The Application Security Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes information system security administration and maintenance, vulnerability management, and configuration of other security software and solutions.
Key Responsibilities:
- Implement and maintain security measures across systems and software development processes, including system hardening, monitoring, vulnerability assessment and remediation, incident response, disaster recovery, enforcing secure software development lifecycle practices, and emerging cybersecurity threats.
- Implement security controls in colocation and cloud environments, focusing on secure configuration and compliance.
- Collaborate with development and IT teams to ensure security practices are integrated into daily operations.
- Participate in the security incident response process by aiding in the detection, containment, and reporting of incidents.
- Deploy, integrate, configure, and maintain software according to WellSky policy and industry standards, including upgrades, patch management, and troubleshooting support.
- Leverage AI tools and platforms as an integral part of daily responsibilities to enhance decision-making, streamline workflows, and drive data-informed outcomes.
- Perform other job duties as assigned.
Required Qualifications:
- Bachelor's degree in a related field or equivalent work experience
- 0 - 2 years related work experience
Preferred Qualifications and Interests:
- Healthcare industry experience
- Experience using AI assistants and agentic tools (e.g., Claude, Gemini) to accelerate security analysis, scripting, log review, and documentation
- Familiarity with prompt engineering and with evaluating AI output for accuracy before acting on it
- Awareness of AI/LLM-specific risks such as prompt injection, data leakage through prompts, insecure output handling, and excessive agent permissions (OWASP Top 10 for LLM Applications)
- Understanding of secure use of AI coding assistants in the SDLC, including reviewing generated code, preventing secrets or PHI from entering prompts, and managing third-party AI tool approval
- Interest in securing AI/ML workloads and agent integrations, including MCP servers, API keys, service accounts, and data boundaries
- Security certification such as Security+, SSCP, GIAC (GSEC), or AWS/Azure security fundamentals, or actively pursuing certification
- Exposure to cloud security services and secure configuration in AWS, Azure, or GCP
- Familiarity with vulnerability management tooling (e.g., Snyk, Wiz) and SIEM/EDR platforms (e.g., Google SecOps, CrowdStrike)
- Scripting and automation skills in Python, PowerShell, or Bash
- Familiarity with HITRUST CSF, HIPAA Security Rule, NIST CSF/800-53, and CIS Benchmarks
- Exposure to DevSecOps practices including CI/CD pipeline security, infrastructure-as-code scanning, and secret detection
- Clear written communication for documenting findings and coordinating remediation with development teams
Job Expectations:
- Willing to work additional or irregular hours as needed
- Must work in accordance with applicable security policies and procedures to safeguard company and client information
- Must be able to sit and view a computer screen for extended periods of time
#LI-TC1
#LI-Onsite
WellSky is where independent thinking and collaboration come together to create an authentic culture. We thrive on innovation, inclusiveness, and cohesive perspectives. At WellSky you can make a difference.
Here are some of the exciting benefits full-time teammates are eligible to receive at WellSky:
- Excellent medical with Rx, dental, and vision benefits
- Mental Health support through EAP
- Generous paid time off, plus 13 paid holidays
- 100% vested 401(K) retirement plans
- Educational assistance up to $2500 per year
WellSky provides equal employment opportunities to all people without regard to race, color, national origin, ancestry, citizenship, age, religion, gender, sex, sexual orientation, gender identity, gender expression, marital status, pregnancy, physical or mental disability, protected medical condition, genetic information, military service, veteran status, or any other status or characteristic protected by law. WellSky is proud to be a drug-free workplace.
Applicants for U.S.-based positions with WellSky must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Certain client-facing positions may be required to comply with applicable requirements, such as immunizations and occupational health mandates.
Data Privacy Notice for Job Applicants and Teammates