Application Security
Why This Role Stands Out
This hybrid role offers a fantastic opportunity to integrate cutting-edge security practices into the software development lifecycle, driving significant impact within a reputable organization. You'll thrive here if you possess a deep understanding of application security, cloud environments, and a passion for automation, making you an invaluable partner to development teams.
Quick Overview
Job Description
W2 - Client does not sponsor visa
Local to Chicago IL only will be considered
- Application Security: Deep understanding of vulnerabilities and remediation (OWASP, CWE/CVE, SANS 25).
Broad Security Knowledge: Experience with enterprise security architecture, threat modeling, vulnerability assessment, risk analysis, defense in depth, SDLC, IAM, and API security.
Cloud Security: Hands-on experience with MS Azure and/or AWS.
Development Experience: Proficiency in one or more languages (Java, Python, .Net, JS, or equivalent).
Automation & Scripting: Implementation of automation to streamline security processes.
Certifications: Professional certification such as CISSP, CCSP, GWAPT, GWEB, or AWS Security Specialty. Technical Skills (Desired)
Professional certifications (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB, etc.).
Strong understanding and experience with information security technologies.
AI Fluency is preferred. The Lead Cybersecurity Engineer will be a key partner to development teams, focusing on integrating security into the software development lifecycle (SDLC). This role is responsible for the security engineering of cloud environments (AWS, Azure) and vulnerability management for both Infrastructure as Code (IaC) and application code. Key Contributions:
Security by Design: Implementing and consulting on secure development practices.
DevSecOps Integration: Integrating security into DevOps pipelines.
Vulnerability Management: Managing and tracking security risks to remediation.
Agile Collaboration: Working closely with development teams in an agile environment.
o Analyzing, validating, and communicating on security defects from tools like CodeQL, Rapid7, penetration testing, and bug bounties.
o Acting as a partner to software engineers by providing accurate information on vulnerabilities and remediation strategies.
o Serving as a trusted advisor ("best friend") to software engineers, architects, and product owners.
o Providing context-aware guidance to help teams make secure decisions and document their architectures.
o Navigating review and approval processes for new features and issue remediation.
o Enabling and monitoring automated defect detection tools (e.g., CodeQL, Rapid7) at the repository or application level.
o Ensuring tools are configured and running according to established processes.
8. Security Test Onboarding & Management:
o Collecting and communicating scope and access information for penetration testing.
o Handling the output of these assessments through the defect management process.
Accountable for a dedicated set of applications and works directly with their respective development teams.
Part of a larger security engineering team that sets standards and best practices for collaboration with developers.
Helps development teams identify security gaps and assists in creating solutions to ensure services are compliant with enterprise security requirements. Soft Skills (Required)
Excellent written and verbal communication skills.
Demonstrated ability to communicate highly technical security concepts to non-security audiences.
Ability to coordinate multiple teams in accomplishing process review and improvement.
Education & Experience
Bachelor's Degree in computer science or a related field with 8+ years in information security.
Master's Degree with 6+ years of experience.
Skills
Similar jobs
Journeyman Network & Computer Systems Administrator with Security Clearance
DataPath, Inc. · Fayetteville, United States
11 minutes agoIntegration/Test Engineer with Security Clearance
L3Harris Technologies · Greenville, United States
11 minutes agoCyber & Compliance Analyst (Hybrid Remote) with Security Clearance
Kforce Federal Solutions · Arlington, United States
11 minutes agoSecurity Manager
StratEdge It consulting INC · Austin, United States
12 minutes agoSr Administrative Assistant
Northern Trust · Miami, United States
31 minutes agoSenior Principal, Strategy Development with Security Clearance
L3Harris Technologies · San Diego, United States
32 minutes ago$159.5k - $196.5k/yr