About the Role
The Senior Application Security Engineer is responsible for integrating security throughout the software development lifecycle across cloud, platform, and enterprise application environments. This role leads secure code review, application security testing, vulnerability management, cloud security assessments, and secure development initiatives while partnering with development teams to ensure compliance with HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 requirements. The position supports applications developed for academic, research, and clinical environments, including biomedical systems operating within healthcare settings.
Responsibilities
- Develop, implement, and maintain Secure Software Development Lifecycle (SSDLC) standards supporting Azure-hosted applications, Adobe Experience Cloud, and other internally managed platforms
- Support secure software development for academic, research, and clinical applications, with an emphasis on higher-risk clinical systems
- Perform manual and automated secure code reviews for internally developed applications, identifying vulnerabilities aligned with the OWASP Top 10 and CWE Top 25
- Integrate Static Application Security Testing (SAST) and Software Composition Analysis (SCA) into CI/CD pipelines
- Partner with software developers to remediate vulnerabilities and promote secure coding practices through guidance and education
- Configure and operate Burp Suite Professional/Enterprise for Dynamic Application Security Testing (DAST) and authorized penetration testing
- Utilize OWASP ZAP for automated and on-demand application security scanning
- Perform controlled validation testing using Metasploit during authorized penetration testing engagements
- Triage, prioritize, and track remediation efforts through a risk-based vulnerability management process
- Coordinate security testing schedules with application owners to minimize operational disruption
- Support QA and automated testing initiatives validating application security controls throughout deployment pipelines
- Assess Microsoft Azure and other cloud environments for security posture, including identity and access management, network segmentation, and resource-level security controls
- Review Adobe Experience Cloud and SaaS/PaaS integrations to ensure secure configuration and appropriate data protection
- Support secure API design, authentication, authorization, and data validation practices
- Recommend improvements that strengthen cloud and enterprise application security architecture
- Assess the security of AI/ML models, data pipelines, and AI-enabled applications
- Review secure integration of generative AI tools, chatbots, and AI-driven APIs supporting institutional applications
- Evaluate security controls for robotics programming, automation platforms, and robotic process automation (RPA) solutions
- Support security assessments of biomedical systems and connected medical devices operating within clinical environments
- Collaborate with research, innovation, and clinical teams to embed secure development practices throughout AI and robotics initiatives
- Align application security practices with HIPAA, HITRUST CSF, NIST CSF 2.0, TAC 202, and UTS 165 requirements
- Support third-party risk assessments (TPRM) and application security reviews
- Participate in audit activities, including HITRUST readiness assessments
- Develop and maintain application security policies, standards, and procedures
- Partner with Cybersecurity Analysts on threat modeling, incident response, and architecture reviews for new applications and integrations
- Collaborate with the campus Information Security Office (ISO) to support application security standards, risk assessments, vulnerability management, and coordinated incident response
- Work closely with Infrastructure, Development, and Platform Engineering teams to integrate security throughout project lifecycles
- Communicate technical findings, security risks, and recommendations to technical and executive stakeholders
- Adhere to internal controls and reporting structure
- Perform related duties as assigned
Requirements
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field; or an equivalent combination of education and professional experience
- Minimum of eight (8) years of experience in application security, secure code review, penetration testing, or secure software development
- Hands-on experience using Burp Suite, OWASP ZAP, and Metasploit for application security testing and vulnerability validation
- Experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) tools such as Checkmarx, Veracode, SonarQube, or similar platforms
- Experience securing Microsoft Azure and other cloud environments
- Experience implementing secure coding practices across common programming languages and web application frameworks
- Knowledge of Secure Software Development Lifecycle (SSDLC) methodologies
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent verbal and written communication skills
- Ability to collaborate effectively with software developers, infrastructure teams, cybersecurity professionals, and business stakeholders
- Relevant education and experience may be substituted as appropriate
- Experience supporting healthcare or higher education environments
- Knowledge of HIPAA, HITRUST, NIST CSF 2.0, TAC 202, and UTS 165 security frameworks
- Experience securing Microsoft Azure, Adobe Experience Cloud, SaaS/PaaS platforms, and cloud-native applications
- Familiarity with AI/ML security concepts, including model security, data governance, prompt injection risks, and adversarial attacks
- Experience supporting robotics, robotic process automation (RPA), biomedical systems, or connected medical devices
- Experience integrating application security testing into QA processes, automated testing frameworks, and CI/CD pipelines
- Experience performing application threat modeling, secure architecture reviews, and third-party risk assessments (TPRM)
Skills
- Secure software development
- Cloud security
- Application security testing
- Emerging cybersecurity technologies
- Microsoft Azure
- Adobe Experience Cloud
- SaaS/PaaS platforms
- Cloud-native applications
- AI/ML security concepts
- Robotics
- Robotic process automation (RPA)
- Biomedical systems
- Connected medical devices
- HIPAA
- HITRUST
- NIST CSF 2.0
- TAC 202
- UTS 165
- OWASP Top 10
- CWE Top 25
- SAST
- DAST
- SCA
- Burp Suite
- OWASP ZAP
- Metasploit
- CI/CD pipelines
- Threat modeling
- Incident response
- Architecture reviews
- Risk assessments
- Vulnerability management
- Secure coding practices
- API security
- Identity and access management
- Network segmentation
- Data protection
- Communication
- Collaboration
- Problem-solving
- Troubleshooting
- Analytical skills
Location
- AUSTIN, TX
Work Type
- Hybrid
- Full-time
Experience Level
- Senior
- 8+ years
Education Level
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field
- Equivalent combination of education and professional experience
Salary/Compensations
- $120,000+
Benefits
- Teacher Retirement System of Texas (TRS)
About the Company
- Dell Medical School
- The University of Texas at Austin
Equal Opportunity
- The University of Texas at Austin, as an equal opportunity/affirmative action employer, complies with all applicable federal and state laws regarding nondiscrimination and affirmative action. The University is committed to a policy of equal opportunity for all persons and does not discriminate on the basis of race, color, national origin, age, marital status, sex, sexual orientation, gender identity, gender expression, disability, religion, or veteran status in employment, educational programs and activities, and admissions.
