998,188open jobs
59,534companies
165,604added this week
Browse all
Salary
$132k – $202k per year
Location
Hybrid (New York, United States)
Seniority
Senior · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 30, 2026. HSS scores B on the Alion truth index.

Overview
Company
Impact
Profile match

HSS

HSS is the #1 hospital in the U.S. for orthopedics, ranked #3 in the U.S. for rheumatology, and is the best pediatric orthopedic hospital in NY, CT and NJ. HSS has locations in NY, NJ, CT, and FL.

How you move is why we’re here. ®

Now more than ever.

Get back to what you need and love to do.

The possibilities are endless...

Now more than ever, our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximizethe abundant opportunities for growth and success.

If this describes you then let’s talk!

HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report. As a recipient of the Magnet Award for Nursing Excellence, HSS was the first hospital in New York City to receive the distinguished designation. Whether you are early in your career or an expert in your field, you will find HSS an innovative, supportive and inclusive environment.

Working with colleagues who love what they do and are deeply committed to our Mission, you too can be part of our transformation across the enterprise.

Emp Status

Regular Full time

Work Shift

Compensation Range

The base pay scale for this position is $132,000.00 - $201,500.00. In addition, this position will be eligible for additional benefits consistent with the role. The salary of the finalist selected for this role will be determined based on various factors, including but not limited to: scope of role, level of experience, education, accomplishments, internal equity, budget, and subject to Fair Market Value evaluation. The hiring range listed is a good faith determination of potential compensation at the time of this job advertisement and may be modified in the future.

What you will be doing

Position Activities

  • Partner with application development, data and analytics, infrastructure, cloud, architecture, and cybersecurity teams to embed secure-by-design principles into applications, services, pipelines, platforms, and infrastructure.
  • Design, implement, and maintain security controls within CI/CD pipelines, including automated testing, security gates, build and deployment checks, and risk-based exception workflows.
  • Manage and support application security capabilities such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), secrets detection, dependency review, and code security scanning using tools such as Snyk, Wiz, and GitHub.
  • Review application designs, architecture patterns, data flows, APIs, cloud workloads, and integration points to identify security risks and recommend practical remediation or compensating controls.
  • Support threat modeling, secure code review, and security design reviews throughout the software development lifecycle.
  • Validate, prioritize, and track remediation of application, cloud, container, infrastructure, and development environment vulnerabilities using platforms such as Snyk, Wiz, Sysdig, Tenable, GitHub, and related tools.
  • Review cloud resources, Infrastructure as Code templates, container images, and deployment configurations against organizational policies, secure configuration baselines, and industry best practices.
  • Develop scripts, integrations, dashboards, and automated workflows that improve security testing, vulnerability management, reporting, evidence collection, and developer self-service.
  • Create metrics, reports, diagrams, runbooks, standards, and technical documentation that communicate application security posture, pipeline security effectiveness, vulnerability trends, and remediation status to technical and non-technical audiences.
  • Support audits, assessments, compliance activities, and control validation requests related to application security, cloud security, software supply chain security, and secure development practices.
  • Perform other related duties as assigned.

Minimum Qualifications

  • Bachelor’s degree in computer science, information technology, cybersecurity, software engineering, data engineering, or a related field, or equivalent experience.
  • Seven or more years of professional IT experience with five or more years in DevSecOps, application security, cloud security, software engineering, infrastructure engineering, security engineering, or a related technical role.
  • Working knowledge of secure software development lifecycle practices, application security principles, cloud security concepts, CI/CD security, and vulnerability management.
  • Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or similar tools.
  • Experience with cloud platforms such as Microsoft Azure, AWS, or similar environments.
  • Familiarity with application security and software supply chain security capabilities such as SAST, SCA, secrets scanning, dependency analysis, container scanning, and Infrastructure as Code scanning.
  • Experience with scripting, automation, source control, code review processes, and development workflows using tools and languages such as Git, Python, PowerShell, Bash, JavaScript, or similar.
  • Ability to assess technical environments, identify security gaps, evaluate risk, and recommend practical remediation activities.
  • Strong written and verbal communication skills, including the ability to explain technical security concepts to developers, engineers, security teams, and non-technical stakeholders.
  • Excellent analytical, problem-solving, troubleshooting, organizational, and prioritization skills.

Preferred Experience

  • Experience with tools such as Snyk, Wiz, Sysdig, Tenable, GitHub Advanced Security, GitHub Dependabot, or similar security platforms.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, CloudFormation, Bicep, Open Policy Agent, YAML, JSON, or similar.
  • Experience securing containers, Kubernetes, container registries, cloud-native workloads, APIs, secrets, and microservices architectures.
  • Experience building security automation, integrations, dashboards, reporting, and developer self-service capabilities.
  • Experience working with data and analytics platforms, data pipelines, APIs, reporting platforms, or related engineering teams.
  • Experience supporting audit readiness, compliance activities, control testing, or automated evidence collection in a regulated environment.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, OWASP Top 10, MITRE ATT&CK, HIPAA, HITRUST, ISO 27001, SOC 2, or similar.
  • Security, cloud, or software security certifications such as Security+, CSSLP, GWEB, GCSA, AWS Security Specialty, Azure Security Engineer, CCSP, CISSP, or similar.
  • Experience in healthcare or another highly regulated environment.

Skills and Abilities

  • Ability to connect security requirements to practical software development, cloud deployment, and engineering outcomes.
  • Ability to automate, standardize, and improve repeatable application security, cloud security, and DevSecOps processes.
  • Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
  • Ability to collaborate effectively with application development, data and analytics, infrastructure, cloud, architecture, cybersecurity, compliance, and business stakeholders.
  • Ability to produce professional-level documentation, reports, diagrams, runbooks, standards, and technical guidance.
  • Ability to think critically, make independent decisions, and recommend practical solutions.
  • Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
  • Ability to communicate application security risks, control gaps, remediation needs, and technical recommendations clearly to both technical and non-technical audiences.
  • Ability to support a positive cybersecurity culture by promoting secure development practices, accountability, and continuous improvement.

Non-Discrimination Policy

Hospital for Special Surgery is committed to providing high quality care and skilled, compassionate, reliable service to our community in a safe and healing environment. Consistent with this commitment, Hospital for Special Surgery provides care, admits, and treats patients and provides all services without regard to age, race, color, creed, ethnicity, religion, national origin, culture, language, physical or mental disability, socioeconomic status, veteran or military status, marital status, sex, sexual orientation, gender identity or expression, or any other basis prohibited by federal, state, or local law or by accreditation standards.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
998,188 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
≈ $70k – $145k per year (Estimated) • In office • Full-Time • 3+ years exp • Associate's Degree • Greensboro
Management
Microsoft Office
Apply
≈ $105k – $207k per year (Estimated) • In office • 6+ years exp • Atlanta
DevOps
Azure
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
DLP
Apply
≈ $108k – $212k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Atlanta
DevOps
GCP
Azure
AWS
Cybersecurity
Zero Trust
Apply
$200k – $290k per year • Remote (United States) • Full-Time
DevOps
AWS
IAM
Cybersecurity
NIST 800-171
Apply
DevSecOps Engineer 1 day ago
≈ $117k – $229k per year (Estimated) • In office • TS/SCI • 5+ years exp • San Diego
Python
PowerShell
DevOps
Terraform
Ansible
Helm
Azure DevOps
Loki
CloudFormation
K3s
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Platform Engineering
Bicep
Cybersecurity
SonarQube
NIST 800-171
Zero Trust
SBOM
Apply
$110k – $170k per year • Hybrid • Herndon
JavaScript
SQL
C#
C#
ASP.NET Core
Databases
PostgreSQL
Frontend
React.js
DevOps
Rest API
Azure DevOps
Azure
Git
AWS
Apply
AI Full Stack Intern 2 hours ago
In office • Internship • Bachelor's Degree • Hyderabad
Python
JavaScript
TypeScript
SQL
Node JS
AI/ML
LangChain
LLM
OpenAI
Agentic Workflows
Tool Use
Machine Learning
Frontend
React.js
DevOps
Git
Apply
In office • Astana
JavaScript
TypeScript
Frontend
Angular
npm
DevOps
Linux
TCP/IP
Apply
Flutter Developer 2 hours ago
In office • 3+ years exp • Minsk
Kotlin
Dart
Kotlin
Mockito
Dart
Riverpod
Dio
Drift
Isar
Mocktail
Databases
SQLite
AI/ML
Machine Learning
Frontend
GraphQL
Mobile
Flutter
Clean Architecture
Fastlane
State Management
Bitrise
Codemagic
DevOps
Rest API
gRPC
GitHub Actions
WebSockets
CI/CD
Git
Gitflow
Management
ClickUp
Notion
Jira
Agile
Scrum
Apply
Data Engineer 2 hours ago
≈ $25k – $61k per year (Estimated) • In office • Moscow
Python
Java
SQL
Databases
HBase
AI/ML
Hadoop
Spark
DevOps
Git
Linux
Analytics
ETL/ELT
Management
Jira
Apply
$132k – $202k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • New York
DevOps
Incident Management
Management
ITIL
Apply
$132k – $202k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • New York
Java
C#
C#
.NET
Apply
≈ $36k – $82k per year (Estimated) • In office • Full-Time • High School Diploma • New York
Apply
≈ $34k – $82k per year (Estimated) • In office • Full-Time • High School Diploma • New York
Apply
≈ $36k – $82k per year (Estimated) • In office • Full-Time • High School Diploma • New York
Apply
$140k – $155k per year • Hybrid • Full-Time • 5+ years exp • New York • Princeton • London
Python
SQL
YARA
AI/ML
AI Agents
Pandas
Edge AI
DevOps
Rest API
Splunk
Terraform
Azure DevOps
Podman
CloudFormation
containerd
Pulumi
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Bitbucket
GitLab
Cybersecurity
Okta
Crowdstrike
YARA
SentinelOne
Microsoft Defender
MISP
Google SecOps
Cortex XSOAR
Anomali
ThreatConnect
Microsoft Entra ID
SIEM
Apply
≈ $44k – $75k per year (Estimated) • Remote (United States) • Full-Time • High School Diploma • New York
Apply
≈ $109k – $210k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp • Bachelor's Degree • Louisville • Charlotte • Tampa • Fort Lauderdale • Washington
Cybersecurity
HIPAA
Apply
$36k – $38k per year • In office • New York
Apply
$36k – $38k per year • In office • New York
Apply
See all jobs
This is one of many
998,188 more open roles from verified company boards, updated every day.