Haystack
← Back to Jobs
Remote
Technology
PR

W2 10+ Cybersecurity Engineer 3 – AI Security Analyst - Chicago, IL | Peoria, IL | Dallas, TX | Broomfield, CO

ProhiresUnited States🇺🇸United StatesPosted 1 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
23 hours ago
OWASPScrumAgileJavaPythonStakeholder Management

Job Description

Cybersecurity Engineer 3 – AI Security Analyst

Request #: 111723-1
Openings: 2
Duration: 12 Months
Location: 100% Remote
Work Eligibility: Candidates must be local to a Caterpillar Digital Hub — Chicago, IL | Peoria, IL | Dallas, TX | Broomfield, CO

Interview: 1-hour virtual panel interview
Contract: 12 months

 

Position Overview

Caterpillar is seeking a Cybersecurity Engineer 3 – AI Security Analyst to strengthen application security across the software development lifecycle. This role will perform security assessments, vulnerability analysis, remediation, secure code review, and security automation across applications, APIs, cloud workloads, repositories, and infrastructure.

The ideal candidate will bring strong Application Security / DevSecOps experience, hands-on knowledge of security scanning and vulnerability management, and the ability to work with Java and Python code. Experience using AI-assisted security tools to improve threat modeling, code review, vulnerability validation, and remediation is highly valuable.

Key Responsibilities

  • Embed application security practices into the SDLC, including security standards, workflows, processes, and Definition of Done criteria.
  • Perform application, API, cloud, repository, and infrastructure security assessments using traditional and AI-assisted security techniques.
  • Manage SAST, SCA, secret scanning, dependency analysis, and infrastructure security scanning.
  • Use GitHub Advanced Security, CodeQL, Burp Suite, and other approved security tools to identify and validate vulnerabilities.
  • Analyze and prioritize findings based on exploitability, severity, business impact, compensating controls, and remediation requirements.
  • Drive vulnerabilities from discovery through remediation, retesting, evidence collection, and verified closure.
  • Identify and reduce security debt, dependency vulnerabilities, open-source risks, and software supply-chain exposure.
  • Perform manual security testing, secure code review, API testing, and vulnerability validation.
  • Apply OWASP Top 10, API Security Top 10, authentication/authorization, and secure coding principles.
  • Read, analyze, test, and modify Java and Python application code to validate findings and support remediation.
  • Support remediation through code fixes, configuration changes, infrastructure updates, and compensating controls.
  • Develop security metrics, coverage reports, dashboards, and portfolio-level security insights.
  • Safely leverage AI tools for security analysis, threat modeling, code review, vulnerability validation, documentation, and remediation guidance.
  • Collaborate with architects, developers, DevOps engineers, product owners, and business stakeholders to communicate risks and drive remediation.
  • Participate in Agile/Scrum ceremonies and maintain security-related stories, tasks, defects, and backlog items.
  • Provide security coaching, knowledge sharing, and best-practice guidance to application teams.

 

Required Qualifications

  • 5–7 years of hands-on Application Security / DevSecOps experience.
  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Systems, or related field; equivalent practical experience may be considered.
  • Strong experience with Secure SDLC, DevSecOps, Agile, and Scrum.
  • Hands-on experience with:
    • Burp Suite
    • GitHub Advanced Security
    • CodeQL
    • SAST / SCA
    • Secret Scanning
    • Dependency Analysis
    • CI/CD Security
  • Ability to analyze and modify Java and Python code for security validation and remediation.
  • Strong understanding of OWASP Top 10 and API Security Top 10.
  • Experience with cloud security, IAM, APIs, and modern application architectures.
  • Strong vulnerability triage, validation, prioritization, and remediation experience.
  • Understanding of responsible and secure use of AI-assisted development/security tools.
  • Strong communication, stakeholder management, documentation, and problem-solving skills.
  • Ability to work independently across multiple applications, teams, and technology stacks.

 

Top 5 Tools

  1. GitHub Advanced Security
  2. CodeQL
  3. Burp Suite
  4. SAST / SCA Tools
  5. CI/CD Security Tooling

 

Top 3 Core Skills

  1. Application Security / DevSecOps
  2. Vulnerability Assessment & Remediation
  3. Secure Code Review – Java & Python

Top 7 Keywords

Application Security | DevSecOps | Secure SDLC | SAST/SCA | CodeQL | GitHub Advanced Security | OWASP

 

Preferred Candidate Profile

  • Application Security Engineer with strong DevSecOps and Secure SDLC experience.
  • Hands-on security testing and vulnerability remediation background.
  • Comfortable reviewing Java/Python source code and working directly with development teams.
  • Experience with AI security / AI-assisted security analysis is a strong advantage.
  • Strong communicator who can influence developers, architects, DevOps teams, and business stakeholders.
  • Experience building security metrics, dashboards, and portfolio-level reporting is preferred.

Similar jobs