Application Cybersecurity Engineer

ALLIANCE SOURCING NETWORK
Chicago, IL, United States
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Agile Methodology Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Security Cyber Security Identity and Access Management Python (Programming Language) Open Web Application Security
+13 more
Systems Development Life Cycle Secure Coding Software Engineering Systems Integration Software Vulnerability Management Cloud Platform System Delivery Pipeline Software Security Infrastructure as Code (IaC) GWAPT Information Technology Devsecops Vulnerability Analysis

Job description

The Lead Cybersecurity Engineer will be a key partner to development teams, focusing on integrating security into the software development lifecycle (SDLC). This role is responsible for the security engineering of cloud environments (AWS, Azure) and vulnerability management for both Infrastructure as Code (IaC) and application code. Key Contributions: Security by Design: Implementing and consulting on secure development practices. DevSecOps Integration: Integrating security into DevOps pipelines. Vulnerability Management: Managing and tracking security risks to remediation. Agile Collaboration: Working closely with development teams in an agile environment. o Analyzing, validating, and communicating on security defects from tools like CodeQL, Rapid7, penetration testing, and bug bounties. o Acting as a partner to software engineers by providing accurate information on vulnerabilities and remediation strategies. o Serving as a trusted advisor (ā€œbest friendā€) to software engineers, architects, and product owners. o Providing context-aware guidance to help teams make secure decisions and document their architectures. o Navigating review and approval processes for new features and issue remediation. o Enabling and monitoring automated defect detection tools (e.g., CodeQL, Rapid7) at the repository or application level. o Ensuring tools are configured and running according to established processes.

  1. Security Test Onboarding & Management: o Collecting and communicating scope and access information for penetration testing. o Handling the output of these assessments through the defect management process. Accountable for a dedicated set of applications and works directly with their respective development teams. Part of a larger security engineering team that sets standards and best practices for collaboration with developers. Helps development teams identify security gaps and assists in creating solutions to ensure services are compliant with enterprise security requirements.

Requirements

  • Application Security: Deep understanding of vulnerabilities and remediation (OWASP, CWE/CVE, SANS 25). Broad Security Knowledge: Experience with enterprise security architecture, threat modeling, vulnerability assessment, risk analysis, defense in depth, SDLC, IAM, and API security. Cloud Security: Hands-on experience with MS Azure and/or AWS. Development Experience: Proficiency in one or more languages (Java, Python, .Net, JS, or equivalent). Automation & Scripting: Implementation of automation to streamline security processes. Certifications: Professional certification such as CISSP, CCSP, GWAPT, GWEB, or AWS Security Specialty. Technical Skills (Desired) Professional certifications (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB, etc.). Strong understanding and experience with information security technologies. AI Fluency is preferred., Excellent written and verbal communication skills. Demonstrated ability to communicate highly technical security concepts to non-security audiences. Ability to coordinate multiple teams in accomplishing process review and improvement., Bachelor’s Degree in computer science or a related field with 8+ years in information security. Master’s Degree with 6+ years of experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa Ā· LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil Ā· LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca Ā· WWC 2021

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova Ā· LIVE

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross Ā· WWC Europe 2026

Videos

See all

Related articles

See all