EngineerJobs.io
← Back to all jobs

Job Description

Advance application security across the software development lifecycle by leading vulnerability strategy, execution, and team enablement.

Responsibilities

  • Build relationships across application development, DevOps, cyber security, and IT to guide secure development outcomes through expert technical direction
  • Lead vulnerability management activities, including prioritization, risk evaluation, progress tracking, and stakeholder communication
  • Track emerging business, technology, and cyber security trends, then translate insights into practical improvements for development teams
  • Partner with engineering and DevOps to evaluate, implement, and optimize vulnerability management capabilities across people, process, and technology
  • Own and improve key components of vulnerability management and application security solutions in complex enterprise environments
  • Conduct and oversee targeted vulnerability assessments to identify control gaps and measure effectiveness of existing safeguards
  • Use security and risk frameworks to guide remediation decisions and priorities, including ISO 27001-2, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, and MITRE ATT&CK
  • Apply hands-on vulnerability management and prioritization platform expertise to drive adoption of risk-based remediation
  • Perform root cause analysis on vulnerabilities and collaborate with development and platform teams to define practical solutions
  • Assess exploitability and business impact to recommend remediation strategies that balance risk reduction with operational needs
  • Provide broad expertise across vulnerability management, privacy, incident response, governance, risk and compliance, enterprise security strategy, and security architecture
  • Lead and coordinate cyber security initiatives by shaping plans, driving execution, and communicating status to technical stakeholders and leadership
  • Mentor teammates through technical guidance, supporting development, and strengthening consistency in application security work
  • Direct vulnerability identification, assessment, prioritization, and remediation across code, infrastructure, and applications, including secure development practices, automation, and risk reduction
  • Act as a trusted technical escalation point for application and vulnerability management; drive remediation and influence technical decisions across multiple initiatives
  • Provide leadership continuity and decision support when the manager is out of office

Requirements

  • Preferred: Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field
  • Minimum: 6–8 years of related experience
  • Strong understanding of the vulnerability management lifecycle, governance, and risk-based prioritization in enterprise environments
  • Deep familiarity with application security and risk frameworks, including ISO 27001-2, ISO 31000, PCI DSS, OWASP ASVS, NIST frameworks, ITIL, COBIT, CVSSv4, and MITRE ATT&CK
  • Hands-on experience with vulnerability management tools: Qualys, Tenable, Snyk, and TruffleHog Pro
  • Experience working in Agile development environments
  • Strong understanding of operating systems: Windows, Unix, and MacOS; cloud concepts including secure build images, ephemeral workloads, and cloud patching; plus networking fundamentals
  • Broad application development background across full-stack and mobile development for iOS and Android
  • Experience building metrics, dashboards, and risk reporting for technical teams and leadership
  • Experience with API security scanning and application security testing approaches
  • Ability to communicate complex technical issues clearly to engineers, senior leaders, and business stakeholders
  • Broad knowledge of cyber security practices including secure configuration management, data protection and privacy, security monitoring, incident response, governance, risk and compliance, patch management, and enterprise security architecture
  • Strong written and verbal communication skills to influence senior management, technical experts, and cross-functional stakeholders
  • Demonstrated ability to analyze issues strategically and analytically while balancing technical depth with practical business outcomes
  • Advanced understanding of the use of AI in application development
  • Experience working in cloud and container environments
  • Penetration testing and application security experience
  • Automation and scripting experience, such as Python or Bash
  • Deep experience in enterprise application development

Technologies

  • ISO 27001-2, ISO 31000, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, OWASP ASVS, MITRE ATT&CK
  • Qualys, Tenable, Snyk, TruffleHog Pro
  • Agile, Windows, Unix, MacOS, iOS, Android, Python, Bash

Benefits

  • Comprehensive medical, dental, vision coverage
  • Life insurance
  • Disability coverage for positions working more than 30 hours per week
  • Retirement program with generous matching employer contributions
  • Paid vacation
  • Sick days and holidays
  • Paid personal and maternity/parental leaves
  • Employee and Family Assistance Program
  • Annual incentive plan participation
  • Long-term incentive plan participation

Location: Deerfield, IL (onsite)

Salary: USD 91,200 - 143,220 per yearly

Similar Jobs