JOBSEARCHER

Senior Application Security Engineer

TempusEvanston, ILL5 SeniorSeptember 15th, 2026
Overview In this role you will lead and execute security testing across web, mobile, and medical device apps to safeguard healthcare data and support improved patient outcomes. You will partner with cross-functional teams to embed secure practices, threat modeling, and risk assessment into product development. Expect hands-on testing, tooling, and mentoring to uplift the organization’s security posture. This role offers impactful work at the intersection of healthcare, technology, and security. Compensation / Benefitsfull range of benefitsincentive compensation potentialrestricted stock units (RSUs) may be offeredmedical and other benefits ResponsibilitiesConduct penetration tests on web, mobile, and software medical device applications and internal systemsLead threat modeling and risk assessment activities for new and existing productsDevelop and execute test plans, scenarios, scripts, or proceduresDocument findings and work with development teams to remediate issuesTrack and manage vulnerabilities through their lifecycleDevelop and maintain custom security testing tools and automation scriptsStay up-to-date with testing methods, tools, and industry trendsAssist in development and maintenance of application security policies, standards, and guidelinesWork with security and IT teams to enhance security postureProvide security training and awareness to development teamsParticipate in design and review of new technologies from a security perspectiveEnsure compliance with HIPAA, GDPREvaluate third-party applications and vendors for security risksMentor junior team members and contribute to security culture Key requirements5+ years of proven penetration testing experienceExperience in healthcare or other highly regulated environmentsStrong understanding of security principles, techniques, and technologiesExperience with security tools (Burp Suite, Snyk, Metasploit, Nmap)Familiarity with Python, JavaScript/TypeScript or similar scripting languagesExperience with cloud security (AWS, Azure, GCP) and secure SDLC practicesExcellent problem-solving, analytical, communication, and interpersonal skillsRelevant certifications such as OSCP, GPEN, OSCE, GWAPT, CSSLP or similar (highly desirable)Experience mentoring and training others in security best practicesstrong communicationanalytical thinkinginterpersonal skillsBurp SuiteSnykMetasploit