Security Engineer
bcbsmn · Eagan, MN · United States · On-site
Pay: USD 79,100 – 104,800 a year
Posted Oct 5, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Blue Cross and Blue Shield of Minnesota
At Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate, you are joining a culture that is built on values of succeeding together, finding a better way, and doing the right thing. If you are ready to make a difference, join us.
The Impact You'll Have

The Security Engineer strengthens the organization’s Application Security (AppSec) and AI Security programs by identifying, assessing, and reducing risk throughout the software and AI development lifecycles. Working under general direction and within established security standards and processes, this role integrates security scanning and automation into GitLab-based workflows, evaluates applications and infrastructure defined through Terraform, and supports protective controls such as web application firewalls (WAFs). The position partners with development and technology teams working in Java and Python amongst others to identify vulnerabilities, improve secure engineering practices, protect organizational assets, and support compliance, risk management, and operational objectives. The role independently performs routine and moderately complex assignments and escalates high-impact, ambiguous, or highly complex matters to senior security resources.

 What You'll Do
Identify, assess, and prioritize routine to moderately complex AppSec and AI Security risks, vulnerabilities, and control gaps through application, code, dependency, infrastructure-as-code, and AI workload scanning; document findings and escalate high-impact or highly complex issues as appropriate.
Implement, maintain, and improve security controls and automation within GitLab development and CI/CD workflows to identify issues earlier, support secure releases, and streamline remediation.
Review Terraform configurations and related cloud deployment patterns for security weaknesses, policy violations, and control gaps; validate remediation using established standards and processes.
Support the configuration, monitoring, and improvement of WAF protections for internet-facing applications and APIs, including services that enable AI capabilities.
Partner with engineering teams developing in Java, Python, and Go to interpret scanning results, recommend practical remediation, promote secure coding practices, and reduce recurring vulnerabilities.
Conduct defined security assessments of applications, APIs, AI solutions, models, agents, and supporting data flows to evaluate control effectiveness, identify improvement opportunities, document results, and validate remediation efforts.
Collaborate with business, development, data, and technology stakeholders to document AppSec and AI Security requirements and implement solutions for defined security needs and identified risks,…