Application Security Engineer
Full-time
Description
<p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p style="text-align:left">Insulet started in 2000 with an idea and a mission to enable our customers to enjoy simplicity, freedom and healthier lives through the use of our Omnipod® product platform. In the last two decades we have improved the lives of hundreds of thousands of patients by using innovative technology that is wearable, waterproof, and lifestyle accommodating.</p><div><div><div><div><p style="text-align:inherit"></p><p style="text-align:left">We are looking for highly motivated, performance driven individuals to be a part of our expanding team. We do this by hiring amazing people guided by shared values who exceed customer expectations. Our continued success depends on it!</p></div></div></div></div><p style="text-align:inherit"></p><p><span style="color:#000000"><span style="font-size:14px">Company Overview:</span></span></p><p><span style="color:#000000"><span style="font-size:14px">Insulet started in 2000 with an idea and a mission to enable our customers to enjoy simplicity, freedom and healthier lives using our Omnipod® product platform. In the last two decades we have improved the lives of hundreds of thousands of patients by using innovative technology that is wearable, waterproof, and lifestyle accommodating.</span></span></p><p><span style="color:#000000"><span style="font-size:14px">We are looking for highly motivated, performance-driven individuals to be a part of our expanding Application Security team. We do this by hiring amazing people guided by shared values who exceed customer expectations. Our continued success depends on it!</span></span></p><p><span style="color:#000000"><span style="font-size:14px">Position Overview:</span></span></p><p><span style="color:#000000"><span style="font-size:14px">We are seeking a highly motivated Security Engineer to help scale and mature our Application Security and DevSecOps capabilities across our product portfolio. In this role, you will partner closely with engineering, product, and compliance teams to embed security into the software development lifecycle, automate security testing, and drive remediation of application and product risks.</span></span></p><p><span style="font-size:14px">This role is ideal for someone who enjoys working </span><i><span style="font-size:14px">hands-on</span></i><span style="font-size:14px"> with development teams, security tooling, and automation, while also contributing to process definition and security program maturity.</span></p><p><span style="color:#000000"><span style="font-size:14px">Responsibilities:</span></span></p><ul><li><p><span style="font-size:14px">Implement and operationalize a Secure Software Development Lifecycle (SSDLC) across products, including defining processes, controls, and security checkpoints in collaboration with cross‑functional teams.</span></p></li><li><p><span style="font-size:14px">Execute and scale automated application security testing in CI/CD pipelines, including:</span></p></li></ul><ul><li><p><span style="color:#000000"><span style="font-size:14px">Static Application Security Testing (SAST)</span></span></p></li><li><p><span style="color:#000000"><span style="font-size:14px">Dynamic Application Security Testing (DAST)</span></span></p></li><li><p><span style="color:#000000"><span style="font-size:14px">Software Composition Analysis (SCA)</span></span></p></li><li><p><span style="color:#000000"><span style="font-size:14px">API and runtime security testing</span></span></p></li></ul><ul><li><p><span style="font-size:14px">Triage, validate, and prioritize security findings, reduce false positives, and partner with engineering teams to drive effective remediation.</span></p></li><li><p><span style="font-size:14px">Perform hands‑on application security activities, including threat modeling, secure design reviews, code reviews, and targeted security testing aligned to OWASP Top 10 and CWE Top 25 risks.</span></p></li><li><p><span style="font-size:14px">Support vulnerability disclosure and bug bounty programs, including intake, validation, coordination, and remediation tracking.</span></p></li><li><p><span style="font-size:14px">Contribute to application security awareness and training, helping developers understand secure coding practices and common vulnerability patterns.</span></p></li><li><p><span style="font-size:14px">Develop and maintain application security metrics and dashboards, providing a consolidated (“single pane of glass”) view of risk posture through automation.</span></p></li><li><p><span style="font-size:14px">Research emerging technologies, frameworks, and attack techniques and assess their applicability and risk to current and future products.</span></p></li><li><p><span style="font-size:14px">Collaborate with Quality, Regulatory, Legal, Privacy, Compliance, Architecture, and Product Development teams to ensure security is designed in, verified during development, and managed in production.</span></p></li><li><p><span style="font-size:14px">Support cybersecurity documentation and evidence required for regulatory submissions in regulated product environments.</span></p></li></ul><p><span style="color:#000000"><span style="font-size:14px">Qualifications:</span></span></p><ul><li><p><span style="font-size:14px">Bachelor’s degree in information security or computer science, or equivalent practical experience.</span></p></li><li><p><span style="font-size:14px">3–5 years of experience in cybersecurity with a strong focus on application security, product security, or DevSecOps.</span></p></li><li><p><span style="font-size:14px">Hands‑on experience with tooling, such as:</span></p></li></ul><ul><li><ul><li><p><span style="color:#000000"><span style="font-size:14px">SAST, DAST, SCA, IAST, and API testing tools</span></span></p></li><li><p><span style="color:#000000"><span style="font-size:14px">Examples include Check Marx, Snyk, ZAP, Dependency‑Track, GitHub Actions, Jenkins, or similar</span></span></p></li></ul></li></ul><ul><li><p><span style="font-size:14px">Demonstrated ability to identify, validate, and explain OWASP Top 10 and CWE Top 25 vulnerabilities.</span></p></li><li><p><span style="font-size:14px">Experience integrating security testing into CI/CD pipelines and modern development workflows.</span></p></li><li><p><span style="font-size:14px">Familiarity with vulnerability disclosure and bug bounty programs.</span></p></li><li><p><span style="font-size:14px">Working knowledge of at least one common programming language (e.g., C, C++, Java, .NET, Python, or similar).</span></p></li><li><p><span style="font-size:14px">Understanding of threat modeling, attack surfaces, common exploit classes, and frameworks such as MITRE ATT&CK.</span></p></li><li><p><span style="font-size:14px">Strong written and verbal communication skills, with the ability to translate security risks into clear, actionable guidance for technical and non‑technical audiences.</span></p></li><li><p><span style="font-size:14px">Required Leadership/Interpersonal Skills & Behaviors:</span></p></li><li><p><span style="font-size:14px">Effectively communicate complex information, concepts, and ideas in a clear and organized manner through verbal, written, and visual mechanisms.</span></p></li><li><p><span style="font-size:14px">Strong collaboration skills and an ability to work with cross-functional teams across the security and privacy organization and broader Corporate Technology organization.</span></p></li><li><p><span style="font-size:14px">Ability to work with virtual and global teams in a fast-paced environment.</span></p></li><li><p><span style="font-size:14px">Experience balancing security needs with broader business objectives.</span></p></li></ul><p><span style="color:#000000"><span style="font-size:14px"> </span></span></p><p><span style="color:#000000"><span style="font-size:14px"> </span></span></p><p><span style="color:#000000"><span style="font-size:14px"> </span></span></p><p><span style="color:#000000"><span style="font-size:14px"> </span></span></p><p><span style="color:#000000"><span style="font-size:14px">At Insulet Corporation all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.</span></span></p>
Insulet
BIOTECHNOLOGY
Insulin Pump
LocationACTON, MA
Employees201-500
Open Jobs390
Metabolic Diseases
View Company ProfilePipeline
Omnipod 5 Automated Insulin Delivery SystemN/A
Omnipod M systemN/A
Omnipod Horizon™ Automated Glucose Control SystemN/A
Heart rate informed SSM+HMMN/A
Omnipod 5 Automated Glucose Control SystemN/A