Henry Ford Health partners with millions of people on their health journey, across Michigan and around the world. We offer a full continuum of services from primary and preventative care to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care and other health care retail. With former Ascension southeast Michigan and Flint region locations now part of our team, Henry Ford's care is available in 13 hospitals and hundreds of ambulatory care locations. Based in Detroit, Henry Ford is one of the nation's most respected academic medical centers and is leading the Future of Health: Detroit, a $3 billion investment anchored by a reimagined Henry Ford academic healthcare campus.
Job DescriptionApplication Security Engineer - Henry Ford Health
Job Title
Application Security Engineer
About the Department
Join the Application Security Services team at One Ford Place, our corporate headquarters in Detroit¿s New Center. Located steps from Amtrak, the QLINE, and the Fisher Buildings, this vibrant area blends downtown energy with accessibility. Our team is part of the Information Privacy and Security Office, collaborating closely with application developers to ensure robust security throughout the software development lifecycle. We¿re dedicated to safeguarding patient data and systems while fostering innovation in a walkable, artsy neighborhood with a dedicated focus on behavioral health.
Role Overview
As an Application Security Engineer, you¿ll play a critical role in embedding security into our software delivery pipeline. You¿ll build automated guardrails, integrate security tools into CI/CD pipelines, and collaborate with engineering teams to identify and remediate vulnerabilities before they reach production. Your work ensures our applications are secure, compliant, and reliable, supporting both our developers and the patients we serve.
Why Henry Ford Health
At Henry Ford Health, we are relentless advocates for exceptional care for our patients, communities, and each other. We come to do meaningful work and grow our careers, and we stay for the connection, support, and shared pride in making the impossible, possible.
What You Will Do
- Integrate and tune SAST, SCA, secrets scanning, and container scanning tools into CI/CD pipelines to identify vulnerabilities early.
- Own the CI/CD security tooling layer end-to-end, including tool selection, integration, and remediation workflows.
- Collaborate with engineering teams to drive vulnerability remediation without blocking development progress.
- Reduce false positives by writing custom rules and improving tool configurations.
- Ensure compliance with software development lifecycle policies, standards, and controls.
What You Will Need
Required Qualifications
- Bachelor¿s Degree in computer science or programming.
- 3+ years in DevOps, application security engineering, or platform/infrastructure engineering with a security focus.
- Hands-on experience integrating SAST tools (e.g., Semgrep, Snyk, SonarQube) into CI/CD pipelines.
- Strong working knowledge of CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins).
- Proficiency in scripting/tooling languages (e.g., Python, Go, JavaScript/TypeScript, Bash).
- Understanding of OWASP Top 10 and CWE Top 25 vulnerability classes.
- Experience with SCA/dependency scanning tools (e.g., Snyk, Dependabot).
- Familiarity with containerization and container security scanning (e.g., Docker, Trivy).
- Cloud platform experience (e.g., AWS, Azure, GCP) and cloud-native security tooling.
- Secrets management experience (e.g., HashiCorp Vault, AWS Secrets Manager).
Preferred Qualifications
- Prior experience as a software engineer.
- Experience with cloud-native security tooling.
What We Offer
Join a team where you¿ll drive innovation, collaborate with passionate professionals, and contribute to mission-driven work. Grow your career through hands-on experience, learning opportunities, and the chance to make a meaningful impact in healthcare technology.
Join Our Team
Ready to secure the future of healthcare technology? Apply now and be part of our mission at Henry Ford Health.
Skills Required
- Bachelor's degree in computer science or programming
- 3+ years of experience in DevOps, application security engineering, or platform/infrastructure engineering with a security focus
- Hands-on experience integrating SAST tools such as Semgrep, Snyk, or SonarQube into CI/CD pipelines
- Strong working knowledge of CI/CD platforms such as GitHub Actions, GitLab CI, or Jenkins
- Proficiency in Python, Go, JavaScript/TypeScript, or Bash
- Understanding of OWASP Top 10 and CWE Top 25 vulnerability classes
- Experience with SCA and dependency scanning tools such as Snyk or Dependabot
- Familiarity with Docker and container security scanning tools such as Trivy
- Cloud platform experience with AWS, Azure, or GCP and cloud-native security tooling
- Experience with secrets management tools such as HashiCorp Vault or AWS Secrets Manager
- Prior experience as a software engineer
- Experience with cloud-native security tooling
What We Do
Henry Ford Health is a Detroit-headquartered academic healthcare system serving more than 2 million people across Michigan and beyond. Its integrated offerings include primary, preventive, urgent, specialty, home, and virtual care, health insurance, pharmacy, and eye care. The organization also advances clinical innovation, research, clinical trials, medical education, community health, health equity, and services for vulnerable communities throughout the region.








