Application Security Engineer
Inovalon
| Company | Inovalon |
| Category | Engineering |
| Location | Hyderabad |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 9 Jun 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Inovalon was founded in 1998 on the belief that technology, and data specifically, would empower the transformation of the entire healthcare ecosystem for the better, improving both outcomes and economics. At Inovalon, we believe that when our customers are successful in their missions, healthcare improves. Therefore, we focus on empowering them with data-driven solutions. And the momentum is building.
Together, as ONE Inovalon, we are a united force delivering solutions that address healthcare’s greatest needs. Through our mission-based culture of inclusion and innovation, our organization brings value not just to our customers, but to the millions of patients and members they serve.
Role Overview
We are seeking a Staff Software Engineer with a strong focus on application security to serve as a technical leader responsible for embedding security across the design, development, and operation of our cloud‑native SaaS platforms. This role plays a critical part in establishing secure coding standards, and ensuring that security risks, requirements, and controls are effectively implemented, tested, and validated throughout the product lifecycle.
The ideal candidate has hands‑on experience securing SaaS applications operating under HIPAA and PCI compliance requirements, and acts as a trusted partner to Engineering, Architecture, Quality Engineering, DevSecOps, and Compliance teams. This is not a policy‑only or audit‑only role—the Staff Engineer is expected to lead through technical depth, influence, and hands‑on contribution.
Key Responsibilities
Secure Software Engineering & Technical Leadership
Act as a security engineering subject matter expert across multiple teams or services.
Establish, document, and evolve secure coding standards, patterns, and best practices for SaaS applications.
Lead and participate in secure design and code reviews , identifying security flaws, architectural risks, and improper patterns early.
Collaborate with engineers to remediate vulnerabilities in a maintainable and scalable manner.
Ensure security considerations are balanced with performance, reliability, and developer productivity.
Risk & Architecture Security
Identify assets, trust boundaries, attack surfaces, and data flows—including PHI and payment data.
Define, track, and manage security risks, mitigations, and accepted residual risks as engineering artifacts.
Security Requirements & Controls
Translate threats and regulatory obligations into clear, actionable, testable security requirements .
Ensure security requirements are incorporated into:
Architecture decisions
Product backlogs
Acceptance criteria and definitions of done
Define and validate security controls for:
Authentication and authorization
Encryption and key management
Secure session management
Protection of PHI and cardholder data
SaaS, Compliance & Regulated Environments
Provide security engineering leadership for SaaS applications subject to HIPAA and PCI DSS requirements.
Partner with Compliance, Risk, and Audit teams to ensure engineering designs and implementations support regulatory obligations without excessive friction.
Ensure compliance requirements are addressed through engineering controls and testable validation , not manual processes alone.
Testing, Validation & Secure SDLC
Partner with Quality Engineering and DevSecOps to validate security controls using:
Secure code analysis
Threat‑driven test scenarios
Security regression testing
Verify that mitigations identified through threat modeling are correctly implemented and effective prior to release.
Support penetration testing, security assessments, and remediation efforts, ensuring findings are resolved sustainably.
Collaboration & Influence
Influence security posture across teams through technical leadership , not enforcement.
986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →