Baylor Genetics Logo

Baylor Genetics

Application Security Engineer

Posted 20 Days Ago
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Build and mature the application security program across the SDLC. Manage SAST, DAST, SCA, and IAST tooling; conduct penetration tests and vulnerability assessments; drive remediation; and embed Secure by Design practices. Partner with engineering on threat modeling, secure coding, architecture reviews, and CI/CD integration. Support HIPAA, NIST, and GDPR compliance through audits, reporting, documentation, policies, and cross-functional risk reduction initiatives.
The summary above was generated by AI

JOB SUMMARY

Baylor Genetics is seeking an Application Security Engineer to build and mature our application security program, embedding security across the software development lifecycle (SDLC) and champion Security by Design principles. As a leader in clinical genetic testing, we handle highly sensitive patient data across our web, API, and pipeline applications, and this role is central to protecting that data and reducing risk.

The engineer will implement and manage static and dynamic code analysis tooling — including SonarQube and BURP — partner closely with engineering to remediate findings, and help close audit-identified gaps in secure coding, software composition analysis, and code review coverage. This role directly supports HIPAA compliance and organizational risk reduction. Scope may evolve as organizational needs change.

KEY RESPONSIBILITIES

• Implement and manage static and dynamic code analysis, integrating SonarQube (and complementary SAST/DAST/SCA tools) into CI/CD pipelines and check-in scans, and partnering with engineering to triage and remediate findings.

• Perform penetration tests and vulnerability assessments across web, API, and pipeline applications, and lead consistent, timely remediation of identified findings.

• Develop and maintain a structured remediation program that addresses and resolves security findings quickly, consistently, and in priority order.

• Evolve Baylor Genetics' SDLC into a Secure SDLC (SSDLC) by embedding Security by Design and Privacy by Design principles at every stage.

• Integrate secure coding practices with development teams, providing guidance, threat modeling, and secure architecture reviews for new features and releases.

• Generate regular reports on the status of application security initiatives, vulnerability management, and risk assessments for technical and executive audiences.

• Collaborate with auditors during internal and external audits, providing explanations, evidence, and documentation, and drafting security policies and procedures as needed.

• Partner cross-functionally with IT, Privacy, Compliance, and business units to support initiatives and drive measurable risk reduction.


QUALIFICATIONS

Required

• Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related field — or an equivalent combination of education and experience.

• Minimum of 3–5 years of experience in application security, DevSecOps, or software engineering with a security focus.

• Hands-on experience with SonarQube for static code analysis and code quality/security gating.

• Experience with SAST, DAST, SCA, and IAST tooling and integrating them into CI/CD pipelines.

• Working knowledge of the OWASP Top 10, common attack vectors, and secure coding practices in languages such as Java, C#/.NET, Python, and JavaScript.

• Familiarity with penetration testing, code review, and vulnerability management processes.

• Understanding of compliance frameworks and regulations relevant to healthcare data, including HIPAA, NIST, and GDPR.

Preferred

• Relevant industry certifications such as OSCP, CSSLP, GWAPT, CISSP, or equivalent.

• Experience securing web applications, APIs, and cloud-native/containerized workloads.

• Knowledge of authentication and authorization frameworks (e.g., SAML, OAuth, OpenID Connect).

• Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.

COMPETENCIES

• Excellent written and verbal communication skills; ability to collaborate cross-functionally and present findings to varying audiences. Strong analytical and problem-solving skills with a risk-based mindset.

• Effective written and verbal communication, able to translate technical risk for non-technical stakeholders.

• Collaborative, cross-functional approach with the ability to influence engineering teams.

• Detail-oriented, self-directed, and able to prioritize in a fast-moving environment.


PHYSICAL DEMANDS AND WORK ENVIRONMENT

• Onsite/Hybrid role based in Houston, TX; primarily an office/laboratory-adjacent setting.

• Frequently required to sit and use hand and finger dexterity for prolonged periods.

• Occasional travel for meetings, conferences, or audits.

EEO STATEMENT

Baylor Genetics is proud to be an equal opportunity employer committed to fostering an inclusive and diverse workplace. We welcome and encourage applicants from all backgrounds to apply. We do not discriminate on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, pregnancy, childbirth, or any other status protected by applicable federal, state, or local law. If you need an accommodation during the application process, please contact our Human Resources team. 

Note to Recruiters:

We value building direct relationships with our candidates and prefer to manage our hiring process internally. While we occasionally partner with select recruitment agencies for specialized roles, we do not accept unsolicited resumes from recruiters or agencies without a written agreement executed by the authorized signatory for Baylor Genetics ("Agreement"). Any resumes submitted to Baylor Genetics in the absence of an Agreement executed by Baylor Genetics' authorized signatory will be considered the property of Baylor Genetics, and Baylor Genetics will not be obligated to pay any associated recruitment fees.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs

6 Days Ago
Remote
USA
143K-214K Annually
Senior level
143K-214K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Build and lead a scalable application security and secure SDLC program across engineering teams. Establish policies, standards, tooling, vulnerability management, threat modeling, developer enablement, security champions, software supply-chain controls, and executive reporting. Partner with development, platform, DevOps, product, and leadership teams to integrate security into CI/CD, source control, build, release, and deployment workflows while supporting audits, advisories, incident response, and regulatory requirements.
Top Skills: Api SecurityBlack DuckBurp SuiteCheckmarxCi/CdContainer Security ScanningCyclonedxDastGithub Advanced SecurityGitlab Security ToolsInfrastructure-As-Code Security ScanningKubernetesMendNist Sp 800-218Nist SsdfOwasp SammOwasp ZapSastSbomScaSecrets DetectionSemgrepSlsaSnykSonarqubeSpdxVeracodeVex
12 Days Ago
In-Office or Remote
Senior level
Senior level
Fintech • Hardware • Payments
Leads application and cloud security architecture, threat modeling, secure design reviews, security standards, and developer enablement. Owns SAST, DAST, SCA, WAF, CSPM, container, and Infrastructure as Code security controls. Builds security automation and custom tooling, supports AI security initiatives, and partners with engineering and infrastructure teams to improve application resilience, compliance, and risk remediation.
Top Skills: Api SecurityAWSAzureC#Ci/CdCis BenchmarksCspmDastDockerEcsGoInfrastructure As CodeJavaJavaScriptKubernetesLlmMtlsNist SsdfOwasp AsvsOwasp SammOwasp Top 10Owasp Top 10 For Llm ApplicationsPci DssPythonSastScaService MeshSoc 2TerraformTypescriptWafZero Trust
14 Days Ago
Easy Apply
Remote or Hybrid
Easy Apply
165K-295K Annually
Expert/Leader
165K-295K Annually
Expert/Leader
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Lead Samsara’s application security and vulnerability management programs across cloud, firmware, IoT, and corporate systems. Set technical direction, improve vulnerability remediation times, build scalable automation, guide engineering teams, mentor security engineers, communicate risk, investigate critical vulnerabilities, and support incident response. The role requires expertise in AWS, vulnerability tooling, SAST, DAST, SCA, security automation, and AI/LLM-assisted security workflows.
Top Skills: Ai/Llm ToolingAWSAws LambdaC/C++Ci/CdCvssDastEpssFedrampGoJavaScriptPythonSastScaSemgrepTinesWiz

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account