effectiveness and drive continuous improvement. • Establish and report on AI security metrics   such as AI tooling adoption, policy compliance, AI risk assessments completed, AI-generated code review coverage, and identified AI-related security findings. • Conduct regular security posture reviews   and present findings, trends, and recommendations to engineering and security leadership. • Support audit, risk, and compliance activities   by ensuring security controls,   AI governance requirements , and secure development standards are d

Salary insight

This posting doesn't disclose pay. Across 1,936 Washington DC jobs with disclosed salaries on ForgeApply, the median is $132k.

See full Security Engineer salary data for Washington DC

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Highmark Health role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Washington DC · Browse all jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview