Talent Apply
Log in
All jobs
S

Application Security Engineer

Solventum
Remote - Pennsylvania; Remote - Ohio
RemoteUSD 125,600 - 172,700 / year

About this role

About the Role Join Solventum as an Application Security Engineer on a team dedicated to securing healthcare information systems and patient data. You will operate and enhance security tool environments and partner with development teams to drive secure software throughout the release cycle. What You'll Do

  • Operate and enhance application security tool environments.
  • Author automation scripts (Python preferred).
  • Setup and execute authenticated and unauthenticated DAST scans against web apps and APIs using approved tools.
  • Manage scan scheduling, configuration, and coverage across tool environments.
  • Tune scanning profiles to reduce false positives and improve detection.
  • Align DAST with release cycles and risk-based scanning requirements.
  • Validate DAST findings for exploitability and business impact.
  • Categorize vulnerabilities using OWASP Top 10; prioritize by risk, criticality, exposure.
  • Eliminate false positives and duplicates before handoff to developers.
  • Explain DAST findings and remediation expectations with development and platform teams.
  • Track remediation progress and verify fixes via re-scans or targeted validation.
  • Maintain accurate vulnerability records in enterprise tracking systems; escalate overdue or high-risk items per policy.
  • Validate software applications meet security guidelines and compliance standards (HIPAA, SOC II, GDPR, NIST 800-53, FedRAMP, etc.).
  • Build solutions to collect and present vulnerability and compliance data to leadership. What We're Looking For
  • Bachelor's Degree and at least 7 years of experience in application security.
  • 3+ years administering, running, and analyzing DAST tools.
  • Experience with AWS or Azure cloud environments.
  • Familiarity with NIST, HITRUST, FedRAMP, and other common compliance programs.
  • Experience developing or testing RESTful APIs with Postman and/or Swagger.
  • Ability to obtain and maintain a Public Trust clearance.
  • Experience administering Qualys or Tenable vulnerability management modules (nice to have).
  • Strong attention to detail, analytical skills, and risk-based prioritization. Nice to Have
  • Experience across multiple teams and disciplines; cross-team collaboration.
  • Additional experience administering vulnerability management tools. Compensation & Benefits
  • Salary range: $125,600 - $172,700 USD per year.
  • Onboarding travel: new hires will travel to a designated company location for on-site onboarding; travel arrangements and related expenses paid by the company.
  • Competitive pay and benefits; travel coordinated per policy.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →