
Senior Security Engineer / AppSec Engineer
PCI Pharma Services
full-time
Posted on:
Location Type: Remote
Location: Pennsylvania • United States
Visit company websiteExplore more
Job Level
About the role
- Serve as the technical security lead for PCI Pharma
- Responsible for security architecture, application security, vulnerability management, and security engineering across enterprise and manufacturing environments
- Combine hands-on technical work with strategic security advisory
- Ensure protection of pharmaceutical intellectual property, patient data, and compliance with industry regulations
- Design and implement security architecture for cloud (Azure, AWS), on-premises, and hybrid environments
- Lead application security program including SAST/DAST integration, secure code reviews, and developer training
- Manage enterprise vulnerability management using Nessus
- Architect and maintain Zero Trust security framework
- Conduct security assessments for new applications and infrastructure changes
- Implement and manage endpoint security solutions
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or related field
- 7+ years of progressive cybersecurity experience with 3+ years in security engineering/architecture
- Deep expertise in vulnerability management tools (Nessus, Qualys, or Rapid7)
- Strong application security knowledge including OWASP Top 10, secure SDLC, and DevSecOps practices
- Experience with cloud security in Azure and/or AWS (security groups, IAM, encryption)
- Proficiency in network security including firewalls, IDS/IPS, and segmentation
- Knowledge of endpoint security solutions and EDR platforms
- Strong scripting abilities (PowerShell, Python) for security automation
- Experience in regulated industries with compliance requirements
- CISSP, CISM, or equivalent security certification
Benefits
- Health insurance
- 401(k) matching
- Paid time off
- Flexible work hours
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security architectureapplication securityvulnerability managementsecurity engineeringSASTDASTsecure code reviewsendpoint securityscripting (PowerShell, Python)cloud security
Soft Skills
strategic security advisoryleadershipcommunication
Certifications
CISSPCISM