Medical Mutual
Application Security & DevSecOps Architect
At a Glance
About This Role
Responsibilities
- Lead the design and implementation of secure application architecture across the enterprise
- Lead the design and implementation of DevSecOps practices across the enterprise
- Embed security throughout the software development lifecycle (SDLC) to reduce risk
- Improve resiliency and enable scalable, secure software delivery
- Serve as the primary technical authority for application security
- Manage vulnerability management and DevSecOps pipeline security
About Medical Mutual
Medical Mutual of Ohio, based in Cleveland, is the oldest and largest health insurance company in the state, established in 1934. Originally founded as the Cleveland Hospital Service Association, it pioneered the prepaid hospitalization insurance model to provide affordable healthcare during the Great Depression. Over the years, the company has evolved through various mergers and rebranding, becoming Medical Mutual of Ohio in 1997. The company serves approximately 1.2 to 1.6 million members, primarily in Ohio, and employs around 2,500 to 2,850 people. Medical Mutual offers a wide range of health and supplemental insurance products, including fully insured and self-funded group coverage, individual plans, Medicare Advantage, and various supplemental coverages like life, dental, and vision insurance. Its subsidiaries, such as MedMutual Protect and Paramount, further enhance its offerings, providing additional Medicare products and commercial plans. Medical Mutual is committed to community engagement and high-quality wellness benefits, earning recognition as one of Ohio's Healthiest Employers.
Security at Medical Mutual
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Information not publicly available. The only direct AppSec philosophy evidence comes from the Application Security & DevSecOps Architect job posting, which frames the AppSec role's mission around embedding security throughout the software development lifecycle (SDLC) and serving as the primary technical authority for application security, vulnerability management, and DevSecOps pipeline security.”
Security Team
Application Security leadership at Medical Mutual includes: (1) Dave Hangen – VP, IT Infrastructure and Chief Information Security Officer (CISO); (2) Justin Prather – Director of Information Security; (3) Joanna D. – Security Engineer. The Information Security function, led by the CISO/Director of Information Security, oversees application security. Team size is not publicly available. Active AppSec job postings include the Application Security & DevSecOps Architect role (Greenhouse Job 7701734003), IT Security Specialist, and Infrastructure Engineer positions. Common skill patterns emphasize SDLC integration and threat modeling with cross-functional influence on engineering/operations security standards.
Key Initiatives
Shift Left in Practice: 'Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling, and deliver developer-focused AppSec training.' Recent initiatives include published corporate 'AI Principles' page , active hiring of Application Security Engineer and IT Security Specialist roles, and updated member-facing 'Security of Your Online Information' page . Security Champions Program and formal vulnerability management process details are not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn