- Company Name
- Tempus AI
- Job Title
- Senior Application Security Engineer
- Job Description
-
Job title: Senior Application Security Engineer
Role summary: Lead the design, execution, and remediation of application security assessments for web, mobile, and medical device platforms to protect sensitive healthcare data and support secure product delivery.
Expectations: • Deliver high‑quality penetration tests and threat models for new and existing products. • Drive vulnerability management throughout the lifecycle. • Provide mentorship and security training to development teams. • Ensure compliance with healthcare and data privacy regulations.
Key responsibilities:
• Conduct penetration tests on web, mobile, and medical device applications and internal systems.
• Lead threat‑modeling, risk assessment, and secure‑design reviews for new and major changes to products.
• Develop, execute, and maintain test plans, scripts, and automation tools.
• Document findings, create detailed reports, and partner with developers to remediate vulnerabilities.
• Track vulnerabilities, coordinate remediation, and verify fixes.
• Develop and maintain custom security testing tools and automation scripts.
• Assist in the creation and maintenance of application security policies, standards, and guidelines.
• Collaborate with security and IT teams to strengthen overall security posture.
• Provide security awareness training to application development teams.
• Evaluate third‑party applications, vendors, and services for security risks.
• Mentor junior team members and contribute to a culture of security excellence.
Required skills:
• Minimum 5 years of proven experience in penetration testing, preferably in healthcare or regulated environments.
• Strong understanding of security principles, techniques, and technologies (OWASP, SDLC, secure coding).
• Proficiency with security tools such as Burp Suite, Metasploit, Nmap, Snyk, etc.
• Competent in scripting/programming (Python, JavaScript/TypeScript, or similar).
• Experience with cloud security (AWS, Azure, GCP) and secure SDLC practices.
• Excellent analytical, problem‑solving, communication, and interpersonal skills.
Required education & certifications:
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent work experience).
• Relevant certifications highly desirable: OSCP, GPEN, OSCE, GWAPT, CSSLP, or equivalent.
---