Secure Development and Code ReviewDevelop, implement, and maintain Secure Software Development Lifecycle (SSDLC) standards supporting Azure-hosted applications, Adobe Experience Cloud, and other internally managed platformsSupport secure software development for academic, research, and clinical applications, with an emphasis on higher-risk clinical systemsPerform manual and automated secure code reviews for internally developed applications, identifying vulnerabilities aligned with the OWASP Top 10 and CWE Top 25Integrate Static Application Security Testing (SAST) and Software Composition Analysis (SCA) into CI/CD pipelinesPartner with software developers to remediate vulnerabilities and promote secure coding practices through guidance and educationSecurity Testing and Vulnerability ManagementConfigure and operate Burp Suite Professional/Enterprise for Dynamic Application Security Testing (DAST) and authorized penetration testingUtilize OWASP ZAP for automated and on-demand application security scanningPerform controlled validation testing using Metasploit during authorized penetration testing engagementsTriage, prioritize, and track remediation efforts through a risk-based vulnerability management processCoordinate security testing schedules with application owners to minimize operational disruptionSupport QA and automated testing initiatives validating application security controls throughout deployment pipelinesCloud and Platform SecurityAssess Microsoft Azure and other cloud environments for security posture, including identity and access management, network segmentation, and resource-level security controlsReview Adobe Experience Cloud and SaaS/PaaS integrations to ensure secure configuration and appropriate data protectionSupport secure API design, authentication, authorization, and data validation practicesRecommend improvements that strengthen cloud and enterprise application security architectureAI, Robotics, and Biomedical Systems SecurityAssess the security of AI/ML models, data pipelines, and AI-enabled applicationsReview secure integration of generative AI tools, chatbots, and AI-driven APIs supporting institutional applicationsEvaluate security controls for robotics programming, automation platforms, and robotic process automation (RPA) solutionsSupport security assessments of biomedical systems and connected medical devices operating within clinical environmentsCollaborate with research, innovation, and clinical teams to embed secure development practices throughout AI and robotics initiativesGovernance, Risk, and ComplianceAlign application security practices with HIPAA, HITRUST CSF, NIST CSF 2.0, TAC 202, and UTS 165 requirementsSupport third-party risk assessments (TPRM) and application security reviewsParticipate in audit activities, including HITRUST readiness assessmentsDevelop and maintain application security policies, standards, and proceduresCross-Functional CollaborationPartner with Cybersecurity Analysts on threat modeling, incident response, and architecture reviews for new applications and integrationsCollaborate with the campus Information Security Office (ISO) to support application security standards, risk assessments, vulnerability management, and coordinated incident responseWork closely with Infrastructure, Development, and Platform Engineering teams to integrate security throughout project lifecyclesCommunicate technical findings, security risks, and recommendations to technical and executive stakeholdersMarginal or Periodic FunctionsAdhere to internal controls and reporting structurePerform related duties as assignedKnowledge, Skills, and AbilitiesTech SavvyMaintain current knowledge of secure software development, cloud security, application security testing, and emerging cybersecurity technologiesEvaluate new tools and technologies that strengthen enterprise application securityApply modern security practices across cloud, application, and software development environmentsDecision QualityMake sound security decisions balancing organizational risk, operational needs, and regulatory requirementsEvaluate vulnerabilities and recommend practical remediation strategiesPrioritize security initiatives using risk-based methodologiesManages ComplexityNavigate complex cloud, application, and healthcare technology environmentsBalance multiple priorities across development, security, and operational initiativesIntegrate security controls into rapidly evolving technology ecosystemsCollaboratesBuild productive working relationships with development, infrastructure, cybersecurity, clinical, research, and operational teamsPromote security awareness and secure development practices throughout the organizationFacilitate collaboration across multidisciplinary technical teamsAction OrientedTake ownership of application security initiatives and vulnerability remediation effortsDrive continuous improvement of secure development practicesRespond proactively to emerging application security risksEnsures AccountabilityMaintain accountability for application security standards and vulnerability management activitiesPromote compliance with organizational security policies and regulatory requirementsSupport secure software delivery through consistent governance and oversightCommunicates EffectivelyCommunicate technical concepts clearly to both technical and non-technical audiencesPresent security findings, recommendations, and risk assessments effectivelyDevelop documentation supporting secure development and application security best practices