<p><span data-contrast="none">Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough medical discoveries, accelerate regulatory-grade evidence, and improve patient care. Today, Truveta enables research on more than 130 million de-identified patients across the US. </span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<p><span data-contrast="none">Achieving Truveta’s ambitious mission requires an incredible team of talented and inspired people with a special combination of health, software and big data experience who share our </span><a href="https://www.truveta.com/careers/"><span data-contrast="none">company values</span></a><span data-contrast="none">.</span></p>
<p><strong><span data-contrast="auto">Role Overview</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">We are looking for a </span><strong><span data-contrast="auto">Senior Security Engineer</span></strong><span data-contrast="auto"> to lead </span><strong><span data-contrast="auto">data security, threat modeling, and security reviews</span></strong><span data-contrast="auto"> across our applications and platforms.</span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">This role focuses on </span><strong><span data-contrast="auto">proactively identifying design-level risks</span></strong><span data-contrast="auto">, securing sensitive data, and ensuring systems are built with strong security foundations. You will work closely with engineering teams to influence architecture and embed security early in the development lifecycle.</span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<p><strong><span data-contrast="auto">Key Responsibilities</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Lead </span><strong><span data-contrast="auto">security design reviews</span></strong><span data-contrast="auto"> for new and existing systems, identifying risks and driving secure architecture decisions. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Perform </span><strong><span data-contrast="auto">threat modeling</span></strong><span data-contrast="auto"> for services and platforms, translating threats into actionable engineering requirements. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Define and implement </span><strong><span data-contrast="auto">data protection strategies</span></strong><span data-contrast="auto">, including: </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Data classification and handling standards </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Encryption (at rest/in transit) </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Key management and secrets handling </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="auto">Review </span><strong><span data-contrast="auto">application architectures and APIs</span></strong><span data-contrast="auto"> for security weaknesses and design flaws. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="11" data-aria-level="1"><span data-contrast="auto">Conduct </span><strong><span data-contrast="auto">third-party/vendor security assessments</span></strong><span data-contrast="auto">, ensuring risks are identified and mitigated. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="12" data-aria-level="1"><span data-contrast="auto">Partner with engineering teams to </span><strong><span data-contrast="auto">remediate findings</span></strong><span data-contrast="auto"> and improve system design. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="13" data-aria-level="1"><span data-contrast="auto">Establish and evolve </span><strong><span data-contrast="auto">secure design patterns and guidelines</span></strong><span data-contrast="auto"> for developers. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="14" data-aria-level="1"><span data-contrast="auto">Integrate </span><strong><span data-contrast="auto">security into design and development workflows</span></strong><span data-contrast="auto"> (shift-left). </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="15" data-aria-level="1"><span data-contrast="auto">Evaluate and secure </span><strong><span data-contrast="auto">AI/ML use cases</span></strong><span data-contrast="auto">, including risks such as data leakage and prompt injection. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="16" data-aria-level="1"><span data-contrast="auto">Contribute to </span><strong><span data-contrast="auto">security standards, policies, and best practices</span></strong><span data-contrast="auto"> across the organization. </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="17" data-aria-level="1"><strong><span data-contrast="auto">Required Qualifications</span></strong><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="18" data-aria-level="1"><span data-contrast="auto">8–12+ years of experience in </span><strong><span data-contrast="auto">security engineering or application security</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="19" data-aria-level="1"><span data-contrast="auto">Strong expertise in </span><strong><span data-contrast="auto">threat modeling and secure system design</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="20" data-aria-level="1"><span data-contrast="auto">Deep understanding of: </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="21" data-aria-level="1"><span data-contrast="auto">Application security principles (OWASP Top 10, API security) </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="22" data-aria-level="1"><span data-contrast="auto">Data protection and privacy concepts </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="23" data-aria-level="1"><span data-contrast="auto">Authentication and authorization mechanisms </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="24" data-aria-level="1"><span data-contrast="auto">Experience conducting </span><strong><span data-contrast="auto">architecture and design-level security reviews</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="25" data-aria-level="1"><span data-contrast="auto">Ability to </span><strong><span data-contrast="auto">read and understand code</span></strong><span data-contrast="auto"> across common languages. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="26" data-aria-level="1"><span data-contrast="auto">Strong communication skills to influence engineering teams. </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="27" data-aria-level="1"><strong><span data-contrast="auto">Preferred Qualifications</span></strong><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="28" data-aria-level="1"><span data-contrast="auto">Experience in </span><strong><span data-contrast="auto">cloud environments (Azure preferred)</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="29" data-aria-level="1"><span data-contrast="auto">Familiarity with </span><strong><span data-contrast="auto">secure SDLC practices and DevSecOps tooling</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="30" data-aria-level="1"><span data-contrast="auto">Experience with </span><strong><span data-contrast="auto">regulated environments</span></strong><span data-contrast="auto"> (e.g., healthcare, finance). </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="31" data-aria-level="1"><span data-contrast="auto">Knowledge of </span><strong><span data-contrast="auto">AI/ML security risks</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="32" data-aria-level="1"><span data-contrast="auto">Relevant certifications (e.g., CISSP, CSSLP). </span><span data-ccp-props="{}"> </span></li>
</ul>
<p> </p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="33" data-aria-level="1"><strong><span data-contrast="auto">What We’re Looking For</span></strong><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="34" data-aria-level="1"><span data-contrast="auto">Strong </span><strong><span data-contrast="auto">analytical thinker</span></strong><span data-contrast="auto"> who can identify risks early in design. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="35" data-aria-level="1"><span data-contrast="auto">Ability to </span><strong><span data-contrast="auto">translate security into practical engineering guidance</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="36" data-aria-level="1"><span data-contrast="auto">Comfortable working across teams and influencing decisions. </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{}"> </span></p>