Blue Cross and Blue Shield Association logo

Information Security Engineer, Principal

    Highlights

    In this role you will design, build, and operate security as code across application, data, cloud, and infrastructure environments, ensuring secure-by-default outcomes through automation and developer-native platforms. We are looking for leaders that are energized by creative and critical thinking, building and sustaining high-performing teams, getting results the right way, and fostering continuous learning.

    Numbers & Facts

    LocationKansas City, MO
    IndustryInsurance
    Company Size2,000 to 2,499 employees
    Websitehttps://www.bcbs.com/about-us/careers

    Description

    Your Role

    The Product Security team builds and operates engineering-driven security capabilities embedded directly into the software and platform lifecycle. The Product Security Engineer will report to the Senior Director, Product Security. In this role you will design, build, and operate security as code across application, data, cloud, and infrastructure environments, ensuring secure-by-default outcomes through automation and developer-native platforms. You will play a key role in securing AI-enabled systems and leveraging AI to scale security engineering, detection, and response capabilities.

    Our leadership model is about developing great leaders at all levels and creating opportunities for our people to grow - personally, professionally, and financially. We are looking for leaders that are energized by creative and critical thinking, building and sustaining high-performing teams, getting results the right way, and fostering continuous learning.

    Your Knowledge and Experience

    • Requires college degree or equivalent experience
    • Requires a minimum of at least 10 years of relevant experience
    • 8+ years in DevSecOps, Security Engineering, or Software Engineering preferred
    • Strong experience building security capabilities into CI/CD pipelines
    • Hands-on experience with Infrastructure-as-Code tools such as Terraform
    • Proficiency in Python, Go, or TypeScript
    • Deep understanding of application security, cloud security, and distributed systems
    • Experience securing Kubernetes or cloud-native environments
    • Strong understanding of IAM, encryption, and network security principles
    • Experience with policy-as-code tools such as OPA or Kyverno
    • Experience with AI/ML systems or applying AI to security problems preferred
    • Experience in regulated environments such as healthcare preferred

    #LI-FB1

    Your Work

    In this role, you will:

    • Design and operate security controls embedded in CI/CD pipelines using policy-as-code and automation-first approaches
    • Build and maintain developer-native security platforms covering SAST, SCA, API validation, and IaC security
    • Implement data protection controls to detect and prevent exposure of sensitive data including PHI, PII, and secrets
    • Develop secure application and API patterns including authentication, authorization, and encryption standards
    • Engineer reusable libraries for encryption, tokenization, and data redaction
    • Define and enforce cloud and infrastructure security using Infrastructure-as-Code and GitOps workflows
    • Build identity, access, encryption, and network guardrails using automated controls
    • Implement software supply chain security including SBOM generation, artifact signing, and provenance validation
    • Develop detection-as-code and automated response capabilities to reduce reliance on manual security operations
    • Design and enforce controls to secure AI systems and prevent misuse, data leakage, and model risk
    • Leverage AI to improve detection, analysis, and automation across security operations
    • Translate regulatory requirements into enforceable technical controls and automated evidence generation
    • Eliminate manual security processes in favor of scalable engineering-driven solutions

    Your Work

    In this role, you will:

    • Design and operate security controls embedded in CI/CD pipelines using policy-as-code and automation-first approaches
    • Build and maintain developer-native security platforms covering SAST, SCA, API validation, and IaC security
    • Implement data protection controls to detect and prevent exposure of sensitive data including PHI, PII, and secrets
    • Develop secure application and API patterns including authentication, authorization, and encryption standards
    • Engineer reusable libraries for encryption, tokenization, and data redaction
    • Define and enforce cloud and infrastructure security using Infrastructure-as-Code and GitOps workflows
    • Build identity, access, encryption, and network guardrails using automated controls
    • Implement software supply chain security including SBOM generation, artifact signing, and provenance validation
    • Develop detection-as-code and automated response capabilities to reduce reliance on manual security operations
    • Design and enforce controls to secure AI systems and prevent misuse, data leakage, and model risk
    • Leverage AI to improve detection, analysis, and automation across security operations
    • Translate regulatory requirements into enforceable technical controls and automated evidence generation
    • Eliminate manual security processes in favor of scalable engineering-driven solutions

    About Company

    At the Blue Cross and Blue Shield Association (BCBSA), we provide business strategy, technical support and consulting expertise to 36 Blue Cross and Blue Shield companies across the nation, employing more than 1,000 of the best strategic thinkers in the industry. We are a Brand manager that sets quality control standards for the 36 independent companies that use the Blue Cross and Blue Shield Brands, and we serve as a trade association that represents these Blue companies. It is through our involvement that the Blues companies share a united vision and strategy while also benefiting from the local strength of all member companies.

    Similar Jobs

    See more jobs