Security Engineer III - Application Security

BOK Financial Corporation
Tulsa, United States of America
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Tulsa, United States of America

Tech stack

Microsoft Excel
API
Artificial Intelligence
Amazon Web Services (AWS)
Data analysis
Azure
Bash
Computer Security
System Configuration
Continuous Integration
Information Leak Prevention
DevOps
Elasticsearch
Python
Key Management
Open Web Application Security
Powershell
Systems Development Life Cycle
Security Information and Event Management
Transport Layer Security
Google Cloud Platform
Spring Cloud
Large Language Models
Software Security
Information Technology
Hashicorp
Splunk
Static Application Security Testing
Vulnerability Analysis
Go
Dynamic Application Security Testing

Job description

As an Application Security Engineer III, you will play a key leadership role in advancing BOKF's application security posture. You will drive the implementation and optimization of security capabilities across the Application Protection portfolio, including WAF, API security, DAST, SAST, IaC, SCA, and SIEM/SOAR.

In this role, you will lead threat modeling and vulnerability assessments for internally developed applications and APIs, design and implement custom security policies and controls, and guide the response to application-layer incidents. You will serve as a subject matter expert, mentoring junior engineers while contributing to the design of advanced detection and prevention strategies.

You will stay ahead of evolving threats-including OWASP Top 10 risks, API vulnerabilities, and software supply-chain attacks-and apply that knowledge to strengthen defenses. The role also includes performing forensic and root cause analysis, partnering with risk, legal, and compliance teams to support regulatory requirements, and developing custom code to enhance application security capabilities.

As BOKF embraces AI-enabled development and security tooling, you will leverage approved AI capabilities to accelerate workflows while ensuring accuracy, safeguarding sensitive data, and maintaining strong governance. You will also assess and mitigate risks associated with AI/LLM-enabled applications and third-party services, including prompt injection, data leakage, and insecure integrations, while helping implement effective monitoring and controls.

Team Culture

Our team thrives in a dynamic and collaborative environment where curiosity, ownership, and continuous improvement are foundational. We encourage innovative thinking, open knowledge-sharing, and proactive problem-solving.

By working together to address complex security challenges, team members are empowered to expand their expertise, influence meaningful outcomes, and shape the future of application security at BOKF. Our strong partnerships across the organization and commitment to excellence ensure we remain resilient and forward-looking.

How You'll Spend Your Time

  • You will lead the design and implementation of advanced application security architectures and controls across the SDLC, including secure CI/CD guardrails.
  • You will conduct threat modeling and in-depth vulnerability assessments for applications and APIs, partnering with stakeholders to prioritize remediation.
  • You will develop, tune, and maintain application security controls, including WAF/API policies and DAST/SAST/SCA/IaC scanning capabilities.
  • You will oversee application-layer incident response, including triage, containment, and forensic/root cause analysis.
  • You will evaluate and define security controls for AI/LLM-enabled features and integrations, including risks related to data protection, model trust, and misuse scenarios.
  • You will leverage AI-enabled security tools to enhance detection, analysis, and response while validating outputs and protecting sensitive data.
  • You will provide technical leadership by mentoring team members and leading initiatives through successful delivery with minimal oversight.
  • You may perform other duties as assigned.

Requirements

This role typically requires a Bachelor's degree in Information Security, Computer Science, or a related field, along with 5+ years of experience in Cyber Security or a related technical discipline; alternatively, 7+ years of relevant experience may be considered in lieu of a degree. A Master's degree, CISSP, or equivalent certifications are preferred., * Advanced expertise in configuring and optimizing application security tools (WAF, API security, DAST, SAST, IaC, SCA, SIEM/SOAR) to deliver effective and scalable protection.

  • Strong understanding of application threat intelligence and the ability to identify and mitigate both known and emerging attack vectors.
  • Proven experience leading application security incident response, including triage, containment, and root cause analysis.
  • Demonstrated ability to lead cross-functional initiatives involving development, DevOps, and risk teams.
  • Excellent analytical and problem-solving skills, with a structured approach to complex challenges.
  • Advanced scripting capabilities (e.g., Python, Bash, Go, PowerShell) to automate security processes and workflows.
  • Experience securing CI/CD pipelines and cloud-native applications across AWS, Azure, and GCP.
  • Strong knowledge of cryptography, TLS, secrets management (e.g., HashiCorp Vault), and key lifecycle management.
  • Ability to clearly communicate complex security concepts to both technical and non-technical stakeholders.
  • Experience leveraging data analysis tools (e.g., Splunk, Elasticsearch, Excel) to drive insights and metrics.
  • Deep understanding of application risk management principles and mitigation strategies.
  • Familiarity with AI/LLM security risks (e.g., prompt injection, data leakage, supply-chain risk) and practical implementation of controls.
  • Ability to use AI-assisted tools responsibly to enhance productivity while validating results and protecting sensitive information.

Benefits & conditions

Investing in our talent and building a great workplace is a top priority for us.

  • Empowered employees
  • Award-winning culture
  • Community commitment

BOK Financial Corporation Group adheres to state specific pay transparency requirements. In order to be considered for a position with BOK Financial Corporation Group, you must complete the entire application process, which includes answering all prescreening questions and providing your eSignature on or before the application deadline.

Base salary range explanation:

The base salary range represents an average range for this position. Actual offers to be determined based on the candidate's qualifications, skills, experience and education. See job details for salary range and bonus type.

About the company

BOK Financial Corporation Group includes BOKF, NA; BOK Financial Securities, Inc. and BOK Financial Private Wealth, Inc. BOKF, NA operates TransFund and Cavanal Hill Investment Management, Inc. BOKF, NA operates banking divisions: Bank of Albuquerque; Bank of Oklahoma; Bank of Texas and BOK Financial®., Our team operates at the forefront of innovation, vigilance, and strategic risk management. We combine deep industry expertise with advanced analytics and a disciplined approach to proactively identify and mitigate emerging threats across the organization. Through continuous monitoring, comprehensive assessments, and strong cross-functional partnerships, we deliver tailored security solutions that strengthen BOKF's resilience. We are passionate about advancing security maturity across the enterprise-collaborating closely with teams to provide actionable insights, champion best practices, and enhance controls. Our work empowers BOKF to pursue its strategic goals with confidence in an evolving threat landscape., For more than a century, BOK Financial Corporation has helped fuel the success of clients and communities. Since our humble beginnings in Tulsa, Oklahoma, we've grown into a diversified financial services company that serves consumers, small businesses and international corporations-and everything in between. Facts: * Operations focused in an eight-state footprint * 5,000 team members * $53.8 billion in assets* * $123.6 billion in assets under management and administration* * $9.3 million donated to local nonprofits in 2025 * 56,000 volunteer hours by our employees in 2025 *At March 31, 2026 Nearest Major Market: Tulsa

Apply for this position