The Senior Information Security Engineer – Application Protection will design, implement, and maintain enterprise security platforms and tools that support vulnerability management, application security, and API protection. The role focuses primarily on engineering and administration of security tools, with secondary support for vulnerability analysis and secure software development initiatives.
Key Responsibilities:
Administer and maintain tools that perform application code scanning, application security posture management, host and network vulnerability scanning, and API security protections.
Design and implement integrations and automation between security tools and enterprise systems, including the ServiceNow platform, using available APIs and orchestration workflows.
Monitor the performance, availability, and efficacy of security tools to ensure accurate and consistent results.
Develop and maintain scripts, dashboards, and reports to improve visibility, efficiency, and response capabilities.
Collaborate with application, infrastructure, and network teams to ensure proper configuration and effective operation of security tools.
Support secure software development lifecycle and API security initiatives through reliable tool operation and ensuring data integrity.
Troubleshoot tool performance issues and coordinate with vendors for maintenance, updates, and enhancements.
Master’s degree with one (1) year experience or Bachelor’s degree in Computer Science, Information Systems, Engineering or related major and a minimum two (2) years’ experience in the information security field required.
The Information Security Senior Engineer also requires the following skills/abilities:
Additional Qualifications
Strong systems engineering background with experience in Windows, Linux, or cloud environments.
Demonstrated expertise in networking concepts, protocols, and troubleshooting.
Familiarity with application security concepts, APIs, and network architectures.
Proficiency with scripting or automation languages such as PowerShell or Python.
Proven ability to diagnose and resolve complex system and tool issues independently, even without vendor support.
Experience administering and integrating enterprise-grade security or IT management tools.
Ability to identify performance issues, detect coverage gaps in security tooling, and recover from operational incidents.
Effective communication and collaboration skills for working across security and IT teams.
This vacancy is not eligible for sponsorship/ we will not sponsor or transfer visas for this position. Also, Mayo Clinic DOES NOT participate in the F-1 STEM OPT extension program.