AppSec Jobs
← Back to all jobs

Humana

Security Architect, Product Security

Onsite
Fort Lauderdale, FLPosted 2 days agoWebsite
Apply on LinkedIn →

About This Role

The job posting indicates the position has been filled and is no longer accepting applications. The markdown content does not contain specific job description details.

Benefits & Perks

Compelling compensation and benefit offerings
Health insurance benefits
Financial security programs
Career development and growth opportunities
Diverse and inclusive workplace culture
Remote work opportunities available

About Humana

Humana Inc. is a leading American health insurance company based in Louisville, Kentucky. As the fourth-largest health insurance provider in the U.S., it serves nearly 20 million members across all 50 states. Humana focuses on making healthcare simple and affordable, aiming to improve health outcomes through meaningful connections between patients, providers, and communities. Founded in 1961, Humana transitioned from a nursing home operator to a health insurance provider in the 1980s. The company operates through two main segments: Insurance and CenterWell. Its Insurance segment includes Medicare Advantage plans, Medicaid options, employer group plans, and specialty benefits. The CenterWell segment offers senior-focused primary care, pharmacy services, home health solutions, and hospice care. Humana is committed to serving seniors, lower-income individuals, employers, military personnel, and families seeking supplemental health plans.

Industry

insurance

Employees

68,000

3410 engineers

Revenue

$130B

Website

Visit →

Security at Humana

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Humana's stated priorities are reducing security risk across enterprise applications, improving application security posture, building secure software platforms, and embedding security controls into application architectures and CI/CD pipelines . The developer-facing posture emphasizes developer experience, engineering enablement, cross-functional partnership, self-service, automation, and reducing developer overhead. Automated quality gates, release gating, and deployment controls are specified, but no public evidence establishes a security-signoff-only model . The risk approach explicitly includes threat modeling, risk analyses, security assessments, risk-based release readiness, business-priority alignment, risk appetite, metrics, thresholds, trade-offs, and compromises. Stated goals include expanding security outcomes across the application portfolio, reducing security defects, improving remediation tracking, automating repeatable processes, conducting root-cause analysis, and reducing manual effort. Information not publicly available: a dedicated Humana AppSec mission statement, a public AppSec-specific pain-point interview, or a published AppSec policy manifesto.

Security Team

Humana's public AppSec organization is described through Product Security and DevSecOps functions. The Product Security Tools team works with Product Security, DevSecOps, Cloud Engineering, AI Security, Security Architecture, Scan & Triage, CSOC/TMR, IAM, application teams, and vendors. The DevSecOps architecture role is within DevSecOps & Engineering and covers secure software platforms, engineering enablement, CI/CD integration, and security automation . Humana's CISO reporting line is to the CIO; the current CIO, Japan Mehta, oversees cybersecurity and reports to the CEO. Publicly identifiable adjacent security leaders include Japan Mehta, Danny J. (Director, CyberSecurity Engineering), and Eddy Arnold (Lead Security Advocate, Cybersecurity Training & Awareness). No current named AppSec/Product Security head was identified. Current AppSec team size: Information not publicly available. A ⚠️ August 2025 posting described a 25–30-person DevSecOps automation team reporting to the Associate Vice President of Product Security; this is historical and not a current AppSec headcount. Two relevant August 2026 postings were identified: Cyber Security Engineer, R-426256, and Lead, DevSecOps Application Architecture, R-424780. The Security Architect, Product Security posting was filled, and the Product Security Product Owner posting was no longer accepting applications. Common patterns include CI/CD integration, SAST/DAST/SCA, secrets detection, cloud security, automation, threat modeling, secure coding, Terraform, Docker, Kubernetes, GitHub Actions, Azure DevOps, and remediation reporting .

Key Initiatives

  • Security Champions program: No Evidence Found.
  • Shift-left in practice: Product Security tools are integrated with CI/CD pipelines, developer workflows, cloud platforms, GitHub/Azure DevOps, Splunk, and ServiceNow.
  • Automated quality gates, pipeline-as-code, pull-request standards, release gating, and deployment controls are named .
  • Vulnerability management: the Product Security Tools role covers scan issues, user-reported incidents, findings and remediation dashboards, ServiceNow integration, Cycode remediation tracking, root-cause analysis, preventive controls, and reporting.
  • A Scan & Triage function is named.
  • Public evidence does not specify vulnerability-intake SLAs, severity-based remediation deadlines, ticket ownership rules, bug-bounty intake, or penetration-test intake.
  • Secure SDLC artifacts include security requirements, threat models, security assessments, secure design patterns, development standards, architecture decisions, automated quality gates, release controls, SOPs, playbooks, knowledge-transfer documentation, escalation paths, and process guides .
  • Recent initiatives in the six months before are represented by 2026 recruiting activity for Product Security Tools, including AppOmni SSPM expansion, Cycode secrets-detection operations, Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, AI application discovery, and AI posture management.
  • A recently posted Senior AI Security Architect role also covers GenAI, MCP, Agentic AI, AI application architecture, threat modeling, AI security standards, safeguards, controls, and tooling automation.
  • These postings document active role scopes and priorities, not a separately published program launch announcement .

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn