Skip to main content
Ensemble

Senior Application Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
$101k–$152.4k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior application security engineer for a remote US/nationwide role. Needs deep AppSec tooling experience across SAST, DAST, SCA, IaC and secret scanning, secure coding/SDLC integration, scripting/programming, and Agile/DevOps collaboration. Must be able to travel onsite to client, temporary, or corporate office locations as business needs require.

Core skills

SASTDASTSCA

Required skills

IaC scanningSecret scanning.NETPythonJavaScriptCI/CDAha! IdeasServiceNow

What you'll do

  • Serve as a key member of the Cybersecurity Technical Assessments team, providing advanced expertise in secure software development practices and application tooling.
  • Manage and optimize the application security tool stack—including SAST, DAST, SCA, IaC scanning, and secret detection—and ensure its effective integration into the software development lifecycle.
  • Collaborate with development, engineering, and product teams to identify, triage, and remediate vulnerabilities.
  • Mentor junior engineers and contribute to the evolution of secure development practices across the organization.
  • Manage and optimize application security tools (SAST, DAST, SCA, IaC, secret scanning) and ensure effective integration into CI/CD pipelines and the SDLC lifecycle.
  • Analyze source code and infrastructure-as-code for security vulnerabilities and provide actionable remediation guidance.
  • Validate and triage findings from security tools, removing false positives and ensuring accurate issue tracking.
  • Create and manage remediation tickets (e.g., Aha! Ideas, ServiceNow Requests), ensuring vulnerabilities are prioritized, assigned, and tracked to resolution.
  • Collaborate with development and engineering teams to validate remediation efforts and confirm closure of security issues.
  • Participate in the risk management process by documenting, reviewing, and maintaining risk exceptions for unresolved or accepted vulnerabilities.
  • Work with risk owners and business stakeholders to ensure appropriate compensating controls are in place and documented.
  • Lead secure code reviews and contribute to threat modeling and design discussions for high-risk applications.
  • Mentor junior engineers and provide technical guidance on secure development practices.
  • Contribute to the development and refinement of secure coding standards, policies, and procedures.
  • Develop and maintain dashboards and reports that communicate application security posture, remediation progress, and risk trends to leadership.
  • Identify recurring security issues and propose systemic improvements to reduce future risk.
  • Lead efforts to evaluate, pilot, and implement new application security tools and integrations that enhance automation and coverage.
  • Continuously refine scanning configurations and policies to improve signal-to-noise ratio in findings.
  • Stay informed on emerging threats, vulnerabilities, and industry trends, and recommend improvements to tooling and processes.
  • Participate in the evaluation and onboarding of new security tools and technologies.
  • Work closely with cross-functional stakeholders to analyze and troubleshoot complex production issues.

What they require

  • Deep expertise in application security tooling (SAST, DAST, SCA, IaC scanning, secret scanning).
  • Strong understanding of secure coding principles and SDLC integration.
  • Proficiency in scripting and programing languages (e.g., .NET, Python, JavaScript).
  • Ability to analyze and validate security findings, prioritize risk, and guide remediation.
  • Strong attention to detail in identifying false positives and systemic security gaps.
  • Ability to clearly communicate technical issues to both technical and non-technical stakeholders.
  • Skilled in writing documentation, reports, and presenting findings to cross-functional teams.
  • Experience working in Agile/DevOps environments with cross-functional teams.
  • Ability to mentor junior engineers and lead small-scale security initiatives.
  • Ability to work effectively with a remotely located team spanning multiple time zones.
  • Commitment to staying current with evolving security tools, threats, and best practices.
  • Active pursuit of professional development and relevant certifications.
  • Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
  • Candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.

Benefits

  • Associate Benefits – We offer a comprehensive benefits package designed to support the physical, emotional, and financial health of you and your family, including healthcare, time off, retirement, and well-being programs.
  • Our Culture – Ensemble is a place where associates can do their best work and be their best selves.
  • Our culture is rooted in collaboration, growth, and innovation.
  • Growth – We invest in your professional development.
  • Each associate will earn a professional certification relevant to their field and can obtain tuition reimbursement.
  • Recognition – We offer quarterly and annual incentive programs for all employees who go beyond and keep raising the bar for themselves and the company.
  • Five-time winner of “Best in KLAS” 2020-2022, 2024-2025.
  • Black Book Research's Top Revenue Cycle Management Outsourcing Solution 2021-2024.
  • 22 Healthcare Financial Management Association (HFMA) MAP Awards for High Performance in Revenue Cycle 2019-2024.
  • Leader in Everest Group's RCM Operations PEAK Matrix Assessment 2024.
  • Clarivate Healthcare Business Insights (HBI) Revenue Cycle Awards for strong performance 2020, 2022-2023.
  • Energage Top Workplaces USA 2022-2024.
  • Fortune Media Best Workplaces in Healthcare 2024.
  • Monster Top Workplace for Remote Work 2024.
  • Great Place to Work certified 2023-2024.
  • Innovation.
  • Work-Life Flexibility.
  • Leadership.
  • Purpose + Values.

Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups.

HealthcareEnterpriseensemble-mouvement.com/

What people say about this company

3.4/ 5

$101k–$152.4k/yr