Information Security Engineer, Principal
BSC
- Employment
- Full-time
- Seniority
- Staff
About the role
About Stellarus and the Ascendiun Family of Companies
Stellarus, launched in January 2025, is designed to scale innovative healthcare solutions that support customers in creating a health care experience deserving of their family, friends, and neighbors.
Stellarus is part of a family of organizations that is overseen by a nonprofit corporate entity named Ascendiun. The Ascendiun Family of Companies also includes Blue Shield of California and its subsidiary, Blue Shield of California Promise Health Plan and Altais, a clinical services company.
Stellarus’ vision is to empower its customers to create a healthcare experience that is worthy of their family, friends, and neighbors. Stellarus’ objective is to offer innovative, modern, scalable solutions that challenge the health care status quo. This very closely aligns with Blue Shield of California’s vision by using innovation to improve quality, affordability, and experience for members.
To achieve our mission, we foster an environment where all employees can thrive and contribute fully to address the needs of the various communities we serve. We are committed to creating and maintaining a supportive workplace that upholds our values and advances our goals.
Our Values:
At Stellarus, our core values of agility, trust, drive, courage and service shape our approach to developing innovative product offerings.
Physical Requirements:
Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.
Please click here for further physical requirement detail.
Equal Employment Opportunity:
External hires must pass a background check/drug screen. Qualified applicants with arrest records and/or conviction records will be considered for employment in a manner consistent with Federal, State and local laws, including but not limited to the San Francisco Fair Chance Ordinance. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or disability status and any other classification protected by Federal, State and local laws.
Your Role
The Application Security team reports to the Director of Information Security and is responsible for driving continual risk reduction across application services. This role partners closely with development teams, providing security oversight at each stage of the Software Development Lifecycle while enabling the business to operate securely at scale.
Your Work
In this role, you will:
- Evaluate new solution proposals and provide security requirements
Perform STRIDE based threat modeling
Complete secure source code reviews
Create and review CICD layer security unit tests
Administer our bug bounty program
Coach security champions in our partnering teams
Provide general security consulting
Create and leverage AI solutions for streamlining your work
- Drive continual maturation of our Application Security program, consistent with proven industry best practices and maturity models.
Your Knowledge and Experience
- Bachelor's degree or equivalent experience
- At least 10 years prior relevant experience with at least 2 years working in Application Security
- Deep, demonstrated understanding of Application Security paradigms and common risks (i.e. OWASP Top Ten)
- Strong understanding of Agile delivery models and backlog management
- Ability to manage multiple complex workstreams and successfully interact with all levels of management
- Experience with regulatory certifications such as HIPAA, SOC2, PCI-DSS and FedRAMP
- Excellent verbal / written communication, collaboration, analytical and presentation skills
- Experience with AI/ML concepts and tools desired
- Preferred experience working within the Healthcare industry
Hybrid
This role requires employees to be in - office based on our hybrid workplace model, balancing purposeful in - person collaboration with flexibility. For most teams, this means coming into the office two days each week.
Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.
#LI-CP4
741,000+ hidden jobs like this
BSC and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.
Everything Pro unlocks:
- Unlimited applications — free stops at 5
- Track every application in one place
- Apply straight to the source, one click
- Save & organize roles you love
- Roles pulled from company boards before the big sites