Senior Application Security Engineer
Job Description
Advance application security across the software development lifecycle by leading vulnerability strategy, execution, and team enablement.
Responsibilities
- Build relationships across application development, DevOps, cyber security, and IT to guide secure development outcomes through expert technical direction
- Lead vulnerability management activities, including prioritization, risk evaluation, progress tracking, and stakeholder communication
- Track emerging business, technology, and cyber security trends, then translate insights into practical improvements for development teams
- Partner with engineering and DevOps to evaluate, implement, and optimize vulnerability management capabilities across people, process, and technology
- Own and improve key components of vulnerability management and application security solutions in complex enterprise environments
- Conduct and oversee targeted vulnerability assessments to identify control gaps and measure effectiveness of existing safeguards
- Use security and risk frameworks to guide remediation decisions and priorities, including ISO 27001-2, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, and MITRE ATT&CK
- Apply hands-on vulnerability management and prioritization platform expertise to drive adoption of risk-based remediation
- Perform root cause analysis on vulnerabilities and collaborate with development and platform teams to define practical solutions
- Assess exploitability and business impact to recommend remediation strategies that balance risk reduction with operational needs
- Provide broad expertise across vulnerability management, privacy, incident response, governance, risk and compliance, enterprise security strategy, and security architecture
- Lead and coordinate cyber security initiatives by shaping plans, driving execution, and communicating status to technical stakeholders and leadership
- Mentor teammates through technical guidance, supporting development, and strengthening consistency in application security work
- Direct vulnerability identification, assessment, prioritization, and remediation across code, infrastructure, and applications, including secure development practices, automation, and risk reduction
- Act as a trusted technical escalation point for application and vulnerability management; drive remediation and influence technical decisions across multiple initiatives
- Provide leadership continuity and decision support when the manager is out of office
Requirements
- Preferred: Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field
- Minimum: 6–8 years of related experience
- Strong understanding of the vulnerability management lifecycle, governance, and risk-based prioritization in enterprise environments
- Deep familiarity with application security and risk frameworks, including ISO 27001-2, ISO 31000, PCI DSS, OWASP ASVS, NIST frameworks, ITIL, COBIT, CVSSv4, and MITRE ATT&CK
- Hands-on experience with vulnerability management tools: Qualys, Tenable, Snyk, and TruffleHog Pro
- Experience working in Agile development environments
- Strong understanding of operating systems: Windows, Unix, and MacOS; cloud concepts including secure build images, ephemeral workloads, and cloud patching; plus networking fundamentals
- Broad application development background across full-stack and mobile development for iOS and Android
- Experience building metrics, dashboards, and risk reporting for technical teams and leadership
- Experience with API security scanning and application security testing approaches
- Ability to communicate complex technical issues clearly to engineers, senior leaders, and business stakeholders
- Broad knowledge of cyber security practices including secure configuration management, data protection and privacy, security monitoring, incident response, governance, risk and compliance, patch management, and enterprise security architecture
- Strong written and verbal communication skills to influence senior management, technical experts, and cross-functional stakeholders
- Demonstrated ability to analyze issues strategically and analytically while balancing technical depth with practical business outcomes
- Advanced understanding of the use of AI in application development
- Experience working in cloud and container environments
- Penetration testing and application security experience
- Automation and scripting experience, such as Python or Bash
- Deep experience in enterprise application development
Technologies
- ISO 27001-2, ISO 31000, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, OWASP ASVS, MITRE ATT&CK
- Qualys, Tenable, Snyk, TruffleHog Pro
- Agile, Windows, Unix, MacOS, iOS, Android, Python, Bash
Benefits
- Comprehensive medical, dental, vision coverage
- Life insurance
- Disability coverage for positions working more than 30 hours per week
- Retirement program with generous matching employer contributions
- Paid vacation
- Sick days and holidays
- Paid personal and maternity/parental leaves
- Employee and Family Assistance Program
- Annual incentive plan participation
- Long-term incentive plan participation
Location: Deerfield, IL (onsite)
Salary: USD 91,200 - 143,220 per yearly