Demo

Application Security Engineer

Public Partnerships | PPL
Syracuse, NY Full Time
POSTED ON 6/27/2026
AVAILABLE BEFORE 7/25/2026

Company Description Public Partnerships | PPL is a leading service provider for self-directed care programs, helping Medicaid and other government-funded program members receive care at home from providers they choose. The organization partners with 18 states across 50 programs, supporting more than 700,000 participant and caregiver relationships. PPL plays a key role in program administration by educating members about self-direction options and guiding them through enrollment. The company’s proprietary technology enables participants to track their care time and ensure their providers are paid accurately and on time. PPL’s mission is to make self-directed care a practical, everyday choice that improves quality of life for individuals and families.


Job Summary

 

We are seeking an experienced and proactive Application Security (AppSec) and DevSecOps Engineer to embed security throughout the software development lifecycle and CI/CD pipelines. You will collaborate with development, operations, and security teams to design, implement, and maintain security best practices in our applications and infrastructure. This role ensures our systems are secure by design and compliant with industry standards, including HIPAA, SOC2, OWASP, NIST 800-53, and NIST SSDF.

 

Key Responsibilities


Secure SDLC Integration:

• Integrate security at every phase of the software development lifecycle.

• Collaborate with engineering and product teams in Agile/Scrum environments to prioritize, track, and remediate security issues during sprint cycles.

• Develop and maintain threat models and perform design reviews. Lead threat modeling sessions and conduct in-depth security architecture reviews.

• Educate development teams on secure coding practices.

• Contribute to secure backlog grooming and definition of security-related user stories and acceptance criteria.

• Actively support the organization’s secure software development lifecycle (SDLC) initiatives by integrating security controls, processes, and testing into development workflows and CI/CD pipelines.

 CI/CD Pipeline Security:

• Integrate security testing tools (SAST, DAST, SCA, IaC scanning) into CI/CD pipelines.

• Automate security checks to ensure continuous compliance and early detection.

• Ensure integration of security scanning outputs into ticketing systems and development workflows for traceable remediation.

Application Security:

• Perform and manage vulnerability assessments, code reviews, and penetration testing.

• Lead application-level penetration testing efforts, both internally and with external vendors.

• Remediate findings by working closely with developers and product teams.

• Facilitate and track remediation activities as part of security sprints.

• Monitor and manage third-party/open-source dependencies for known vulnerabilities.

• Conduct security code reviews using both automated and manual analysis techniques.

Infrastructure & DevSecOps:

• Secure containerized environments (Docker, Kubernetes).

• Ensure cloud infrastructure security (AWS/Google Cloud Platform/Azure) using infrastructure-as-code (IaC) tools like Terraform or CloudFormation.

• Implement secrets management, identity and access control, and other cloud-native security features.

Governance & Compliance:

• Contribute to security policies, standards, and compliance efforts (e.g., ISO 27001, SOC 2, NIST 800-53, GDPR).

• Ensure application security controls comply with HIPAA Security Rule safeguards (e.g., access control, audit logging, encryption).

• Support documentation and evidence collection for SOC 2 Type II audits and HIPAA security risk assessments.

• Map security activities and controls to NIST 800-53 and NIST SSDF frameworks.

• Support audit activities and create documentation for security controls.


Required Skills:           

• Integrate security at every phase of the software development lifecycle.

• Collaborate with engineering and product teams in Agile/Scrum environments to prioritize, track, and remediate security issues during sprint cycles.

• Develop and maintain threat models and perform design reviews.

• Lead threat modeling sessions and conduct in-depth security architecture reviews.

• Educate development teams on secure coding practices.

• Contribute to secure backlog grooming and definition of security-related user stories and acceptance criteria.

• Actively support the organization’s secure software development lifecycle (SDLC) initiatives by integrating security controls, processes, and testing into development workflows and CI/CD pipelines.

• Integrate security testing tools (SAST, DAST, SCA, IaC scanning) into CI/CD pipelines.

• Automate security checks to ensure continuous compliance and early detection.

• Ensure integration of security scanning outputs into ticketing systems and development workflows for traceable remediation.

• Perform and manage vulnerability assessments, code reviews, and penetration testing.

• Lead application-level penetration testing efforts, both internally and with external vendors.

• Remediate findings by working closely with developers and product teams.

• Facilitate and track remediation activities as part of security sprints.

• Monitor and manage third-party/open-source dependencies for known vulnerabilities.

• Conduct security code reviews using both automated and manual analysis techniques.

• Secure containerized environments (Docker, Kubernetes).

• Ensure cloud infrastructure security (AWS/Google Cloud Platform/Azure) using infrastructure-as-code (IaC) tools like Terraform or CloudFormation.

• Implement secrets management, identity and access control, and other cloud-native security features.

• Contribute to security policies, standards, and compliance efforts (e.g., ISO 27001, SOC 2, NIST 800-53, GDPR).

• Ensure application security controls comply with HIPAA Security Rule safeguards (e.g., access control, audit logging, encryption).

• Support documentation and evidence collection for SOC 2 Type II audits and HIPAA security risk assessments.

• Map security activities and controls to NIST 800-53 and NIST SSDF frameworks.

• Support audit activities and create documentation for security controls.


Qualifications:            

 

Education: Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience).

Experience: 5 years of experience in AppSec, DevSecOps, or related roles (7 preferred)

Certifications: OSCP, CISSP, CSSLP, CEH, or similar.

Preferred Attributes: Experience with cloud-native security in Azure, AWS, and Google Cloud Platform.

Hands-on experience with NIST, HIPAA, and SOC 2 application security compliance, including security assessments and control implementation. Experience leading penetration testing engagements and managing remediation in collaboration with development teams. Experience with bug bounty programs or working with security researchers. Experience implementing or supporting a security champions program is a plus.


https://publicpartnerships.wd1.myworkdayjobs.com/en-US/PPL/job/US-Remote/AppSec---DevSecOps-Engineer_JR26-0838

Salary.com Estimation for Application Security Engineer in Syracuse, NY
$80,040 to $108,232
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Engineer?

Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Application Security Engineer jobs in the Syracuse, NY area that may be a better fit.

  • Actalent East Syracuse, NY
  • Information Security Engineer We are seeking an experienced Information Security Engineer with strong Microsoft Windows infrastructure expertise to support... more
  • 14 Days Ago

AI Assistant is available now!

Feel free to start your new journey!