athenahealth Logo

athenahealth

Lead Application Security Engineer- DevSecOps

Posted 22 Days Ago
In-Office or Remote
Hiring Remotely in Boston, MA
143K-243K Annually
Mid level
In-Office or Remote
Hiring Remotely in Boston, MA
143K-243K Annually
Mid level
Lead application security strategy and DevSecOps implementation across engineering teams. Own application security capabilities, including SAST, SCA, DAST, API security testing, vulnerability management, and CI/CD controls. Lead API security discovery, testing, onboarding, findings routing, and operational readiness. Partner with product, engineering, DevOps, infrastructure, IAM, and enterprise security teams to identify architectural weaknesses, improve SDLC adoption, automate abuse-case coverage, and operate hardened platforms.
The summary above was generated by AI

Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.

athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security.

This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes.

About the Team
This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment.

Core Responsibilities

  • Security strategy and SDLC adoption

  • Socialize and drive execution of key security best practices across the R&D organization.

  • Contribute to the enterprise security catalog of best practices, techniques, and patterns.

  • Improve the quality and adoption of Security Development Lifecycle practices.

  • Application security capability ownership

  • Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities.

  • Support SAST, SCA, DAST, API security testing, and vulnerability management workflows.

  • Document, share, and help automate coverage for common abuse cases and attacks.

  • API security program leadership

  • Lead the API security testing program.

  • Manage API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness.

  • Identify and explain feature-level design or architectural weaknesses that could create security issues.

  • Cross-functional partnership and issue management

  • Partner with enterprise security leadership to track and prioritize open issues and follow through on resolution.

  • Work with DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to design and operate security-hardened platforms.

Required Experience & Skills

  • Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or similar, or equivalent experience.

  • At least 3 years of experience as a software developer and 3–5 years in a security-focused development role in an agile environment.

  • Experience in software and product design and architecture, product security, and security issue prevention and mitigation.

  • Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages.

  • Practical experience with Docker and Terraform.

  • Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication.

  • Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts.

  • Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls.

  • Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD.

  • Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus.

Why This Role Matters
This role is central to strengthening secure software delivery across athenahealth. It combines technical depth, security leadership, and cross-functional influence to improve how security is built into products from the start.


Expected Compensation

$143,000 - $243,000

The base salary range shown reflects the full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates.  Base pay is only one part of our competitive Total Rewards package - depending on role eligibility, we offer both short and long-term incentives by way of an annual discretionary bonus plan, variable compensation plan, and equity plans.


About athenahealth

Our vision: In an industry that becomes more complex by the day, we stand for simplicity. We offer IT solutions and expert services that eliminate the daily hurdles preventing healthcare providers from focusing entirely on their patients — powered by our vision to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.

Our company culture: Our talented  employees — or athenistas, as we call ourselves — spark the innovation and passion needed to accomplish our vision. We are a diverse group of dreamers and do-ers with unique knowledge, expertise, backgrounds, and perspectives. We unite as mission-driven problem-solvers with a deep desire to achieve our vision and make our time here count. Our award-winning culture is built around shared values of inclusiveness, accountability, and support.

Our DEI commitment: Our vision of accessible, high-quality, and sustainable healthcare for all requires addressing the inequities that stand in the way. That's one reason we prioritize diversity, equity, and inclusion in every aspect of our business, from attracting and sustaining a diverse workforce to maintaining an inclusive environment for athenistas, our partners, customers and the communities where we work and serve.

What we can do for you:

Along with health and financial benefits, athenistas enjoy perks specific to each location, including commuter support, employee assistance programs, tuition assistance, employee resource groups, and collaborative  workspaces  — some offices even welcome dogs.

We also encourage a better work-life balance for athenistas with our flexibility. While we know in-office collaboration is critical to our vision, we recognize that not all work needs to be done within an office environment, full-time. With consistent communication and digital collaboration tools, athenahealth enables employees to find a balance that feels fulfilling and productive for each individual situation.

In addition to our traditional benefits and perks, we sponsor events throughout the year, including book clubs, external speakers, and hackathons. We provide athenistas with a company culture based on learning, the support of an engaged team, and an inclusive environment where all employees are valued. 

Learn more about our culture and benefits here: athenahealth.com/careers  

https://www.athenahealth.com/careers/equal-opportunity

Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
78K-117K Annually
Mid level
78K-117K Annually
Mid level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Own global mobility and immigration programs, including case management, policy administration, compliance, vendor coordination, employee support, and process optimization. Partner with HR, Recruiting, Legal, and external providers to improve workflows using AI and automation. The role also supports benefits and leave-of-absence coordination while developing broader expertise in Total Rewards.
Top Skills: AIAutomation
Entry level
Insurance • Financial Services
Verifies life and health insurance applications through outbound calls, documents information for underwriting, explains application procedures, assesses additional verification needs, completes paperwork, updates quality assurance records, transfers calls, and meets departmental performance targets.
Top Skills: MS Office
An Hour Ago
Remote or Hybrid
United States
67K-101K Annually
Junior
67K-101K Annually
Junior
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Analyzes operational and vehicle inspection data, builds and maintains reports, dashboards, queries, metrics, and data processes, and delivers insights to Operations and leadership. The role cleans and transforms large datasets, validates data quality, supports data science and engineering teams, develops monitoring systems, and presents trends and recommendations for business decisions. It also partners with product, dispatch, quality assurance, and technology teams on operational data and reporting needs.
Top Skills: AlteryxAWSIbm Db2ExcelMicrosoft PowerpointMicrosoft Sql ServerOraclePower BISnowflakeSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account