Full-Time

US – Senior Application Security Engineer

Posted on 3/21/2023

PointClickCare

PointClickCare

1,001-5,000 employees

Cloud-based healthcare software platform


Senior

Remote in USA

Required Skills
Microsoft Azure
Agile
Python
JavaScript
Communications
MySQL
Management
Ruby
Ruby on Rails
SQL
Java
AWS
Perl
C/C++
Development Operations (DevOps)
Requirements
  • OPEN TO US & CANADIAN CANDIDATES
  • The Senior Application Security Engineer will be part of a team driving embedding security seamlessly into the product development lifecycle, focusing on reducing risk in our software delivery processes. The Senior Application Security Engineer will serve as a technical interface, key adviser and subject matter expert working with Engineering, Product Management, SaaSOps, and DevOps teams to determine security requirements and support development, testing and delivery of secure products in a modern public cloud architecture and to ensure a secure PointClickCare SaaS delivered product platform. You can expect to work closely with software development teams as well as third party organizations to ensure that security, privacy, and compliance requirements are planned for, designed, and built into software applications
  • Bachelor's Degree in Information Technology or the equivalent combination of education, training or experience
  • Significant experience in the field of cybersecurity and/or application security, including time as an engineer writing code, conducting code reviews or in a senior role contributing to secure software design, development and testing processes
  • Expert knowledge in security best practices, principles, and common security frameworks such as OWASP, NIST and ISO
  • Familiarity with common security libraries, security controls, and common security flaws
  • Basic development or scripting experience and skills. Ruby and Ruby on Rails is preferred
  • Experience building secure software based on frameworks such OWASP, BSIMM and SANS
  • Significant experience with methodologies and security testing tools for threat analysis of complex applications and services including threat modeling, software fuzzing, static and dynamic analysis and penetration testing (SAST, DAST, RASP, SCA) and other application security testing tools and techniques
  • Knowledge of common scripting and compiled languages including C#, Java, JavaScript, Python, Perl, PowerShell, and the .NET development frameworks. Full stack experience including MySQL/SQL preferred
  • Knowledge of secure architecture and design patterns for Web, Mobile and Microservices
  • Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
  • Advanced organizational, planning, communication, analytical and time management skills
  • Experience working with developers
  • Excellent and professional communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner
  • Experience identifying security issues through code review
  • Experience in integrating security solutions into CI-CD pipelines and automating tooling orchestration
  • Understand DevSecOps cultural mindsets, and an engineering focused approach to solving complex security problems
  • Desired Qualifications
  • Advanced degree in Information Technology, or the equivalent combination of education, training or experience CISSP, CISM or other related Information Security certifications
  • Experience in SaaS and/or health care environments
  • Experience with API security testing
  • #LI-TP1
  • #LI-Hybrid/Remote
  • When you apply for a position, your information is processed and stored with Lever, in accordance with Lever's Privacy Policy. We use this information to evaluate your candidacy for the posted position. We also store this information, and may use it in relation to future positions to which you apply, or which we believe may be relevant to you given your background. When we have no ongoing legitimate business need to process your information, we will either delete or anonymize it. If you have any questions about how PointClickCare uses or processes your information, or if you would like to ask to access, correct, or delete your information, please contact PointClickCare's human resources team: [email protected]
  • PointClickCare is committed to Information Security. By applying to this position, if hired, you commit to following our information security policies and procedures and making every effort to secure confidential and/or sensitive information
Responsibilities
  • Provide subject matter expertise on secure architecture, design and coding practices based on current knowledge of security threats and vulnerabilities that could impact the technology stack Participate in and support application security reviews and threat modeling, including code review and dynamic testing
  • Own and perform application security vulnerability management
  • Facilitate and support the preparation of security releases
  • Support and consult with Product and Engineering teams in the area of application security
  • Assist in development of automated security testing to validate that secure coding best practices are being used
  • Identify solutions for difficult security problems while collaborating in a broader agile Application Security team
  • Building a comprehensive solution to conduct consolidation, aggregation, and notification of security findings to respective stakeholders
  • Perform application testing and review security test results from scans and penetration testing to identify viable vulnerabilities that may be exploited and propose remediation solutions or mitigation controls
  • Develop security controls and processes for products and services developed and deployed for both on-prem and cloud environments
  • Perform threat modeling, conduct security architecture reviews and provide training to architects and developers to enhance adoption of secure coding practice within the product development lifecycle
  • Provide security related coaching, training and expertise to drive and elevate security expertise within the development teams
  • Responsible for promoting, designing, and evaluating application security in all phases of the software development life cycle, and constantly looking for innovative ways to improve processes
  • Understanding of and experience securing cloud infrastructure and applications using contemporary cloud computing models (IaaS, PaaS, SaaS, etc) with emphasis on Azure/AWS technologies
  • Write proof of concept code to demonstrate the severity of a potential security issue

PointClickCare, a leader in cloud-based healthcare software, offers a work environment focused on integrating essential patient data and boosting care outcomes. Employees can take pride in contributing to a system that enhances care coordination and optimizes financial processes for healthcare providers, fostering a significant impact on the industry. This commitment to improving healthcare efficiency and outcomes makes it an appealing place for professionals passionate about making a meaningful difference in the sector.

Company Stage

Private

Total Funding

$231M

Headquarters

Mississauga, Canada

Founded

2000

Growth & Insights
Headcount

6 month growth

4%

1 year growth

5%

2 year growth

30%

Benefits

Competitive financial rewards & equity potential

Comprehensive benefits available from day 1

Midweek mingles with free lunch

Wellness spending account

Retirement savings plan with employer match

Flexible PTO

Hybrid work models

Parental leave

Family planning support

Training & development programs

Corporate discounts program

Summer half-day Fridays

Health & wellness programs

INACTIVE