This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Labcorp
Posted 2mo ago

Cybersecurity Engineer – Application Security Enablement

Labcorp
Durham or Burlington or United States
$160k-$170k/yrHybridFull Time
Responsibilities
  • defining standards
  • enabling design
  • advising developers
Requirements
  • 8+ years application security experience
  • Strong secure design
  • Secure coding, OWASP
  • Cloud (AWS/Azure)
  • IAM (OAuth 2.0/OIDC/SAML)
  • Consultative collaboration
  • Threat remediation, and application security tooling (SAST/DAST/SCA)
Technical tools mentioned
OWASPNISTCIS ControlsISO 27001OAuth 2.0OIDCSAMLOktaMicrosoft Entra IDSailPointAWSAzureSASTDASTSCADevSecOpsCI/CD

Job description


Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives.


Labcorp is seeking a Cybersecurity Engineer – Application Security Enablement to join our team in a remote capacity. 

Location: Remote 

Applicants who live within 35 miles of either the Burlington, NC or Durham, NC location will follow a hybrid schedule. This schedule includes a minimum of three in-office days per week at an assigned location, either Burlington or Durham, supporting both collaboration and flexibility.  

 

Work Schedule: This is a fulltime, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in your local time zone. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible. 

Work Authorization: This position requires permanent authorization to work in the United States without employer sponsorship now or in the future. Sponsorship (including H-1B, OPT/CPT, EAD, or other temporary work authorization) is not available.

 

Job Responsibilities 

Application Security Design Standards & Patterns 

  • Define and document secure development standards and patterns for modern application architectures (web, API, microservices), with guidance grounded in industry best practices such as OWASP and informed by broader frameworks (i.e. NIST, CIS Controls). 

  • Develop reusable patterns for common application scenarios such as secure APIs, service-to-service communication and front-end/back-end architecture. 

  • Translate complex security risks into clear, developer-focused guidance that can be easily adopted. 

  • Contribute to the creation of machine-consumable security patterns to support AI-enabled and automated development tools. 

 

Secure Design Enablement 

  • Collaborate with engineers and architects during design discussions to provide guidance on secure application architecture and design decisions. 

  • Identify common security pitfalls early in the lifecycle. 

  • Provide guidance on secure integration and data protection patterns. For example: 
    - Input validation and output encoding 
    - API security and authentication flows 
    - Session management and token handling 
    - Secrets management and secure configuration 

  • Promote secure-by-design and secure-by-default principles to enable efficient and secure development practices. 

 

Identity & Access Management (Supporting Role) 

  • Support the integration of authentication and authorization patterns within application architecture. 

  • Ensure secure implementation of protocols such as OAuth 2.0, OIDC, and SAML. 

  • Align application security practices with identity and access management, identity governance, and privileged access management solutions. 

Cross-Functional Collaboration 

  • Partner with Digital Identity Services, Cybersecurity Engineering, Product Security Testing, and other teams to provide application security guidance and support risk mitigation. 

  • Collaborate with the Governance, Risk, and Compliance team to align application security practices with enterprise policies and regulatory requirements. 

  • Work with Cybersecurity Operations to enhance detection and response capabilities for application-level threats. 

  • Engage with Enterprise Architecture teams to influence secure design decisions. 

  • Support data protection initiatives by ensuring appropriate controls for sensitive data handling and exposure mitigation are utilized. 

 

Risk Advisory 

  • Review vulnerability patterns and provide guidance on prioritization and remediation of application security risks. 

  • Serve as a trusted advisor to engineering and architecture teams, offering practical and actionable security recommendations. 

  • Support standardization of application security risk management practices across teams. 

 

Continuous Improvement and Innovation 

  • Stay current with emerging threats, vulnerabilities, and trends in application security. 

  • Evaluate and evolve security standards to support cloud native, API first, distributed, and AI enabled applications. 

  • Contribute to the development of scalable, consistent application security enablement practices across the organization. 

 

Minimum Qualifications 

  • High school diploma with 12 or more years of experience in application security, secure software development, or cybersecurity engineering; or Associate degree with 10 or more years of experience; or Bachelor’s degree in Computer Science, Information Security, or Engineering with 8 or more years of experience; or Master’s degree in Computer Science, Information Security, or Engineering with 6 or more years of experience.

  • 8 or more years of experience in application security, secure software development, or cybersecurity engineering, with a focus on identifying and addressing application-layer risks. 

  • 5 or more years of experience applying secure coding principles and addressing application security risks using OWASP Top 10 or similar best practices, with the ability to translate risks into actionable developer guidance. 

  • 3 or more years of experience working with enterprise security frameworks such as NIST CSF, CIS Controls, or ISO 27001, with demonstrated ability to align application security practices to these or other applicable frameworks. 

  • 3 or more years of experience in application or software development, OR equivalent experience working closely with development teams, with demonstrated ability to engage developers credibly on secure coding practices, design, and remediation strategies. 

  • 5 or more years of experience designing or securing web applications, APIs, and microservices architectures, including providing guidance on secure design decisions. 

  • 5 or more years of experience identifying, analyzing, and guiding remediation of common vulnerabilities such as injection, XSS, CSRF, broken authentication, and insecure deserialization. 

  • 3 or more years of experience applying secure design patterns in real-world systems, with the ability to guide teams on secure-by-design and secure-by-default principles. 

  • 2 or more years of experience securing cloud-native applications and APIs in AWS or Azure, including advising on secure architecture and integration patterns. 

  • 2 or more years of experience working with authentication and authorization protocols such as OAuth 2.0, OIDC, and SAML, including advising on appropriate implementation within application architectures. 

  • 3 or more years of experience operating in a consultative, cross-functional role, providing actionable security guidance to engineering and architecture teams and influencing secure design decisions. 

 

Preferred Qualifications 

  • 3 or more years of experience defining or contributing to secure development standards, guidelines, or reference architectures. 

  • 3 or more years of experience integrating security into the software development lifecycle (SDLC), including DevSecOps practices and collaboration with CI/CD pipelines and development workflows. 

  • 3 or more years of experience working with API security frameworks, standards, or tooling, with the ability to guide teams on securing modern API-driven architectures. 

  • 2 or more years of experience applying threat modeling methodologies to identify design-level risks and guide mitigation strategies with engineering and architecture teams. 

  • 2 or more years of experience working with application security testing tools (SAST, DAST, SCA), including interpreting findings and helping development teams prioritize and remediate vulnerabilities effectively. 

  • 1 or more years of experience enabling the secure design of AI-enabled applications, focusing on security controls and best practices, including emerging risks and secure design patterns, with the ability to guide engineering teams on secure adoption practices. 

 

Additional Job Standards 

  • Experience supporting security testing or assessment teams. 

  • Familiarity with identity and access management platforms such as Okta, Microsoft Entra ID, or SailPoint. 

  • Broad familiarity with cloud platform security capabilities and their integration into enterprise environments. 

  • Relevant certifications such as CSSLP, GWAPT, or CISSP. 

  • Strong analytical and problemsolving skills with a pragmatic approach to security solutions. 

  • Developerfocused mindset with an understanding of modern application development practices. 

  • Ability to simplify complex technical concepts for diverse audiences. 

  • Strong collaboration skills across engineering, security, and architecture teams. 

  • Proven ability to deliver practical, scalable, and reusable solutions. 

  • High level of professionalism, adaptability, and continuous learning mindset. 

  • Strong communication skills with the ability to translate complex security concepts into practical guidance. 

 

About the Role 

The Cybersecurity Engineer – Application Security Enablement plays a critical role in strengthening Labcorp’s application security posture by enabling secure design and development practices across engineering teams. This position combines deep technical expertise with a consultative approach to guide teams in building secure, scalable applications. The role supports enterprise security strategy by embedding security standards, improving risk management practices, and advancing secure development capabilities, including the adoption of emerging technologies such as AIenabled applications. 

 

Application Window: 8/15/2026  

Pay Range: $160-170k 

All job offers will be based on a candidate’s skills and prior relevant experience, applicable degrees/certifications, as well as internal equity and market data.  

 

Benefits: Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan.Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan.Employees who are regularly scheduled to work a 7 on/7 off schedule are eligible to receive all the foregoing benefits except PTO or FTO. For more detailed information, pleaseclick here. 


Labcorp is proud to be an Equal Opportunity Employer:

Labcorp strives for inclusion and belonging in the workforce and does not tolerate harassment or discrimination of any kind. We make employment decisions based on the needs of our business and the qualifications and merit of the individual. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), family or parental status, marital, civil union or domestic partnership status, sexual orientation, gender identity, gender expression, personal appearance, age, veteran status, disability, genetic information, or any other legally protected characteristic. Additionally, all qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law. 


We encourage all to apply

If you are an individual with a disability who needs assistance using our online tools to search and apply for jobs, or needs an accommodation, please visit our accessibility site or contact us at Labcorp Accessibility. For more information about how we collect and store your personal data, please see our Privacy Statement.


About Labcorp

Provides clinical laboratory testing and drug development services globally.

Similar jobs

Cybersecurity Engineer roles near Durham, North Carolina
5d
Save
Mark Applied
Hide
Senior Cybersecurity Engineer
Cary, North Carolina, United States
$115k-$135k/yr HybridFull Time
American Tower
American TowerNYSE: AMT: Leases space on wireless and broadcast towers for communications.
5+ YOEBachelor's degree or equivalent experience and 5+ years in security engineering, SecOps, data loss protection, monitoring, and risk-based alerting; cybersecurity tools, scripting, communication, and collaboration skills required.
Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, Sentinel, Ansible, Python, PowerShell, SIEM
3mo
Save
Mark Applied
Hide
Senior Staff Cybersecurity Engineer - Identity Security
Morrisville or Hillsboro or Canonsburg
$161k-$242k/yr OnsiteFull Time
Synopsys
SynopsysNasdaq: SNPS: Provides software and IP for semiconductor design and manufacturing.
5+ YOEBachelor's degree, 5+ years in cybersecurity with 2+ years in a senior role; deep HashiCorp Vault and secrets management experience; cloud (AWS/Azure/GCP), Kubernetes, Python/PowerShell/Bash, IAM concepts, and strong communication skills.
HashiCorp Vault, AWS, Azure, GCP, Kubernetes, Python, PowerShell, Bash
1mo
Save
Mark Applied
Hide
Cybersecurity Assessment Engineer
Washington or Maryland or Virginia or Raleigh or Durham or Chapel Hill or Denver or Colorado Springs or Dallas or Fort Worth
$125k-$140k/yr RemoteFull Time
Second Front Systems
Second Front Systems: Secure cloud hosting and automated compliance for government software.
3+ YOE3+ years cybersecurity experience; hands-on cloud and DevSecOps knowledge; familiarity with NIST RMF/SP 800-53, FedRAMP, vulnerability analysis, and authorization artifacts; ability to attain DoD 8570 IAT II (CYSA+ preferred).
Anchore, Trivy, Tenable, Docker, GitLab, Kubernetes, Python, Bash, AWS, Azure, GCP
4mo
Save
Mark Applied
Hide
Operational Technology (OT) Cybersecurity Engineer
New York or Newark or Boston or Baltimore or Raleigh or Miami or Charleston
$102k-$185k/yr HybridFull Time
WSP
WSPToronto Stock Exchange: WSP: Provides engineering, design, and environmental consultancy services globally.
7+ YOEBachelor’s degree in engineering or cybersecurity; 7-10+ years OT cybersecurity; transit/rail/critical infrastructure experience; IEC/NIST/ISO/ST standards knowledge; certifications CISSP/GICSP/ISA/IEC; strong client-facing and writing skills.
Nozomi, Claroty, Dragos, protocol analysis tools
1mo
Save
Mark Applied
Hide
Cybersecurity Forward Deployed Engineer - FDE Senior Manager
Atlanta or Milwaukee or Herndon or Dallas or Columbus or Kirkland or Irvine or Cincinnati or New York or Cleveland or Oklahoma City or Austin or Albany or Chicago or Arlington or St. Petersburg or Hartford or Pittsburgh or St. Louis or Miami or Sacramento or Raleigh or Minneapolis or Scottsdale or Mountain View or Morristown or San Francisco or Denver or Boston or Philadelphia or Des Moines or Overland Park or Los Angeles or Charlotte or Walnut Creek or Carmel or Seattle or Houston or Redmond or Bentonville or Beaverton or Nashville or Detroit or San Diego
$113k-$366k/yr FieldFull Time
Accenture
AccentureNYSE: ACN: Global provider of management consulting and technology services.
10+ YOE10+ years engineering experience with production cybersecurity depth, 2+ years hands-on agentic AI production experience, 8+ years end-to-end security delivery, 8+ years cloud security experience (AWS/Azure/GCP), Bachelor's or equivalent, people leadership experience.
Claude Code, Cursor, GitHub Copilot, AWS, Azure, GCP, OWASP LLM Top 10, NIST AI RMF, EU AI Act, MLOps, RAG
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Systems Software Engineer
Colorado Springs or Durham or Spring or Fort Collins or Andover
$162k-$371k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Provides global edge-to-cloud technology solutions and IT infrastructure services.
10+ YOEBachelor's or Master's in CS/Engineering/IS, 10+ years cybersecurity engineering/architecture and software development experience, strong knowledge of cybersecurity standards and technologies, ability to design solutions, lead certification/compliance, and mentor teams.
NIST SP 800-53, DISA SRG/STIG, Common Criteria, PQC, EU CRA, 802.1ar, Agentic AI, FIPS, TLS, SSH, Cryptography
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Systems Software Engineer
Colorado Springs or Durham or Spring or Fort Collins or Andover
$162k-$371k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Providing global edge-to-cloud infrastructure and IT solutions for businesses.
10+ YOEBachelor's or Master's in CS/Engineering/Information Systems; 10+ years in cybersecurity engineering, architecture, and software development; expertise in cybersecurity standards, solutions, and compliance; strong communication and leadership skills.
NIST SP 800-53, DISA SRG/STIG, Common Criteria, Post-Quantum Cryptography (PQC), EU Cyber Resilience Act (EU CRA), 802.1 ar Device Identities, cybersecurity Agentic AI, FIPS, TLS/SSH, Cryptography
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Systems Software Engineer
Colorado Springs or Durham or Spring or Fort Collins or Andover
$170k-$323k/yr HybridFull Time
Hewlett Packard Enterprise
Hewlett Packard EnterpriseNYSE: HPE: Provides edge-to-cloud IT infrastructure and platform services.
10+ YOEBachelor’s degree in CS/Engineering/Info Systems, 10+ years cybersecurity engineering and software development, experience with security architectures, standards and certifications, strong communication and executive influence skills.
Post-Quantum Cryptography (PQC), EU Cyber Resilience Act (EU CRA), 802.1AR Device Identities, NIST SP 800-53, DISA SRG/STIG, Common Criteria, Agentic AI, FIPS, TLS, SSH, Cryptography
This job has expired