Skip to main content
Back to jobs

Cybersecurity Engineer - Application Security Enablement

External
Labcorp logoLabcorp · US
$160K–$170K/yrFull-timeRemote3d ago
Application SecurityDevSecOps
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Labcorp is seeking a Cybersecurity Engineer - Application Security Enablement to join our team in a remote capacity. Location : Remote Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility. Work Schedule: This is afull‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in your local time zone.Business needs may occasionally require flexibility in work hours, including earlier, later, oradditionalhours, with reasonable notice provided when possible. Job Responsibilities Application Security Design Standards & Patterns Define and document secure development standards and patterns for modern application architectures (web, API, microservices), with guidance grounded in industry best practices such as OWASP and informed by broader frameworks (i.e.NIST, CIS Controls). Develop reusable patterns for common application scenarios such as secure APIs, service-to-servicecommunicationand front-end/back-end architecture. Translate complex security risks into clear, developer-focused guidance that can be easily adopted. Contribute to the creation of machine-consumable security patterns to support AI-enabled and automated development tools. Secure Design Enablement Collaboratewith engineers and architects during design discussions toprovide guidance on secure application architecture and design decisions. Identifycommon security pitfalls early in the lifecycle. Provide guidance onsecure integration and data protection patterns. For example: - Input validation and output encoding - API security and authentication flows - Session management and token handling - Secrets management and secure configuration Promotesecure-by-design and secure-by-default principlesto enable efficient and secure development practices. Identity & Access Management (Supporting Role) Support the integration of authentication and authorization patterns within applicationarchitecture. Ensure secure implementation of protocols such as OAuth 2.0, OIDC, and SAML. Align application security practices with identity and access management, identity governance, and privileged access management solutions. Cross-Functional Collaboration Partner with Digital IdentityServices, Cybersecurity Engineering, Product Security Testing, and other teams to provide application security guidance and support risk mitigation. Collaborate withtheGovernance, Risk, and Compliance team to align application security practices with enterprise policies and regulatory requirements. Work with Cybersecurity Operations to enhance detection and response capabilities forapplication-levelthreats. Engage with Enterprise Architecture teams to influence secure design decisions. Support data protection initiatives by ensuringappropriate controlsfor sensitive data handling and exposure mitigationareutilized. Risk Advisory Review vulnerability patterns and provide guidance on prioritization and remediation of application security risks. Serve as a trusted advisor to engineering and architecture teams, offering practical and actionable security recommendations. Support standardization of application security risk management practices across teams. Continuous Improvement and Innovation Stay current with emerging threats, vulnerabilities, and trends in application security. Evaluate and evolve security standards to support cloud native, API first, distributed, and AI enabled applications. Contribute to the development of scalable, consistent application security enablement practices across the organization. Minimum Qualifications High school diploma with 12 or more years of experience in application security, secure software development, or cybersecurity engineering; or Associate degree with 10 or more years of experience ; or Bachelor's degree in Computer Science, Information Security, or Engineering with 8 or more years of experience ; or Master's degree in Computer Science, Information Security, or Engineering with 6 or more years of experience. 8 or more years of experience in application security, secure software development, or cybersecurity engineering, with a focus onidentifyingand addressing application-layer risks. 5 or more years of experience applying secure coding principles and addressing application security risks using OWASP Top 10 or similar best practices, with the ability to translate risks into actionable developer guidance. 3 or more years of experience working with enterprise security frameworks such as NIST CSF, CIS Controls, or ISO 27001, withdemonstratedability to align application security practices tothese or otherapplicableframeworks. 3 or more years of experience in application or software development, OR equivalent experience working closel


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Labcorp? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect