Quick Overview
Job Description
Cybersecurity Engineer – AI Security Analyst
Position Overview
Seeking a Cybersecurity Engineer 3 – AI Security Analyst to strengthen application security across the software development lifecycle. This role will perform security assessments, vulnerability analysis, remediation, secure code review, and security automation across applications, APIs, cloud workloads, repositories, and infrastructure.
The ideal candidate will bring strong Application Security / DevSecOps experience, hands-on knowledge of security scanning and vulnerability management, and the ability to work with Java and Python code. Experience using AI-assisted security tools to improve threat modeling, code review, vulnerability validation, and remediation is highly valuable.
Key Responsibilities
- Embed application security practices into the SDLC, including security standards, workflows, processes, and Definition of Done criteria.
- Perform application, API, cloud, repository, and infrastructure security assessments using traditional and AI-assisted security techniques.
- Manage SAST, SCA, secret scanning, dependency analysis, and infrastructure security scanning.
- Use GitHub Advanced Security, CodeQL, Burp Suite, and other approved security tools to identify and validate vulnerabilities.
- Analyze and prioritize findings based on exploitability, severity, business impact, compensating controls, and remediation requirements.
- Drive vulnerabilities from discovery through remediation, retesting, evidence collection, and verified closure.
- Identify and reduce security debt, dependency vulnerabilities, open-source risks, and software supply-chain exposure.
- Perform manual security testing, secure code review, API testing, and vulnerability validation.
- Apply OWASP Top 10, API Security Top 10, authentication/authorization, and secure coding principles.
- Read, analyze, test, and modify Java and Python application code to validate findings and support remediation.
- Support remediation through code fixes, configuration changes, infrastructure updates, and compensating controls.
- Develop security metrics, coverage reports, dashboards, and portfolio-level security insights.
- Safely leverage AI tools for security analysis, threat modeling, code review, vulnerability validation, documentation, and remediation guidance.
- Collaborate with architects, developers, DevOps engineers, product owners, and business stakeholders to communicate risks and drive remediation.
- Participate in Agile/Scrum ceremonies and maintain security-related stories, tasks, defects, and backlog items.
- Provide security coaching, knowledge sharing, and best-practice guidance to application teams.
Required Qualifications
- 5–7 years of hands-on Application Security / DevSecOps experience.
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, or related field; equivalent practical experience may be considered.
- Strong experience with Secure SDLC, DevSecOps, Agile, and Scrum.
- Hands-on experience with:
- Burp Suite
- GitHub Advanced Security
- CodeQL
- SAST / SCA
- Secret Scanning
- Dependency Analysis
- CI/CD Security
- Ability to analyze and modify Java and Python code for security validation and remediation.
- Strong understanding of OWASP Top 10 and API Security Top 10.
- Experience with cloud security, IAM, APIs, and modern application architectures.
- Strong vulnerability triage, validation, prioritization, and remediation experience.
- Understanding of responsible and secure use of AI-assisted development/security tools.
- Strong communication, stakeholder management, documentation, and problem-solving skills.
- Ability to work independently across multiple applications, teams, and technology stacks.
Preferred Candidate Profile
- Application Security Engineer with strong DevSecOps and Secure SDLC experience.
- Hands-on security testing and vulnerability remediation background.
- Comfortable reviewing Java/Python source code and working directly with development teams.
- Experience with AI security / AI-assisted security analysis is a strong advantage.
- Strong communicator who can influence developers, architects, DevOps teams, and business stakeholders.
- Experience building security metrics, dashboards, and portfolio-level reporting is preferred.
Work Environment
- 100% remote currently, but candidates must be local to Chicago, Peoria, Dallas, or Broomfield.
- Monday–Friday, 1st shift.
- Agile/Scrum environment with significant cross-functional collaboration.
- Caterpillar will provide required equipment/assets.
- 0–25% travel may be required.
Similar jobs
- PR
Cybersecurity Engineer 3 – AI Security Analyst, 100% Remote
NewProhires
United States🇺🇸Remote20 hours agoOWASPScrumAgile+3Technology - NI
Senior Information Systems Security Specialist with Security Clearance
Nightwing
Sterling, VA🇺🇸$99k - $206k/yrOn-site4 weeks agoDockerAWSSplunk+3Technology - NI
Cyber Host Forensic Analyst II with Security Clearance
Nightwing
Arlington, VA🇺🇸$77k - $163k/yrOn-site7 weeks agoSplunkTechnology - NG
2026 Part-Time Cyber Security Engineering Intern - Aurora CO with Security Clearance
NewNorthrop Grumman
Aurora, CO🇺🇸$21 - $38/hrHybrid20 hours agoSpringAgileHTTPTechnology - KR
Vulnerability Remediation Engineer
NewK-Tek Resourcing LLC
Raritan, NJ🇺🇸Hybrid20 hours agoEngineering - CI
Cybersecurity Analyst
NewCogent Infotech Corp
White Plains, NY🇺🇸On-site20 hours agoSplunkZero TrustTechnology