Lead Application Security Engineer- DevSecOps
athenahealth
- Location
- Boston, Massachusetts, United States of America
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Salary
- $143k – $243k/yr
- Posted
- Sep 8, 2026
Skills
About this role
Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. athenahealth is seeking a Lead Security Engineer to help increase the security capabilities of its teams. This role works closely with scrum teams, product managers, and engineering leadership to improve the quality and adoption of Security Development Lifecycle practices, with a strong emphasis on API security. This position owns the technical direction, implementation, and operation of security capabilities and is suited for someone who enjoys setting technical strategy, influencing stakeholders, and defining measurable security outcomes.
About the Team
This team solves application security problems at scale and partners across engineering and security functions to help protect athenahealth’s products and platforms. The work combines security engineering, software development, and cross-functional communication to support secure product delivery in a healthcare environment.
Core Responsibilities
Security strategy and SDLC adoption Socialize and drive execution of key security best practices across the R&D organization. Contribute to the enterprise security catalog of best practices, techniques, and patterns. Improve the quality and adoption of Security Development Lifecycle practices. Application security capability ownership Own the evaluation, design, implementation, integration, reliability, and continuous improvement of application security capabilities. Support SAST, SCA, DAST, API security testing, and vulnerability management workflows. Document, share, and help automate coverage for common abuse cases and attacks. API security program leadership Lead the API security testing program. Manage API discovery, authenticated and unauthenticated testing, scanner attribution, onboarding, exclusions, ownership mapping, findings routing, and operational readiness. Identify and explain feature-level design or architectural weaknesses that could create security issues. Cross-functional partnership and issue management Partner with enterprise security leadership to track and prioritize open issues and follow through on resolution. Work with DevOps, Infrastructure, IAM, API Gateway, NOC, Enterprise Security, and application teams to design and operate security-hardened platforms. Required Experience & Skills Bachelor’s degree in Computer Science, Computer Engineering, Cyber Security, or similar, or equivalent experience. At least 3 years of experience as a software developer and 3–5 years in a security-focused development role in an agile environment. Experience in software and product design and architecture, product security, and security issue prevention and mitigation. Strong software engineering background with the ability to develop, review, and troubleshoot code in one or more languages. Practical experience with Docker and Terraform. Strong knowledge of OAuth 2.0, OpenID Connect, JWT, SAML, and service-to-service authentication. Solid understanding of RESTful services, service bus architectures, JSON, and related web services concepts. Experience with SAST, SCA, DAST, API security testing, vulnerability aggregation, and CI/CD security controls. Hands-on experience with cloud platforms, containers, infrastructure as code, secrets management, and CI/CD. Knowledge of HIPAA, HITRUST, and PCI-DSS is a plus. Why This Role Matters This role is central to strengthening secure software delivery across athenahealth. It combines technical depth, security leadership, and cross-functional influence to improve how security is built into products from the start. Expected Compensation $143,000 - $243,000 The base salary range shown reflects the full range for this role from minimum to maximum. At athenahealth, base pay depends on multiple factors, including job-related experience, relevant knowledge and skills, how your qualifications compare to others in similar roles, and geographical market rates.