CybersecurityJobs.io
← Back to all jobs

Job Description

Solventum is seeking an Application Security Engineer to help protect healthcare information systems by strengthening application security processes and tooling. This remote role in Pennsylvania focuses on operating application security environments, running authenticated and unauthenticated DAST scans, and supporting validation, remediation tracking, and compliance reporting.

What You’ll Do

  • Operate and enhance application security tool environments.
  • Write automation scripts for recurring tasks, with Python preferred.
  • Set up and run authenticated and unauthenticated dynamic application security testing (DAST) against web applications and APIs using approved tools.
  • Manage scan scheduling, configuration, and coverage across application security tool environments.
  • Tune scanning profiles to reduce false positives and improve detection accuracy.
  • Ensure DAST scanning aligns with release cycles and risk-based scanning requirements.
  • Validate DAST findings to confirm exploitability and business impact.
  • Categorize vulnerabilities using industry standards such as OWASP Top 10.
  • Prioritize findings based on risk, application criticality, and exposure.
  • Eliminate false positives and duplicate findings prior to developer handoff.
  • Partner with development and platform teams to explain DAST findings and expected remediation.
  • Track remediation progress and verify fixes through re-scans or targeted validation.
  • Maintain accurate vulnerability records in enterprise tracking systems.
  • Escalate overdue or high-risk vulnerabilities according to policy.
  • Work with application teams to validate software meets security guidelines and compliance standards including HIPPA, SOC II, GDPR, NIST 800-53, and FedRAMP.
  • Build solutions that collect and present vulnerability and compliance data for Solventum leadership.

Requirements

  • Bachelor’s Degree and 7 years of experience in application security.
  • 3 years experience administering, running, and analyzing DAST tools.
  • Knowledge of AWS or Azure cloud environments.
  • Familiarity with software security requirements used in industry compliance programs such as NIST, HITRUST, and FedRAMP.
  • Experience developing or testing RESTful APIs, including understanding Postman and/or Swagger files.
  • Ability to obtain and maintain a Public Trust clearance.

Tools and Technologies

  • Python
  • DAST
  • AWS, Azure
  • Postman, Swagger
  • RESTful APIs
  • Qualys, Tenable

Compensation and Work Details

  • Location: Pennsylvania (remote)
  • Work location: Remote, US only
  • Salary: USD 125,600 - 172,700 per year (includes base pay plus variable incentive pay, if eligible)
  • Travel: No travel required
  • Relocation assistance: Not authorized

Benefits

  • Medical, Dental & Vision
  • Health Savings Accounts
  • Health Care & Dependent Care Flexible Spending Accounts
  • Disability Benefits
  • Life Insurance
  • Voluntary Benefits
  • Paid Absences
  • Retirement Benefits

Onboarding requirement: new employees hired for this position will be required to travel to a designated company location for on-site onboarding during their initial days of employment. This applies to new hires with a start date of October 1st 2025 or later.

Application note: your application may not be considered if you do not provide your education and work history, either by uploading a resume or entering the information into the application fields directly.

Similar Jobs