> Markdown version of [/jobs/ext/1264993-engineer-application-security](https://www.wearedevelopers.com/jobs/ext/1264993-engineer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineer, Application Security - **Company:** Cboe Exchange, Inc. - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Salary:** $102,850.0 - $133,100.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), C Sharp (Programming Language), Cyber Security, Continuous Integration, Python (Programming Language), Node.Js, Role-Based Access Control, Secure Coding, Software Engineering, Software Security, Git, Kubernetes, Information Technology, Tenable Nessus, Codebase, Oracle Cloud Infrastructure, Docker, Static Application Security Testing, Golang - **Published:** July 14, 2026 - **Apply:** https://cboe.wd1.myworkdayjobs.com/External_Career_CBOE/job/Chicago-IL/Engineer--Application-Security_R-4521 ## About the Role * 2+ years of professional experience in software engineering, application security, or a closely related role * Bachelor's degree in Computer Science, Information Security, or a related field * Hands-on software development experience, including building, testing, and deploying production services and comfort reading and modifying existing codebases * Experience building and running Docker/OCI containers, with an understanding of container images, layers, and runtime behavior * Familiarity with Kubernetes, including deploying or supporting applications and working with core primitives (pods, deployments, services, ingress) and basic security concepts (RBAC, namespaces, service accounts) * Working knowledge of common web and API vulnerabilities (authentication/authorization issues, injection, SSRF, etc.) and secure coding practices * Proficiency in at least one backend programming language (e.g., Go, Java, C#, Python, Node.js) and experience with modern CI/CD workflows and Git-based development * Exposure to application security tooling such as SAST, dependency or container image scanning, or secret scanning tools * Bachelor's degree preferred ## Description Secure Development Partnership * Partner with engineering teams to improve security of containerized services running on Kubernetes * Participate in secure design reviews and threat modeling for new features, services, and APIs * Perform code-level security reviews and provide clear, actionable remediation guidance to developers Security Tooling & CI/CD Integration * Help integrate and operate security tooling in CI/CD pipelines, including SAST, dependency and container image scanning (SCA), and secret detection * Validate and triage security findings - distinguishing real risk from false positives and helping prioritize remediation based on impact Container & Kubernetes Security * Contribute to container image security practices including secure base image usage, dependency hygiene, and attack surface reduction * Assist in defining and applying secure coding and deployment standards for Kubernetes workloads, APIs, and service-to-service communication Incident Support & Growth * Support incident response and post-incident reviews by helping analyze root causes and contributing to preventative fixes, At Cboe, we are committed to providing a competitive, transparent, and market-informed total rewards program. The anticipated base salary range for this role is $102,850-$133,100, with actual compensation determined by job-related factors such as skills, relevant experience, education, internal alignment, and location. This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs. ## Related Videos - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)