About this role
About Blue Cross and Blue Shield of Minnesota
At Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate, you are joining a culture that is built on values of succeeding together, finding a better way, and doing the right thing. If you are ready to make a difference, join us.
# The Impact You'll Have

The Security Engineer strengthens the organization’s Application Security (AppSec) and AI Security programs by identifying, assessing, and reducing risk throughout the software and AI development lifecycles. Working under general direction and within established security standards and processes, this role integrates security scanning and automation into GitLab-based workflows, evaluates applications and infrastructure defined through Terraform, and supports protective controls such as web application firewalls (WAFs). The position partners with development and technology teams working in Java and Python amongst others to identify vulnerabilities, improve secure engineering practices, protect organizational assets, and support compliance, risk management, and operational objectives. The role independently performs routine and moderately complex assignments and escalates high-impact, ambiguous, or highly complex matters to senior security resources.


# What You'll Do
- Identify, assess, and prioritize routine to moderately complex AppSec and AI Security risks, vulnerabilities, and control gaps through application, code, dependency, infrastructure-as-code, and AI workload scanning; document findings and escalate high-impact or highly complex issues as appropriate.
- Implement, maintain, and improve security controls and automation within GitLab development and CI/CD workflows to identify issues earlier, support secure releases, and streamline remediation.
- Review Terraform configurations and related cloud deployment patterns for security weaknesses, policy violations, and control gaps; validate remediation using established standards and processes.
- Support the configuration, monitoring, and improvement of WAF protections for internet-facing applications and APIs, including services that enable AI capabilities.
- Partner with engineering teams developing in Java, Python, and Go to interpret scanning results, recommend practical remediation, promote secure coding practices, and reduce recurring vulnerabilities.
- Conduct defined security assessments of applications, APIs, AI solutions, models, agents, and supporting data flows to evaluate control effectiveness, identify improvement opportunities, document results, and validate remediation efforts.
- Collaborate with business, development, data, and technology stakeholders to document AppSec and AI Security requirements and implement solutions for defined security needs and identified risks, with senior guidance for complex or cross-enterprise decisions.


# How You'll Do It
- Provide practical guidance on established security controls, risk management practices, and security-related standards; refer novel, high-risk, or complex interpretations to senior security resources.
- Develop and maintain security procedures, work instructions, standards, and technical documentation, incorporating review and approval as required.
- Participate in risk assessments, audits, and continuous improvement initiatives by supplying evidence, completing assigned actions, and recommending improvements within the scope of the role.
- Performs additional responsibilities consistent with the scope and level of the role, as assigned


# Required Skills & Experience
- 3+ years of related IT Security professional experience.
- Bachelor’s degree; in lieu of a degree, an additional two years of relevant experience beyond the qualifications listed above may be accepted.
Preferred Skills & Experience
- Knowledge of information security, cybersecurity practices, and risk management principles.
- Knowledge of security standards, frameworks, and regulatory or compliance requirements.
- Experience supporting process improvement, operational effectiveness, or security practices.
- Ability to communicate complex topics clearly and concisely, actively listen to anticipate stakeholder needs, and align others to drive informed decisions.
- Ability to analyze complex information, evaluate options, and work cross-functionally to drive resolution and prevent recurrence.
- Ability to effectively organize work, balance competing priorities, and manage time across complex assignments and competing deadlines.


# Licensure/Certifications

Preferred -
Amazon AWS Cloud Practitioner - Amazon


# Role Designation

Hybrid


Role designation definition:
- Teleworking is working full time remote.
- Hybrid is a minimum of 2 days onsite.
- Onsite is full-time onsite.
Anchored in Connection
Our hybrid approach is designed to balance flexibility with meaningful in-person connection and collaboration. We come together in the office two days each week – most teams designate at least one anchor day to ensure team interaction. These in-person moments foster relationships, creativity, and alignment. The rest of the week you are empowered to work remote.


# Compensation and Benefits

$79,100.00 - $104,800.00 - $130,500.00 Annual
Pay is based on several factors which vary based on position, including skills, ability, and knowledge the selected individual is bringing to the specific job.
We offer a comprehensive benefits package which may include:
- Medical, dental, and vision insurance
- Life insurance
- 401k
- Paid Time Off (PTO)
- Volunteer Paid Time Off (VPTO)
- And more
To discover more about what we have to offer, please review our benefits page .


# Equal Employment Opportunity Statement
At Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. Blue Cross of Minnesota is an Equal Opportunity Employer and maintains an Affirmative Action plan, as required by Minnesota law applicable to state contractors. All qualified applications will receive consideration for employment without regard to, and will not be discriminated against based on any legally protected characteristic.
Individuals with a disability who need a reasonable accommodation in order to apply, please contact us at: [email protected].
Blue Cross® and Blue Shield® of Minnesota and Blue Plus® are nonprofit independent licensees of the Blue Cross and Blue Shield Association.
Physical requirements.