Job Summary:
Tempus AI is focused on precision medicine and advancing the healthcare industry through AI technology. They are seeking a Senior Application Security Engineer to lead efforts in identifying and remediating vulnerabilities in their applications, ensuring the security of sensitive healthcare data.
Responsibilities:
• Conduct penetration tests on web, mobile, and software medical device applications, as well as internal systems.
• Lead threat modeling and risk assessment activities for new and existing products.
• Develop and execute test plans, scenarios, scripts, or procedures.
• Document findings, prepare detailed reports, and work with development teams to remediate identified issues.
• Track and manage vulnerabilities through their lifecycle.
• Develop and maintain custom security testing tools and automation scripts.
• Stay up-to-date with the latest testing and ethical hacking methods, tools, and industry trends.
• Assist in the development and maintenance of application security policies, standards, and guidelines.
• Work with security and IT teams to enhance the overall security posture of the organization.
• Provide security training and awareness to development teams.
• Participate in the design and review of new technologies and major changes to existing technologies from a security perspective.
• Ensure compliance with healthcare and data privacy regulations (e.g., HIPAA, GDPR).
• Evaluate third-party applications and vendors for security risks.
• Mentor junior team members and contribute to a culture of security.
Qualifications:
Required:
• 5+ years of proven experience in penetration testing.
• Strong understanding of security principles, techniques, and technologies.
• Experience with a variety of security tools and products (e.g., Burp Suite, Snyk, Metasploit, Nmap).
• Familiarity with programming/scripting languages such as Python, JavaScript/TypeScript, or others.
• Experience with cloud security (AWS, Azure, GCP) and secure SDLC practices.
• Excellent problem-solving, analytical, communication, and interpersonal skills.
• Experience mentoring and training others in security best practices.
Preferred:
• Experience in healthcare or other highly regulated environments.
• Relevant certifications such as OSCP, GPEN, OSCE, GWAPT, CSSLP, or similar are highly desirable.
Company:
Tempus is a technology company advancing precision medicine through the practical application of artificial intelligence in healthcare. Founded in 2015, the company is headquartered in Chicago, USA, with a team of 1001-5000 employees. The company is currently Late Stage.