Security Engineer - Application Security & Identity
Job description
About the role
At Real Chemistry, making the world a healthier place is our everyday reality. Our drive to transform healthcare is informed by a blend of deep scientific expertise, human-centred creativity, and AI-driven insights, fostering a unique environment where innovation thrives and our people are impact-obsessed. As a global agency, we provide a full suite of services across healthcare communications and marketing to our clients, including top players in the pharmaceutical and biotech industries. Our #LifeatRealChem culture is rooted in our people - we believe we are best together and are committed to excellence for both our clients and colleagues. Whether you are a seasoned professional or just starting your career, if you share our passion for healthcare and connection, we invite you to explore our opportunities. Discover your purpose. Embrace innovation. Experience #LifeatRealChem.
This Security Engineer - Application Security & Identity role focuses on owning application security across multiple environments, each with increasing control and compliance requirements. You will act as reviewer for the least complex environments and co-reviewer for higher complexity and controlled environments. You will define and enforce security controls across AWS-hosted workloads and GitHub-based development pipelines while maintaining independent review authority. Applications often originate as AI-assisted prototypes and require structured security validation before enterprise production deployment. You will partner with DevOps Engineering to ensure security policies are implemented in pipelines and infrastructure, and you will maintain independent authority to approve or reject releases based on security findings.
What you'll do
- Conduct security reviews of internally developed applications, including data flow validation, security control design and implementation, secrets handling, and AI/LLM Data Loss Prevention (DLP).
- Co-lead production readiness reviews for strictly governed environments, covering threat modeling, hardening validation, and compliance mapping (SOC 2 and contractual and regulatory requirements).
- Define and enforce identity architecture for corporate identity using Entra ID and for workload identity using AWS IAM and GitHub OIDC.
- Define and manage GitHub native security controls, including GitHub Advanced Security (CodeQL / SAST), Dependabot (dependency scanning), secret scanning, and branch protection and environment controls.
- Establish standards for security tooling, such as SAST (CodeQL, Semgrep), SCA (Dependabot, Snyk), container scanning (Trivy, ECR scanning), and Infrastructure as Code policy (OPA, Sentinel, tfsec).
- Define AWS security standards covering IAM design and least-privilege access, logging and audit requirements, and secrets management and rotation.
- Scope and coordinate third-party penetration testing engagements.
- Maintain audit logging maturity per environment requirements, including baseline logging, user-level activity tracking, and tamper-evident audit trails with SIEM integration.
- Perform initial triage and risk classification within time requirements for critical issues identified in intake, such as data exposure, credentials, and regulatory risk.
- Partner with DevOps Engineering to ensure security policies are implemented in pipelines and infrastructure.
- Define approved AI providers and usage boundaries, establish prompt data classification and handling policies, enforce human-in-the-loop requirements where appropriate, and define cost/spend guardrails for AI services.
- Contribute to continuous improvement of security processes, evidence collection, and compliance reporting across cloud and identity domains.
Requirements
- 5+ years (or 3-5+ in high-growth environments) in cloud security, 2 of which should be focused application security.
- Hands-on security experience with AWS IAM, SAML / OIDC federation, and GitHub security tooling.
- Experience with threat modeling and coordinating penetration testing.
- Familiarity with SOC 2, GDPR, and HIPAA-adjacent controls.
- In-depth understanding of the risk lifecycle.
Nice to have
- Experience securing GitHub-based CI/CD pipelines.
- Experience in AWS native environments.
- Exposure to regulated industries (GxP, 21 CFR Part 11).
- Security certifications (CISSP, CCSP, OSCP, GIAC, etc.).
- Associates degree or higher.
- Experience bringing low-code or AI-generated applications under enterprise security controls.
Practical notes
This is a hybrid role, based in any of our US offices - including New York City, Boston, Chicago, Carmel, or San Francisco - or remotely within the US, depending on team and business needs.