Source description
About the role
JOB DESCRIPTION
Provides application security architecture and governance support within the Application Security Center of Excellence (AppSec CoE). Responsible for identifying, assessing, and managing application and software supply chain risks, and defining secure-by-design patterns that enable development teams to deliver secure applications at scale.
Partners with development teams, solution architects, DevOps teams, and security stakeholders to embed security controls across the Software Development Lifecycle (SDLC) and support a shift-left DevSecOps model
Essential Job Duties
Partners with application teams to evaluate application security risks across the SDLC (design, build, test, deploy)
Conducts or supports threat modeling, secure design reviews, and architecture reviews for applications, APIs, and cloud-native systems
Defines and promotes secure architectural patterns, guardrails, and reusable controls aligned with AppSec standards
Provides guidance on integration and usage of AppSec tools (e.g., SAST, DAST, SCA) within CI/CD pipelines
Supports enforcement of security requirements, standards, and control gating within SDLC processes
Identifies application security gaps and works with teams to define actionable risk mitigation strategies
Assists in tracking vulnerabilities, exceptions, and risk acceptances (RARE/SRA) in alignment with governance processes
Collaborates with Security Champions and development teams to improve application security maturity and adoption
Contributes to AppSec awareness, training, and enablement initiatives
Acts as a subject matter expert for application security and DevSecOps practices
Job Requirements
3+ years experience in application security, software security, or DevSecOps
Knowledge of secure SDLC practices, threat modeling, and secure design principles
Experience with application security testing tools (SAST, DAST, SCA)
Understanding of OWASP Top 10, API security risks, and secure coding practices
Familiarity with CI/CD pipelines and DevOps tooling
Ability to translate technical risks into business context
Preferred Qualifications
-
CISSP, CISM, CCSP, or equivalent
-
Experience implementing OWASP SAMM or NIST SSDF-aligned programs
-
Experience leading AppSec or DevSecOps transformation initiatives
-
To all current Molina employees. If you are interested in applying for this position, please apply through the Internal Job Board.
-
Molina Healthcare offers a competitive benefits and compensation package. Molina Healthcare is an Equal Opportunity Employer (EOE) M/F/D/V
More at Molina Healthcare
Related open roles
Analyst, Data & Analytics (Must reside in CA)
Los Angeles
Engineer, EIS - Endpoint Security/Tanium/Intune - Remote
United States
Senior Engineer, EIS - SASE & Data Security - Remote
United States
Architect, Information Security (network security, cloud security)
United States
Crisis & Cyber Response Manager
United States
Senior Artificial Intelligence Security Architect - Remote
United States