<p><span data-contrast="none">Truveta provides unprecedented real-world data and real-time intelligence, powered by a dataset built with and owned by US health systems united in a mission of Saving Lives with Data. Together, we power breakthrough medical discoveries, accelerate regulatory-grade evidence, and improve patient care. Today, Truveta enables research on more than 130 million de-identified patients across the US. </span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<p><span data-contrast="none">Achieving Truveta’s ambitious mission requires an incredible team of talented and inspired people with a special combination of health, software and big data experience who share our </span><a href="https://www.truveta.com/careers/"><span data-contrast="none">company values</span></a><span data-contrast="none">.</span></p>
<p><strong><span data-contrast="auto">Role Overview</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<p><span data-contrast="auto">We are looking for a <strong>Senior </strong></span><strong><span data-contrast="auto">Security Engineer</span></strong><span data-contrast="auto"> to drive </span><strong><span data-contrast="auto">vulnerability management and penetration testing</span></strong><span data-contrast="auto"> across applications and infrastructure.</span><span data-ccp-props="{"335559685":720}"> </span></p>
<p><span data-contrast="auto">This role is focused on </span><strong><span data-contrast="auto">hands-on identification, validation, and remediation of security issues</span></strong><span data-contrast="auto">, with an emphasis on building scalable processes and improving overall security posture.</span><span data-ccp-props="{"335559685":720}"> </span></p>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<p><strong><span data-contrast="auto">Key Responsibilities</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Own and operate the </span><strong><span data-contrast="auto">vulnerability management lifecycle</span></strong><span data-contrast="auto">, including: </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Continuous scanning (applications, infrastructure, dependencies) </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Risk-based prioritization </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Tracking and driving remediation </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Perform </span><strong><span data-contrast="auto">penetration testing</span></strong><span data-contrast="auto"> on web applications, APIs, and cloud environments. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Validate and triage vulnerabilities to eliminate false positives and ensure actionable findings. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Partner with engineering teams to </span><strong><span data-contrast="auto">fix vulnerabilities and prevent recurrence</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Implement and manage tools for: </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">SAST, DAST, and dependency scanning </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Infrastructure and container scanning </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Develop </span><strong><span data-contrast="auto">repeatable testing methodologies and automation</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Conduct </span><strong><span data-contrast="auto">adversarial testing and exploit validation</span></strong><span data-contrast="auto"> to simulate real-world attack scenarios. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="auto">Track metrics and report on </span><strong><span data-contrast="auto">risk posture and remediation progress</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="auto">Contribute to improving </span><strong><span data-contrast="auto">secure development practices</span></strong><span data-contrast="auto"> based on findings. </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<p><strong><span data-contrast="auto">Required Qualifications</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">5–9+ years of experience in </span><strong><span data-contrast="auto">security engineering, vulnerability management, or penetration testing</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Hands-on experience with: </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Web and API security testing </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Common vulnerabilities (OWASP Top 10, misconfigurations, auth flaws) </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Strong understanding of </span><strong><span data-contrast="auto">attack techniques and exploitation methods</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Experience with </span><strong><span data-contrast="auto">security scanning tools and frameworks</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Ability to </span><strong><span data-contrast="auto">analyze and validate vulnerabilities in real-world systems</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Familiarity with </span><strong><span data-contrast="auto">cloud environments (Azure preferred)</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<p><strong><span data-contrast="auto">Preferred Qualifications</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Experience with </span><strong><span data-contrast="auto">automating security testing in CI/CD pipelines</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Familiarity with </span><strong><span data-contrast="auto">container and Kubernetes security</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Experience with </span><strong><span data-contrast="auto">bug bounty or red teaming</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Relevant certifications (e.g., OSCP, CEH, GWAPT). </span><span data-ccp-props="{}"> </span></li>
</ul>
<p><span data-ccp-props="{"335559685":720}"> </span></p>
<p><strong><span data-contrast="auto">What We’re Looking For</span></strong><span data-ccp-props="{"335559685":720}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Strong </span><strong><span data-contrast="auto">hands-on tester and problem solver</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Ability to go beyond tools and </span><strong><span data-contrast="auto">think like an attacker</span></strong><span data-contrast="auto">. </span><span data-ccp-props="{}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Focus on </span><strong><span data-contrast="auto">impact-driven security</span></strong><span data-contrast="auto">, not just findings.</span><span data-ccp-props="{}"> </span></li>
</ul>