Company
healthcare
SecurityChampion
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Security Champion. Skills: application security, Java development, DevSecOps. embedding security best practices into the software development lifecycle. continuously improving the security posture of the solution”
What You'll Achieve.
continuously improving the security posture of the solution; drive remediation activities; promote a security‑first culture; ensure alignment with corporate security policies and regulatory requirements.
Industry & Context.
What They're Looking For.
Must Have
Former or current Java developer with a focus on application security., Solid experience with enterprise Java applications (e.g., Spring ecosystem, REST APIs, relational databases)., understanding of application security principles and common vulnerabilities (e.g., OWASP Top 10)., Proven experience applying secure coding practices in Java and related frameworks., Familiarity with security frameworks and standards (e.g., OWASP ASVS, NIST, ISO 27001)., Ability to perform and document threat modeling and risk assessments., Hands-on experience with vulnerability assessment and verification (automated tools and manual analysis)., Knowledge of DevSecOps practices and integrating security controls into CI/CD pipelines., Awareness of data protection and compliance requirements (e.g., healthcare-related regulations are a plus)., Clear, concise communication skills, able to explain security risks and trade-offs to both technical and non-technical stakeholders., collaboration and influencing able to drive security improvements while remaining pragmatic., High level of integrity, proactive mindset, and attention to detail.
Nice to Have
Experience working on data-sensitive or mission-critical healthcare domain experience is an advantage., Security-related certifications (e.g., CSSLP, CEH, Security+, GWAPT) are an advantage but not mandatory.
What You'll Do.
embedding security best practices into the software development lifecycle
continuously improving the security posture of the solution
identifying security gaps
drive remediation activities
promote a security‑first culture
Act as the primary application security point of contact for G3 HIS teams.
Conduct security design reviews
and security‑focused code reviews for new and existing features.
Define and refine security requirements and controls for G3 HIS components and services.
Support the selection
and effective use of security tooling
and track remediation of findings from security tools and external assessments.
Monitor security trends
and vulnerabilities relevant to the stack and domain
and translate them into concrete improvements.
How You'll Work.
Team & Collaboration
Collaborate with G3 HIS development, QA, DevOps, and architecture teams; Collaborate with developers, architects, QA, and DevOps to integrate security into design, implementation, testing, and deployment.; Coordinate with central Security / InfoSec and Compliance teams to ensure alignment with corporate security policies and regulatory requirements.
Communication Scope
Clear, concise communication skills; able to explain security risks and trade-offs to both technical and non-technical stakeholders.
Full Job Description
**Role Summary** The Security Champion for the G3 HIS product is responsible for embedding security best practices into the software development lifecycle and continuously improving the security posture of the solution. The role collaborates with G3 HIS development, QA, DevOps, and architecture teams to identify security gaps, drive remediation activities, and promote a security‑first culture across the project. **Key Responsibilities** * Act as the primary application security point of contact for G3 HIS teams. * Collaborate with developers, architects, QA, and DevOps to integrate security into design, implementation, testing, and deployment. * Conduct security design reviews, threat modeling, and security‑focused code reviews for new and existing features. * Define and refine security requirements and controls for G3 HIS components and services. * Support the selection, configuration, and effective use of security tooling (e.g., SAST, DAST, SCA, secret scanning). * Analyze, prioritize, and track remediation of findings from security tools and external assessments. * Monitor security trends, emerging threats, and vulnerabilities relevant to the stack and domain, and translate them into concrete improvements. * Coordinate with central Security / InfoSec and Compliance teams to ensure alignment with corporate security policies and regulatory requirements. **Candidate Profile** **Background** * Former or current **Java developer** with a focus on **application security**. * Solid experience with enterprise Java applications (e.g., Spring ecosystem, REST APIs, relational databases). * Experience working on data‑sensitive or mission‑critical systems; healthcare domain experience is an advantage. **Required Skills (Technical & Soft)** * Strong understanding of application security principles and common vulnerabilities (e.g., OWASP Top 10). * Proven experience applying secure coding practices in Java and related frameworks. * Familiarity with security frameworks and stand
Applying for this Security Champion role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.