Application Security Engineer
Job Description
Solventum is seeking an Application Security Engineer to help protect healthcare information systems through strong application security practices. This remote role supports security tool operations, DAST scanning for web applications and APIs, and evidence-driven validation for compliance expectations.
This position is based in Pennsylvania (remote, US only) and offers an expected annual compensation range of USD 125,600 - 172,700, which includes base pay plus variable incentive pay, if eligible.
Responsibilities
- Operate and enhance application security tool environments.
- Write automation scripts for recurring tasks (Python preferred).
- Set up and run authenticated and unauthenticated DAST scans against web applications and APIs using approved tools.
- Manage scan scheduling, configuration, and coverage across application security tool environments.
- Tune scanning profiles to reduce false positives and improve detection accuracy.
- Ensure DAST scanning aligns with release cycles and risk-based scanning requirements.
- Validate DAST results to confirm exploitability and business impact.
- Categorize vulnerabilities using industry standards (for example, OWASP Top 10).
- Prioritize findings based on risk, application criticality, and exposure.
- Eliminate false positives and remove duplicate findings before developer handoff.
- Partner with development and platform teams to explain DAST findings and expected remediation.
- Track remediation progress and verify fixes through re-scanning or targeted validation.
- Maintain accurate vulnerability records in enterprise tracking systems.
- Escalate overdue or high-risk vulnerabilities according to policy.
- Work with application teams to validate software meets security guidelines and compliance standards such as HIPPA, SOC II, GDPR, NIST 800-53, and FedRAMP.
- Build solutions that collect and present vulnerability and compliance data to Solventum leadership.
- Ensure corporate policies, procedures, and security standards are followed during assigned duties.
Requirements
- Bachelor’s Degree and 7 years of experience in application security.
- 3 years experience administering, running, and analyzing DAST tools.
- Knowledge of AWS or Azure cloud environments.
- Familiarity with best-practice software security requirements in industry compliance programs (including NIST, HITRUST, FedRAMP, etc.).
- Experience developing or testing RESTful APIs, with understanding of Postman and/or Swagger files.
- Ability to obtain and maintain a Public Trust clearance.
Technologies
- Python
- DAST
- AWS
- Azure
- Postman
- Swagger
- RESTful APIs
- Qualys
- Tenable
Benefits
- Medical, Dental & Vision
- Health Savings Accounts
- Health Care & Dependent Care Flexible Spending Accounts
- Disability Benefits
- Life Insurance
- Voluntary Benefits
- Paid Absences
- Retirement Benefits
Work Location and Travel
- Remote – US Only
- No travel required
- Relocation assistance: Not authorized
Onboarding Requirement
New employees hired for this position will be required to travel to a designated company location for on-site onboarding during their initial days of employment. This applies to new hires with a start date of October 1st, 2025 or later.
Application Notes
Your application may not be considered if you do not provide your education and work history, either by uploading a resume or entering the information directly into the application fields.