CybersecurityJobs.io
← Back to all jobs

Job Description

Medidata is hiring a Senior InfoSec Engineer to advance application security across the Software Development Life Cycle. This role supports secure SDLC practices, threat modeling, security testing, and release pipeline hardening while partnering with Engineering, Privacy, and DevOps teams.

Role Overview

Reporting to the Manager of Application Security & Sourcing, the Senior InfoSec Engineer focuses on building and enforcing application security standards throughout the SDLC. The position emphasizes secure development practices, vulnerability identification and remediation support, and collaboration across functions to deploy and maintain secure solutions in a cost-effective way.

Key Responsibilities

  • Integrate secure SDLC practices into the development lifecycle, including conducting static and dynamic code analysis (SAST/DAST), managing open-source components, performing threat modeling, and completing architectural security reviews
  • Manage and optimize source code control and source code management (SCM) to support secure, streamlined release pipelines
  • Apply knowledge of programming and application engineering to guide best-practice architecture and implementation using common coding patterns
  • Use working knowledge of web technologies and architectures (Web Services, Service-Oriented and Object-Oriented Architectures) and network/web protocols (HTTP) to support robust system communication
  • Support modern infrastructure deployment by managing Infrastructure as Code (IaC) and executing Kubernetes Cluster Administration
  • Leverage HTML and JavaScript experience, including a deep understanding of HTTP, to optimize frontend integrations and strengthen web security
  • Use hands-on development experience to review and improve codebase integrity across multiple languages, including .NET (C#), Java, Ruby, Python, JavaScript, TypeScript, AngularJS, and ReactJS
  • Implement and maintain data solutions using both relational and non-relational databases (MySQL, MS SQL, Oracle, MongoDB, DynamoDB, Redis)
  • Support and manage secure AI workflows in SDLC (AI code generation and tools such as Copilot and ClaudeCode) and in application features backed by AI
  • Apply information security principles and knowledge of web application vulnerabilities to identify, mitigate, and defend against malicious code and common hacker techniques
  • Collaborate with other functions to deploy and maintain solutions in an appropriate and cost-effective manner

Required Qualifications

  • Bachelor’s degree (or above) in Computer Science/Engineering, Information Technology, or comparable, and 3 to 5 years of related experience

Preferred Qualifications

  • AWS or vendor-agnostic cloud management certification (plus)
  • CISSP or equivalent certification (bonus)

Tools, Technologies, and Skills

  • Security Testing: SAST, DAST
  • Application Security: open-source components, threat modeling, secure SDLC practices
  • Web and Networking: Web Services, Service-Oriented Architecture, Object-Oriented Architectures, HTTP, HTML, JavaScript
  • Infrastructure and Deployment: Infrastructure as Code (IaC), Kubernetes
  • Programming and Frameworks: .NET (C#), Java, Ruby, Python, TypeScript, AngularJS, ReactJS
  • Databases: MySQL, MS SQL, Oracle, MongoDB, DynamoDB, Redis
  • AI Workflows: AI code generation, Copilot, ClaudeCode
  • Source Control and Artifacts: Git, GitHub, Artifactory
  • CI/CD: GitHub Actions
  • Cloud: AWS

Location and Work Arrangement

This role is remote. Medidata follows a hybrid office policy for in-person roles, where employees hired for in-person positions are expected to work on site a certain number of days per week following Company policy.

Compensation

Salary (all other United States locations): USD 102,750 - 137,000 per year.

Salary (NYC metro area positions physically based): USD 114,750 - 153,000 per year.

Pay ranges vary based on function, level, candidate expertise, and geographic location. Compensation for the role is commensurate with experience, with the total expected compensation range between $102,750 and $137,000, including base salary (annualized if estimated hourly compensation applies) and a target bonus.

Benefits

  • Medical, dental, life, and disability insurance
  • 401(k) matching
  • Family leave
  • Flexible paid time off
  • 10 paid holidays per year

About the Team

The Information Security Application Architecture team designs, evaluates, and enforces application security across all phases of the Software Development Life Cycle (SDLC). The team works with Engineering, Privacy, and DevOps to define and implement application security standards, perform software architecture design reviews, and conduct threat modeling. It also conducts white box security testing and supports identifying, interpreting, and remediating vulnerabilities across a range of applications, programming languages, and platforms.

Equal Employment Opportunity

  • Employment decisions are based on merit, qualifications, and abilities.
  • Policy of non-discrimination and equal opportunity applies without regard to specified protected characteristics.
  • Reasonable accommodations will be provided for qualified individuals with known disabilities in accordance with applicable law.
  • Applications are accepted on an ongoing basis until the position is filled.
  • #LI-EM1
  • #LI-Hybrid

Additional Inclusion Statement

3DS (Medidata) is committed to fair employment practices and evaluates candidates based on qualifications, including consideration of applicants with arrest or conviction records in accordance with applicable state laws and local ordinances.

Similar Jobs