You desire impactful work.
You’re RGA ready
RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.
The Lead Application Security Engineer will help reduce risk across our application portfolio by partnering with engineers and product teams, coordinating external penetration tests, and turning findings into prioritized, trackable remediation work. This position will run and configure application security tooling—SAST, DAST, SCA, and secrets scanning—integrating results into engineering workflows and helping teams focus on the fixes that matter most.
Principle Duties
Coordinate external penetration tests (scoping, scheduling, access, and logistics) across multiple application teams.
Partner with application owners to triage findings, validate impact, and prioritize remediation based on risk and business context.
Operate, tune, and maintain SAST and SCA tooling (rulesets, baselines, false-positive management, and integrations) to improve signal-to-noise.
Run and configure DAST scanning and validate results with engineering teams, including safe testing practices and environment coordination.
Implement and operate secrets scanning across source control and CI/CD, and partner on prevention patterns (rotation, vaulting, and developer guidance).
Integrate findings into ticketing and SDLC workflows, define SLAs, and track remediation progress to closure with clear ownership.
Create lightweight standards, guidance, and enablement so application teams can remediate faster without security becoming a blocker.
Education
Bachelor’s Degree in Arts/Sciences (BA/BS) or equivalent experience - Required
Master’s degree in Arts/Sciences (MA/MS) or professional industry certification - Preferred
Work Experience
6+ years in application security, product security, or software engineering with a security focus.
Experience coordinating and/or consuming third-party penetration tests and translating results into actionable remediation plans.
Skills and Abilities
Strong hands-on skill with Terraform, Python, Bash, and CI/CD (Jenkins or equivalent).
Hands-on experience running and configuring SAST, DAST, SCA, and secrets scanning in CI/CD or adjacent workflows.
Strong understanding of common web and API vulnerabilities (e.g., OWASP Top 10) and practical remediation strategies.
Comfort with Git-based workflows, build pipelines, and issue tracking; able to work with engineers where they are.
Ability to communicate risk clearly and drive alignment on prioritization and timelines with application owners and stakeholders.
Advanced oral and written communication skills demonstrating ability to share and impart knowledge. Ability to liaise with individuals across a wide variety of operational, functional, and technical disciplines. Advanced ability to translate business needs and problems into viable/accepted solutions.
Ability to quickly adapt to new methods, work under tight deadlines and stressful conditions. Ability to appropriately balance priorities, deadlines, and deliverables.
Advanced ability to set goals and handle multiple tasks, clients, and projects simultaneously. Advanced investigative, analytical and problem solving skills.
Ability to work well within a team environment and participate in department/team projects
Advanced skills in customer relationship management and change management. Advanced negotiating and persuasion skills
#LI-CW1
#LI-Remote
What you can expect from RGA:
Gain valuable knowledge from and experience with diverse, caring colleagues around the world.
Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.
Join the bright and creative minds of RGA, and experience vast, endless career potential.
We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.
Compensation Range:
$126,710.00 - $188,840.00 AnnualBase pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits.
RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.