Senior Application Security Engineer

Tempus AI · Vertical AI · Chicago, IL

Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities in web, mobile, and medical device applications, safeguarding sensitive healthcare data and ensuring compliance with regulations like HIPAA and GDPR.

What you'd actually do

  1. Conduct penetration tests on web, mobile, and software medical device applications, as well as internal systems.
  2. Lead threat modeling and risk assessment activities for new and existing products.
  3. Develop and execute test plans, scenarios, scripts, or procedures.
  4. Document findings, prepare detailed reports, and work with development teams to remediate identified issues.
  5. Track and manage vulnerabilities through their lifecycle.

Skills

Required

  • penetration testing
  • security principles
  • security tools (e.g., Burp Suite, Snyk, Metasploit, Nmap)
  • programming/scripting languages (Python, JavaScript/TypeScript)
  • cloud security (AWS, Azure, GCP)
  • secure SDLC practices
  • problem-solving
  • analytical skills
  • communication skills
  • interpersonal skills

Nice to have

  • OSCP
  • GPEN
  • OSCE
  • GWAPT
  • CSSLP
  • mentoring junior team members
  • training others in security best practices

What the JD emphasized

  • healthcare or other highly regulated environments
  • HIPAA
  • GDPR