Cybersecurity Engineer IV Application Security

The Aes Group, Inc
Chicago, IL, United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$187,200.0 - $193,440.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Applications Architecture Code Review Encodings Cyber Security Computer Programming Continuous Integration Corona (Software Development Kit) Github Software Maintenance Systems Development Life Cycle Secure Coding
+10 more
Software Engineering Systems Integration Software Vulnerability Management Web Applications Software Security Information Technology Software Version Control Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

Seeking an experienced Cybersecurity Engineer IV specializing in Application Security to join its Security Engineering team. This is not a general cybersecurity role the primary focus is embedding security throughout the Software Development Lifecycle (SDLC) while partnering directly with software engineering teams.

The selected candidate will support external-facing, revenue-generating eCommerce and web applications, ensuring security is integrated from application design through deployment and production. This position is ideal for security professionals who have experience working alongside developers to build secure applications rather than performing security assessments after development is complete.

About the Team

The Security Engineering team partners closely with clients eCommerce Development organization to integrate security into every phase of application development. Engineers work directly with software developers, architects, and technical leaders to improve secure coding practices, identify vulnerabilities early, and implement scalable security solutions throughout the SDLC., * Partner with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC).

  • Embed Security by Design principles into application architecture and development.
  • Review and improve application security practices across enterprise web applications.
  • Identify, analyze, prioritize, and help remediate application security vulnerabilities.
  • Utilize and support security testing throughout the SDLC, including Static and Dynamic Application Security Testing (SAST/DAST).
  • Analyze application code when necessary to identify security risks and recommend remediation.
  • Collaborate with developers to implement secure coding practices.
  • Communicate security risks, findings, and recommendations to software engineers, technical leadership, and business stakeholders.
  • Provide guidance on secure software development, application security governance, and security best practices.
  • Support security integration within CI/CD pipelines and modern development workflows.
  • Educate development teams on application security principles and secure development methodologies.

Requirements

  • Software Development Lifecycle (SDLC)
  • Secure Software Development
  • SAST & DAST
  • Security Governance
  • DevSecOps / CI-CD Security
  • Vulnerability Management
  • Secure Coding Practices
  • Software Development Background
  • Strong Communication & Stakeholder Management, * Bachelor’s degree in Computer Science or a related technical field with 8+ years of Information Security experience OR

  • Master’s degree with 6+ years of Information Security experience

Senior candidates with significant Application Security experience are encouraged to apply., * Strong hands-on experience in Application Security.

  • Experience integrating security into modern Software Development Lifecycles.
  • Knowledge of secure software development practices.
  • Experience with application security governance.

Software Development Lifecycle (Highest Priority)

Candidates must demonstrate strong understanding of the complete SDLC, including:

  • Requirements gathering
  • Application architecture
  • Software development
  • Testing
  • Deployment
  • Production support
  • Application maintenance

Previous software development experience is highly desirable, as this role partners directly with development teams throughout the development lifecycle.

Security Testing

Experience with application security testing methodologies such as:

  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)

Experience with any commercial security testing platform is acceptable.

Software Development

Preferred experience with:

  • Reading and understanding application source code
  • Working alongside software developers
  • Secure coding practices
  • Security integration within CI/CD pipelines

Source Control

Experience with GitHub or similar source control platforms.

Preferred Qualifications

  • Software development experience
  • Ability to review and analyze application source code
  • AI programming or AI model experience
  • Experience utilizing AI tools within software development
  • Familiarity with secure DevSecOps practices

Candidates with AI experience will receive additional consideration when technical qualifications are otherwise comparable.

Required Soft Skills

  • Excellent written and verbal communication skills
  • Ability to explain complex cybersecurity concepts to technical and non-technical audiences
  • Strong collaboration and stakeholder management skills
  • Experience working with software engineers, architects, and technical leadership
  • Strong presentation and interpersonal skills
  • Ability to influence security decisions across multiple teams, Successful candidates will have experience:
  • Embedding security throughout the Software Development Lifecycle
  • Working directly with software engineering teams
  • Supporting secure application development
  • Integrating security into CI/CD pipelines
  • Performing application security assessments
  • Helping developers understand and remediate vulnerabilities
  • Securing customer-facing web and eCommerce applications, Required
  • Strong Application Security experience
  • Deep understanding of the Software Development Lifecycle (SDLC)
  • Secure software development expertise
  • Experience with SAST and DAST
  • Security governance experience
  • Ability to work directly with software developers
  • Excellent communication and stakeholder management skills

Preferred

  • Software development background
  • Source code review and analysis experience
  • GitHub experience
  • AI programming or AI model experience
  • DevSecOps experience

About the company

The AES Group is a premier technology and engineering consulting company that has been bringing businesses and talent together for over 20 years to deliver innovative solutions that have the greatest positive impact on society. AES has helped over 40 business enterprises, including Fortune 500 companies, engage their customers, empower their employees, and transform their business operations with the power of cloud, data, AI, engineering, and other emerging technologies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:17 min

Optimizing character encoding with Kim variable byte encoding

Douglas Crockford Douglas Crockford · WWC 2024

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all