Salvatech logo

Application Engineer

Salvatech
Posted 3 hours ago
ColombiaRemoteEngineering & Development
Is this job info correct?
About Us

Salvatech connects Colombian talent with international companies looking for skilled professionals. We help organizations build efficient remote teams while enabling professionals to access global opportunities, providing full support throughout hiring, onboarding, employment management, and local assistance. We combine technology, proximity, and human talent to create partnerships that drive growth and productivity on both sides.

  • Location: Colombia (100% Remote)
  • Employment Type: Full-time | Indefinite Contract
  • Work Schedule: Full-time / Monday to Friday | 8:00 AM – 5:00 PM (ET)
  • Work Environment: Collaborative environment with Colombian and international teams
  • Language: Professional English
  • Industry: Healthcare Technology / Payments
  • Salary: Negotiable

Role Summary

We are looking for a hands-on Application Engineer to join a dedicated engineering team supporting a security-remediation program for a leading U.S. healthcare payments and revenue-cycle software company. In this role, you will work directly with Java and .NET applications to identify and remediate application-security findings across multiple repositories and codebases. You will collaborate with senior engineers and follow established secure-coding, deployment, and compliance processes. This is a highly hands-on role focused on application security remediation, secure coding, dependency upgrades, testing, and resolving vulnerabilities identified through security scanning tools.

Responsibilities

  • Remediate application-security vulnerabilities in Java and/or .NET (C#) code.
  • Address issues related to authentication, authorization, injection, input validation, session management, cryptography, and secrets handling.
  • Upgrade vulnerable dependencies and frameworks, and resolve the breakage those upgrades introduce.
  • Work across multiple codebases and teams, following the client's secure-coding standards.
  • Write and adjust tests to validate fixes and prevent regression.
  • Move fixes through the established deployment and change-control path.
  • Capture remediation evidence for audit and compliance review.
  • Triage assigned findings; escalate architectural findings to the POD's senior SRE and the shared Lead Engineer.

Qualifications

  • 3–5 years of hands-on software engineering experience with Java and/or .NET/C#.
  • Strong proficiency in at least one of Java or .NET/C#, with working knowledge of the other.
  • Advanced English level (spoken and written).
  • Solid grasp of application-security fundamentals (OWASP Top 10, injection, authentication / authorization, session management, cryptography basics, and secrets handling).
  • Experience upgrading dependencies and frameworks (for example Spring, .NET Framework / .NET Core) and fixing the resulting issues.
  • Experience remediating from SAST / DAST / SCA output (e.g., Checkmarx, Fortify, Snyk, Veracode), this seatvworks a queue of scanner findings.
  • Familiarity with common build and dependency tooling (Maven / Gradle, NuGet / MSBuild).
  • Version control and pull-request workflow (Git); comfortable writing tests.

Nice To Have

  • Experience in healthcare or another regulated industry.
  • Knowledge of HIPAA, HITRUST, PCI DSS, or SOC 2.
  • Strong hands-on experience in both Java and .NET.
  • Secure-coding certification or formal security training.
  • Experience with AWS and/or Azure.
  • Familiarity with CI/CD pipelines and deployment processes.

Similar jobs