empty

Application Security Engineer - Hybrid

Blue Cross Blue Shield of Arizona

Job Description

Posted on: 
March 3, 2025

Summary and company overview

Summary

Awarded a Healthiest Employer, Blue Cross Blue Shield of Arizona aims to fulfill its mission to inspire health and make it easy.  AZ Blue offers a variety of health insurance products and services to meet the diverse needs of individuals, families, and small and large businesses as well as providing information and tools to help individuals make better health decisions.

At AZ Blue, we have a hybrid workforce strategy, called Workability, that offers flexibility with how and where employees work. Our positions are classified as hybrid, onsite or remote. While the majority of our employees are hybrid, the following classifications drive our current minimum onsite requirements:

  • Hybrid People Leaders: must reside in AZ, required to be onsite at least once per week
  • Hybrid Individual Contributors: must reside in AZ, unless otherwise cited within this posting, required to be onsite at least once per month
  • Onsite: daily onsite requirement based on the essential functions of the job
  • Remote: not held to onsite requirements, however, leadership can request presence onsite for business reasons including but not limited to staff meetings, one-on-ones, training, and team building

Please note that onsite requirements may change in the future, based on business need, and job responsibilities. Most employees should expect onsite requirements and at a minimum of once per month.

This position is hybrid within the state of AZ only. This hybrid work opportunity requires residency, and work to be performed, within the State of Arizona.

Responsibilities

  • Perform ongoing security vulnerability assessments and application pen tests, including identifying, assessing, and driving remediation of application vulnerabilities.
  • Develop security improvements for the company’s websites and backend applications and serve as a SME on website and application-related projects.
  • Research and recommend emerging security technologies/tools to address current and future threats and create and maintain documentation as it relates to security designs/configuration, processes, and requirements.
  • Participate in security incident response processes.
  • Mentor development teams on the use of secure coding practices and evangelize secure software development practices and processes throughout the SDLC.

Application security

  • Participate in the building, automation, and operation automated security review capabilities across multiple technology stacks and languages throughout the SDLC.
  • Coordinate security code reviews, application vulnerability testing, and penetration testing, and train engineering team on best practices in application security throughout the SDLC.
  • Drive assessment of applications to identify and prioritize risks, driving prioritization and remediation across application development teams.
  • Be an expert on vulnerabilities and attack vectors that have the potential to impact BCBSAZ systems.
  • Proactively identify and implement products and tools to ensure security of our applications, collaborating with all areas of IT to harden our environment.

Strategy

  • Participate in developing technical strategy; apply and promote security technology that optimizes the portfolio of technologies, tools, products, and applications.
  • Work with IT leaders and subject matter experts to use technology to improve overall corporate security posture.
  • Deliver assessment services, develop business cases, design solution architecture, and recommend multi-phased, complex migration programs that address application security.

Project Management

  • Develop timelines, work estimates, cost projections, and manage projects related to application security initiatives to approved guidelines; review and consult on design and technical approach of projects to ensure consistency.

OTHER

  • The position requires a full-time work schedule. Full-time is defined as working at least 40 hours per week, plus any additional hours as requested or as needed to meet business requirements.
  • Position may require evening, weekend, or on-call schedules, depending on project requirements and/or system status.
  • Perform all other duties as assigned.

Job Requirements

Required Qualifications:

Required Work Experience

  • 8 years of experience with application design and development.
  • 3 years as an application security engineer analyzing the application modules for enhancing the application security.

Required Education

  • Bachelor’s degree in business, information technology, computer systems, or related field

Required Licenses

  • N/A

Required Certifications

  • N/A

Preferred Qualifications:

Preferred Work Experience

  • 10 years of experience with application design and development.
  • 5 years as an application security engineer analyzing the application modules for enhancing the application security.
  • Proven experience with web pen testing and application vulnerability assessments

Preferred Education

  • Master’s degree in business, computer science or related field

Preferred Licenses

  • CISSP, CEH and/or CSSLP Certifications

Preferred Certifications

  • Technical certifications in software and systems design and development

Additional commentary

Our Commitment

AZ Blue does not discriminate in hiring or employment on the basis of race, ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or any other protected group.

Thank you for your interest in Blue Cross Blue Shield of Arizona. For more information on our company, see azblue.com. If interested in this position, please apply.

Summary and company overview

Summary

Awarded a Healthiest Employer, Blue Cross Blue Shield of Arizona aims to fulfill its mission to inspire health and make it easy.  AZ Blue offers a variety of health insurance products and services to meet the diverse needs of individuals, families, and small and large businesses as well as providing information and tools to help individuals make better health decisions.

At AZ Blue, we have a hybrid workforce strategy, called Workability, that offers flexibility with how and where employees work. Our positions are classified as hybrid, onsite or remote. While the majority of our employees are hybrid, the following classifications drive our current minimum onsite requirements:

  • Hybrid People Leaders: must reside in AZ, required to be onsite at least once per week
  • Hybrid Individual Contributors: must reside in AZ, unless otherwise cited within this posting, required to be onsite at least once per month
  • Onsite: daily onsite requirement based on the essential functions of the job
  • Remote: not held to onsite requirements, however, leadership can request presence onsite for business reasons including but not limited to staff meetings, one-on-ones, training, and team building

Please note that onsite requirements may change in the future, based on business need, and job responsibilities. Most employees should expect onsite requirements and at a minimum of once per month.

This position is hybrid within the state of AZ only. This hybrid work opportunity requires residency, and work to be performed, within the State of Arizona.

Apply now