Senior Application Security Engineer
Senior
Application Security
Bug Bounty
Cloud Platforms
Cybersecurity Tools
Data Security
Dynamic Application Security Testing
Information Security
InfoSec
Offensive Security
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Security Testing Tools
Software Composition Analysis
Software Security
Software Supply Chain Security
Solution Architecture
Static Application Security Testing
Job Description
Senior Application Security Engineer role on the Cybersecurity team at Cat Digital, focused on guiding software engineers in securing application development and delivery. The position emphasizes security defect management, security consulting, tool enablement, onboarding security testing, maturity measurement, and correcting error reports across a portfolio of applications.
Responsibilities
- Analyze, validate, communicate, and consult on security defects identified from automated and manual sources, including CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, and similar channels.
- Partner with software engineers, architects, product owners, and leaders to deliver context-aware guidance. Document decisions and the resulting architectures, and navigate relevant review and approval processes when implementing new features and remediating existing issues.
- Enable and monitor automated defect detection tooling (such as CodeQL and Rapid7) at the repository or application level according to established process.
- Collect and communicate scope and access information needed for penetration testing and security assurance assessments, then process outputs through the Defect Management Process.
- Consult with software engineers to strengthen application security maturity using scorecards and maturity models established by Cat Digital.
- Author, in close collaboration with software engineers, corrections to error reports so engineers and architects across Cat Digital can avoid similar issues in their own applications.
- Act as a technical engineer across a portfolio of related applications, guiding cybersecurity practices, influencing security and prioritization decisions at the bug or story level, and supporting secure delivery.
Requirements
- Knowledge of decision-making processes and associated tools and techniques, with the ability to analyze situations and make productive judgments.
- Understanding of effective communication concepts, tools, and techniques, with the ability to communicate, receive, and interpret ideas and needs accurately.
- Knowledge of the software development life cycle and ability to use structured methods to deliver and manage new or enhanced software products.
- Knowledge of software integration processes and functions, including designing and maintaining interfaces and linkage to alternative platforms and software packages.
- Knowledge of software product design, including translating market requirements into software product design.
- Experience as a software engineer in any language or framework, with a preference for cybersecurity-focused work.
- Experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
- Experience analyzing and remediating security findings from automated and manual sources such as SAST, DAST, penetration testing, and SCA.
- Experience using one or more of the following for secure coding and decision-making: OWASP Top 10, MITRE Common Weakness Enumeration (CWE) Top 25, OWASP Application Security Verification Standard (ASVS), and other industry-standard best-practice guides or frameworks.
- Experience building or supporting web applications and APIs, including Single Page Applications (SPA) and RESTful APIs.
- Professional certifications in either cybersecurity or software engineering, including options such as cloud provider certifications (Associate or Professional level), CompTIA Security+, Cloud+, CCSK, and/or ISC2 Certified Software Lifecycle Professional (CSLP).
- Ability to be based in one of the following locations: Chicago, IL; Peoria, IL; or Dallas, TX.
Technologies
- CodeQL
- Rapid7 Web Application Security
- Penetration testing
- Bug bounty
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- OWASP Top 10
- MITRE Common Weakness Enumeration (CWE) Top 25
- OWASP Application Security Verification Standard (ASVS)
- AWS, Azure, GCP, Salesforce
- Single Page Applications (SPA)
- RESTful APIs
- CompTIA Security+, Cloud+, CCSK
- ISC2 Certified Software Lifecycle Professional (CSLP)
Benefits
- Medical, dental, and vision benefits*
- Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
- 401(k) savings plans*
- Health Savings Account (HSA)*
- Flexible Spending Accounts (FSAs)*
- Health Lifestyle Programs*
- Employee Assistance Program*
- Voluntary Benefits and Employee Discounts*
- Career Development*
- Incentive bonus*
- Disability benefits
- Life Insurance
- Parental leave
- Adoption benefits
- Tuition Reimbursement
- These benefits also apply to part-time employees
Location, Pay, and Posting Dates
- Location: Chicago, IL (onsite)
- Base Salary Range: USD 112,710 - 183,140 per year
- Posting Dates: September 22, 2026 - October 4, 2026
Additional Details
- This position requires the candidate to be based in either Chicago, IL; Peoria, IL; or Dallas, TX.
- Relocation assistance is NOT available.
- Visa sponsorship is NOT available.
- Compensation and benefits may vary depending on job level, market location, job-related knowledge, skills, individual performance, and experience.
- Any offer of employment is conditioned upon the successful completion of a drug screen.