Senior InfoSec Engineer- Remote
Requisition ID
550192
Category
Research & Development
Location
United States - TX, Houston
Location: Remote
Medidata follows a hybrid office policy in which employees who are hired for an in-person position are expected to work on site a certain number of days per week following Company policy.
About our Company:
Medidata is powering smarter treatments and healthier people through digital solutions to support clinical trials. Celebrating over 25 years of ground-breaking technological innovation across more than 38,000 trials and 12 million patients, Medidata offers industry-leading expertise, analytics-powered insights, and one of the largest clinical trial data sets in the industry. More than 1 million registered users across approximately 2,300 customers trust Medidata's seamless, end-to-end platform to improve patient experiences, accelerate clinical breakthroughs, and bring therapies to market faster. A Dassault Systèmes brand (Euronext Paris: FR0014003TT8, DSY.PA), Medidata is headquartered in New York City and has been recognized as a Leader by Everest Group and IDC. Discover more at www.medidata.com. Listen to our latest podcast, from Dreamers to Disruptors, and follow us at @Medidata.
About the Team:
The Information Security Application Architecture team is responsible for designing, evaluating and enforcing application security in all phases of the Software Development Life Cycle (SDLC).
We work closely with our Engineering, Privacy and DevOps teams to define and implement the application security standards, perform software architecture design reviews, and threat modeling. We conduct white box security testing, and support the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms. This role will report to the Manager of Application Security & Sourcing department.
Responsibilities:
- Integrate secure SDLC practices into the development lifecycle, including conducting static and dynamic code analysis (SAST/DAST), managing open-source components, threat modeling, and performing architectural security reviews
- Manage and optimize source code control and source code management (SCM) systems to ensure secure, streamlined release pipelines
- Leverage fundamental knowledge of programming, application engineering, and common coding patterns to guide best-practice architecture and implementation
- Apply working knowledge of web-related technologies (Web Services, Service-Oriented and Object-Oriented Architectures) and network/web protocols (HTTP) to maintain robust system communication
- Support modern infrastructure deployment protocols by managing Infrastructure as Code (IaC) and executing Kubernetes Cluster Administration
- Leverage experience with HTML, JavaScript, and a deep understanding of the HTTP protocol to optimize frontend integrations and web security
- Utilize hands-on development experience across various coding languages—including .NET (C#), Java, Ruby, Python, JavaScript, TypeScript, AngularJS, and ReactJS—to review and improve codebase integrity
- Implement and maintain data solutions across both Relational Databases (e.g., MySQL, MS SQL, Oracle) and Non-Relational Databases (e.g., MongoDB, DynamoDB, Redis)
- Supporting and managing Secure AI workflows in both SDLC (ie. AI code generation, Copilot, ClaudeCode, etc) and in App Features (ie. customer facing functionality backed by AI)
- Apply a strong understanding of information security principles and web application vulnerabilities to proactively identify, mitigate, and defend against malicious code and common hacker techniques
- Collaborating with other functions in order to deploy and maintain solutions in an appropriate and cost-effective manner
Qualifications:
- Bachelor's degree (or above) in Computer Science/Engineering, Information Technology or comparable required 3-5 years of related experience
- AWS or Vendor Agnostic Cloud Management Certification is a plus
- CISSP or equivalent certification is a bonus
- Source Code & Artifact Management: Git, GitHub, Artifactory
- CI & CD Pipelines: GitHub Actions
- Scripting languages: Python, Typescript
- Programming languages: Java, .NET
- Hosting Architectures: Cloud & Self Hosted
- Security Exercises: SAST, DAST
As with all roles, Medidata sets ranges based on a number of factors including function, level, candidate expertise and experience, and geographic location. Pay ranges for candidates in locations other than New York City, may differ based on the local market data in that region.
The salary range for positions that will be physically based in the NYC Metro Area is $114,750-153,000.
The salary range for positions that will be physically based in all other locations within the United States is $102,750-137,000.
Base pay is one part of the Total Rewards that Medidata provides to compensate and recognize employees for their work. Most sales positions are eligible for a commission on the terms of applicable plan documents, and many of Medidata's non-sales positions are eligible for annual bonuses. Medidata believes that benefits should connect you to the support you need when it matters most and provides benefits, including medical, dental, life and disability insurance, 401(k) matching, family leave, flexible paid time off; and 10 paid holidays per year.
Note: Please be on the lookout for job scams. Medidata recruiters will never ask applicants for monetary compensation, credit card, or banking details.
Equal Employment Opportunity:In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Medidata are based on merit, qualifications and abilities. Medidata is committed to a policy of non-discrimination and equal opportunity for all employees and qualified applicants without regard to race, color, religion, gender, sex (including pregnancy, childbirth or medical or common conditions related to pregnancy or childbirth), sexual orientation, gender identity, gender expression, marital status, familial status, national origin, ancestry, age, disability, veteran status, military service, application for military service, genetic information, receipt of free medical care, or any other characteristic protected under applicable law. Medidata will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.
We will accept applications on an ongoing basis until we fill the position.
#LI-EM1
#LI-Hybrid