Applications Security Engineer II
Remote-MO, United States
You could be the one who changes everything for our 28 million members by using technology to improve health outcomes around the world. As a diversified, national organization, Centene's technology professionals have access to competitive benefits including a fresh perspective on workplace flexibility.
Position Purpose:
Applies cybersecurity and privacy principles to ensure the organization's applications and services are implemented according to internal security standards. Recognizes vulnerabilities in security systems (e.g., vulnerability and compliance scanning). Performs threat modeling, security code reviews, security assessments, security hardening reviews, evaluates security designs, etc. throughout the Secure Software Development Life Cycle (SSDLC) process. Engineers and develops cloud automation routines to streamline operations. Promotes understanding and adherence to the SSDLC Policy and Standards.
- Monitor daily activities and reports from application security testing (AST) platforms (Tier 2 support).
- Review and manage escalated weaknesses and vulnerabilities from Tier 1 Engineers.
- Promote understanding and adherence to the secure SDLC policy and standard.
- Review and improve existing standard operating plans (SOPs), policies, and procedures for the response and recovery from incidents.
- Assist in development of training on application security test procedures, DevSecOps maturity, tool integrations and strategy.
- Performs other duties as assigned.
- Complies with all policies and standards.
Education/Experience:
A Bachelor's degree in a quantitative or business field (e.g., statistics, mathematics, engineering, computer science).
Requires 2 – 4 years of related experience.
Or equivalent experience acquired through accomplishments of applicable knowledge, duties, scope and skill reflective of the level of this position.
Technical Skills:
- Basic knowledge of programming and/or scripting languages including, but not limited to C#, Java, Go, JavaScript, Bash, PowerShell.
- Knowledge of application security testing (AST) platforms such as Snyk, Veracode, Netsparker, AppScan, NowSecure, Contrast, etc.
- Knowledge of API security platforms such as Traceable.ai, Salt, Noname Security, etc.
- Knowledge of administrating containerized applications running within Kubernetes.
- Knowledge of administrating applications and/or security tools running within AWS.
- Understanding of DevOps workflows.
- Understanding of CIA triad.
- Standard Operating Procedure development.
- Understanding of Agile operations.
Soft Skills:
- Intermediate - Seeks to acquire knowledge in area of specialty
- Intermediate - Ability to identify basic problems and procedural irregularities, collect data, establish facts, and draw valid conclusions
- Intermediate - Ability to work independently
License/Certification:
- Associate level IT Security certification, ex. AWS, Azure, GIAC, Security+ce, etc. preferred.
Centene offers a comprehensive benefits package including: competitive pay, health insurance, 401K and stock purchase plans, tuition reimbursement, paid …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
Holidays MO
Benefits/Perks401(k) Competitive benefits Competitive pay Comprehensive benefits Comprehensive benefits package Flexible approach Flexible work schedules Health insurance Holidays Paid Time Off Stock purchase Stock purchase plans Tuition reimbursement Workplace flexibility
Tasks- Automation
- Compliance
- Ensure security standards
- Perform security assessments
- Review security policies
- Test
- Testing
Access Agile AI API API security Application security testing Automation AWS Azure Bash Benefits Business C Cloud Cloud Automation Compliance Cybersecurity DevOps DevSecOps Education Flexibility Go Health Insurance Health outcomes Insurance Java Javascript Kubernetes Mathematics Operations PowerShell Procedures Programming Scripting Scripting Languages SDLC Secure SDLC Security Security assessments Soft Software Software Development Software development life cycle SOP Development Statistics Strategy Technology Testing Threat modeling Training Vulnerability Scanning
Experience2-4 years
EducationAS Bachelor's Bachelor's degree Business Business Field Computer Science Education Engineering Equivalent Equivalent experience Insurance IT Mathematics Statistics
CertificationsAWS Azure Certification CIA GIAC
TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9