25 Sep
|
Ensemble Health Partners India
|
India
25 Sep
Ensemble Health Partners India
India
Thank you for considering a career at Ensemble Health Partners India!
Ensemble Health Partners - The single solution for a frictionless revenue cycle with the purpose of redefining the possible in healthcare by empowering people to be the difference. Our India Office is an extension of Ensemble’s team and culture designed to augment and enhance our talent and skill base in Revenue Cycle Management in addition to our long-standing presence in technology. Leveraging our platform of services, technology, business intelligence and analytics, our teams are creating and maintaining innovative products and systems to help our revenue cycle operators achieve the most efficient, ideal outcomes for our clients. Our teams are certified in revenue cycle best practices and are supporting end-to-end RCM operations. We are at the forefront of innovation using cutting-edge technology to drive meaningful impact in the Revenue Cycle Management landscape. As a leading player in the industry, we offer an setting that fosters growth, creativity, and collaboration, where your expertise will be valued, and your contributions will make a difference.
The Opportunity:
Job Title: Application Security Architect
Experience: 12+ Years
Job Location: Hyderabad (Hybrid)
Position Summary:
We are looking for a hands-on **Application Security Architect** who combines strong software engineering skills with deep application security expertise. This is a generalist role — you should be comfortable reading and writing production-quality code across multiple languages, and equally comfortable designing and running an AppSec program that spans SAST, DAST, and SCA tooling, secure architecture reviews, and developer enablement. This position will require occasional after-hours and weekend work. The selected candidate will be expected to attend work on a regular and predictable schedule in accordance with agency leave policy and perform other duties as assigned.
Key Responsibilities
Design and drive the application security strategy across the SDLC — from design reviews through CI/CD to production.
Own and continuously tune **SAST** (e.g., Checkmarx, Fortify, Semgrep, CodeQL), **DAST** (e.g., Burp Suite Enterprise, OWASP ZAP, Invicti), and **SCA** (e.g., Snyk, Black Duck, Mend, Dependency-Track) tooling — integration, rule tuning, false-positive reduction, and coverage.
Perform secure architecture and design reviews for new features, services, and major system changes.
Read, write, and refactor code (not just review it) to build internal tooling, PoCs for vulnerabilities, custom scanners, and secure-by-default libraries/frameworks.
Conduct manual code reviews and threat modeling for high-risk services, complementing automated tooling.
Partner with engineering teams to remediate vulnerabilities, and act as a technical escalation point for security findings.
Build and maintain CI/CD security gates (pre-commit hooks, pipeline scanning, break-the-build policies).
Define and evangelize secure coding standards, guardrails, and reusable security patterns/libraries.
Run or support penetration tests and coordinate remediation with engineering.
Mentor developers and security champions; deliver secure coding training.
Track and report AppSec metrics (vulnerability density, MTTR, tool coverage, false-positive rates) to leadership.
Stay current on emerging threats (OWASP Top 10, CWE/SANS Top 25, supply chain attacks) and evolve the program accordingly.
Required Skills:
**Engineering foundation (must-have — this is a generalist coding role, not a pure GRC/tooling role): **
Strong hands-on software development experience in at least one backend language (e.g., Java, Python, Go, Node.js, C#) and working familiarity with others.
Comfortable reading and writing code across the stack — APIs, web front ends, mobile, or infrastructure-as-code, as relevant to your environment.
Solid understanding of software design patterns, frameworks, and modern CI/CD pipelines.
**Application security expertise: **
Deep, practical experience with **SAST**, **DAST**, and **SCA** tools — selection, deployment, tuning, and interpreting results (not just running scans).
Strong grasp of OWASP Top 10, OWASP ASVS, CWE/SANS Top 25, and secure design principles (authN/authZ, cryptography, input validation, session management).
Experience with threat modeling methodologies (STRIDE, PASTA, or similar).
Familiarity with container/cloud security (Docker, Kubernetes, AWS/Azure/GCP security services) is a plus.
Understanding of software supply chain security (SBOM, dependency risk, artifact signing).
Experience building custom security tooling or writing SAST/DAST rules.
Exposure to regulated industries (BFSI, healthcare) or compliance frameworks (PCI-DSS, ISO 27001, SOC 2).
Why Choose Ensemble India?
People First, Last + Always
We believe in putting people at the heart of everything. Our culture is rooted in collaboration, growth and innovation—where your contributions are valued, your voice is heard and your potential is nurtured.
A Place to Thrive
Whether you're just starting out or looking to grow your career, Ensemble India is a place where you can do your best work and be your best self. We offer structured career paths, paid professional certifications, tuition reimbursement and mentorship opportunities to help you advance.
Comprehensive Total Rewards
We support the physical, emotional and financial well-being of you and your family. Our Total Rewards package include:
- Healthcare coverage for associates and their immediate families including parents
- Paid time off plans
- Retirement benefits
- Recognition and wellness programs
- Market competitive pay rates
Inclusive Culture
Our organization is deeply committed to fostering a positive environment and culture where we celebrate and reward merit and contribution and where every associate feels valued, included, and empowered to succeed.
Purpose-Driven Impact
We proudly partner with local communities through philanthropic initiatives—from school supply drives to health awareness campaigns—because giving back is part of who we are.
Ensemble Health Partners is an equal employment opportunity employer. It is our policy not to discriminate against any applicant or employee based on race, color, sex, sexual orientation, gender, gender identity, religion, national origin, age, disability, military or veteran status, genetic information or any other basis protected by applicable federal, state, or local laws. Ensemble Health Partners also prohibits harassment of applicants or employees based on any of these protected categories.
📌 Application Security Architect, Cybersecurity (India)
🏢 Ensemble Health Partners India
📍 India