UT Austin logo
UT AustinPosted 1 month ago

Senior Application Security Engineer

$120,000–$120,000 year

On-siteAustin, Texas, United States

Full TimeSenior LevelEnterprise

Job Summary

Lead secure software development lifecycle (SSDLC) initiatives across Dell Medical School's cloud, platform, and enterprise application environments, including Microsoft Azure and Adobe Experience Cloud. Perform manual and automated secure code reviews, configure Burp Suite and OWASP ZAP for dynamic and static application security testing, and integrate SAST and Software Composition Analysis into CI/CD pipelines. Manage vulnerability remediation efforts through risk-based triage while partnering with development, infrastructure, and clinical teams to ensure compliance with HIPAA, HITRUST, and NIST CSF 2.0 standards. Assess security posture for AI/ML models, robotics, and biomedical systems, supporting secure API design and threat modeling. Work 40 weekly hours in a hybrid environment, with no employer-sponsored work authorization available.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field
  • Minimum of eight (8) years of experience in application security, secure code review, penetration testing, or secure software development
  • Hands-on experience using Burp Suite, OWASP ZAP, and Metasploit for application security testing and vulnerability validation
  • Experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools such as Checkmarx, Veracode, SonarQube, or similar platforms
  • Experience securing Microsoft Azure and other cloud environments
  • Experience implementing secure coding practices across common programming languages and web application frameworks
  • Knowledge of Secure Software Development Lifecycle (SSDLC) methodologies
  • Strong analytical, troubleshooting, and problem-solving skills
  • Excellent verbal and written communication skills
  • Ability to collaborate effectively with software developers, infrastructure teams, cybersecurity professionals, and business stakeholders

Desired Qualifications

  • Experience supporting healthcare or higher education environments
  • Knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 security frameworks
  • Experience securing Microsoft Azure, Adobe Experience Cloud, SaaS/PaaS platforms, and cloud-native applications
  • Familiarity with AI/ML security concepts, including model security, data governance, prompt injection risks, and adversarial attacks
  • Experience supporting robotics, robotic process automation (RPA), biomedical systems, or connected medical devices
  • Experience integrating application security testing into QA processes, automated testing frameworks, and CI/CD pipelines
  • Experience performing application threat modeling, secure architecture reviews, and third-party risk assessments (TPRM)
  • Offensive Security Certified Professional (OSCP)
  • GIAC Web Application Penetration Tester (GWAPT)
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Certified Ethical Hacker (CEH)
  • Microsoft Azure Security Engineer Associate (AZ-500)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce