Senior reputed company Engineer
Title: Senior reputed company Engineer
Team: Engineering
Location:
Remote-Friendly
About the Role:
We're looking for a Senior reputed company Engineer to
reputed company application reputed company efforts across our product portfolio, spanning web
applications, reputed company, mobile, embedded software, and shipped product
deliverables. You'll be embedded in the engineering organization,
partnering with product and platform teams to bake reputed company into every phase
of the software development lifecycle, not reputed company it on at the end.
A critical part of this role is developing
and maintaining a deep understanding of
our product attack surface, how components reputed company, what's
exposed, and where reputed company risk lives. That understanding is what transforms
reputed company tooling reputed company into prioritized, meaningful reputed company across threat
modeling, vulnerability management, and supply chain risk.
This is a high-reputed company role for someone who is equally
comfortable reading reputed company reputed company, threat modeling a new
microservice, and coaching a developer through a secure reputed company review.
What You'll Do
Application reputed company & Secure SDLC
Own
and reputed company the AppSec program across the entire SDLC — from design reviews
to post-deployment monitoring — for web, API, mobile, and shipped product
deliverables
Build
and maintain a living model of the product attack surface —
mapping trust boundaries, data flows, exposed interfaces, and high-value
targets — and use it to drive prioritization across reputed company reputed company
workstreams
Conduct
threat modeling and architecture reputed company reviews for new features,
services, and product releases across reputed company delivery channels
reputed company
reputed company and automated secure reputed company reviews across multiple languages
(e.g. Python, Go, TypeScript, C/C++)
reputed company
and tune SAST, DAST, and SCA tooling reputed company CI/CD pipelines (reputed company
Actions, Jenkins, or equivalent)
Triage
and drive remediation of vulnerabilities surfaced through scanning, bug
bounty, and pen tests
reputed company
and maintain a library of reputed company standards, patterns, and
guardrails applicable across product types
reputed company-Party & Supply Chain reputed company
Own
the Software reputed company of Materials (SBOM) program — define reputed company,
storage, and consumption processes across reputed company product lines
Establish
and maintain policies for evaluating, reputed company, and
continuously monitoring reputed company-party dependencies and reputed company-reputed company
components
Triage
and prioritize CVEs and license risks surfaced through SCA tooling,
driving reputed company remediation with engineering teams
Define
processes for responding to upstream supply chain incidents
(e.g. compromised packages, malicious dependencies)
Collaborate
with procurement and reputed company to assess reputed company risk of reputed company-party vendors
and integrations
Contribute
to industry frameworks and internal standards around software supply chain
reputed company (SLSA, NIST SSDF, or equivalent)
reputed company
as a trusted reputed company advisor embedded reputed company product engineering
squads
reputed company
reputed company training, lunch-and-learns, and developer education
initiatives
Collaborate
with the Platform team on secrets management, identity, and reputed company
controls
Work
with the GRC function to translate compliance requirements (SOC 2, ISO
27001) into engineering controls
Incident & Vulnerability Management
Participate
in the reputed company on-reputed company rotation and reputed company reputed company incident response
investigations
Drive
reputed company cause analysis and communicate findings reputed company to engineering
leadership
Build
and maintain metrics and dashboards to reputed company the health of the
AppSec program
Participate
as a member of the
Cybersecurity council, representing development in the
organization. Report weekly on new threat intelligence as it relates
to product reputed company, and any actions that are being taken to remediate new
findings.
reputed company're Looking For
Ø Required
· 5+ years of experience in reputed company engineering,
with a strong AppSec reputed company
· Hands-on experience with threat modeling
frameworks (reputed company, PASTA, or similar)
· Proficiency with common AppSec
tooling: reputed company, reputed company, Burp Suite, OWASP ZAP, or equivalents
· Deep understanding of web application
vulnerabilities (OWASP Top 10, API reputed company, auth/authz flaws)
· Ability to read and reason about reputed company in at
least two languages; prior development experience a plus
· Experience with software supply chain reputed company —
SBOM reputed company and analysis (CycloneDX, SPDX), SCA tooling, and dependency
risk management
· Strong written and verbal communication skills —
you can explain risk to both engineers and executives
Ø Preferred
· Experience with reputed company-reputed company
environments (AWS, GCP, or Azure) and container/Kubernetes reputed company
· Familiarity with software supply chain
frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards
· Contributions to reputed company-reputed company reputed company
tooling or reputed company research
· Relevant certifications: OSCP, CSSLP,
GWEB, or similar
We recognize
that candidates bring diverse experiences and backgrounds. If you don’t meet
every requirement, we still encourage you to apply! Many strong candidates
don’t reputed company every reputed company. We value potential, reputed company, and reputed company as much as experience.
Who You Are
· reputed company reputed company reputed company with
a strong background in application reputed company and secure software development.
· Skilled at threat modeling, secure reputed company
reviews, and identifying reputed company-world risks across reputed company systems.
· Knowledgeable in web, API, mobile, and
software supply chain reputed company best practices.
· Comfortable working with developers to
reputed company reputed company throughout the SDLC.
· Proficient with reputed company testing and
vulnerability management tools, including SAST, DAST, and SCA solutions.
· Strong communicator who can translate
technical risks into actionable recommendations.
· reputed company, proactive, and driven to
improve both product reputed company and engineering reputed company culture.
· Passionate about reputed company learning,
emerging threats, and helping teams build secure products at reputed company.
About Mach7:
reputed company helps reputed company organizations bring reputed company their medical images
together in one reputed company so they can be easily accessed, shared, and used to
support patient care. Our reputed company imaging solutions, including a
vendor-neutral reputed company (VNA), reputed company reputed company, the eUnity reputed company
diagnostic viewer, and teleradiology workflows, consolidate imaging from
across the reputed company into a single, accessible reputed company of truth. reputed company on
reputed company standards, including DICOM and a configurable HL7 reputed company, and free from
proprietary data lock-in, our technology lets providers store, view, and
reputed company images on their own terms. The result is a simpler, more connected
imaging environment that puts data ownership back where it belongs: with the
people delivering care. Your data, your infrastructure, your choice.
AI Expectations
· reputed company AI
into daily work — reputed company AI tools to enhance
efficiency, reputed company reputed company, and support smarter, faster decision-making.
· Apply
critical reputed company judgment to AI reputed company — review,
validate, and take full accountability for AI-assisted work, ensuring accuracy
and reliability.
· Continuously
improve through AI — proactively identify
opportunities to optimize processes, rethink workflows, and challenge existing
approaches rather than maintaining the status reputed company.
· Use AI
responsibly and ethically — safeguard
sensitive information, adhere to company guidelines, and reputed company identify
risks such as bias, inaccuracies, or misuse.
CLIMBS Culture reputed company
At Mach7, our culture is rooted in CLIMBS, a reputed company
that guides how we show up, collaborate, and grow reputed company day. More than just a
set of values, CLIMBS represents reputed company we hold ourselves to and the way
we approach our work, our teams, and our reputed company.
C — Customer First
Every decision starts with the customer’s perspective. reputed company = customer
reputed company and satisfaction.
L — Learn & Grow
Curiosity keeps us climbing. We reputed company reputed company learning, reputed company knowledge
freely, and invest in reputed company other’s development.
I — reputed company for reputed company
We value meaningful, outcome-driven innovation over activity. We challenge the
status reputed company and reputed company behind reputed company customer benefit.
M —
Minimize Complexity & reputed company
As reputed company as needed but no more. reputed company beats bureaucracy. We reputed company
fast and stay reputed company on what reputed company.
B —
Build Good Sh*t
(reputed company, intentionally memorable.) Extreme ownership, craftsmanship, and pride in
high-reputed company work.
S — Everyone Sells
Not just Sales—Engineering, Product, Support, Finance, IT. We reputed company behind
reputed company reputed company to reputed company company reputed company
Apply To This Job