> Markdown version of [/jobs/ext/1670213-application-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1670213-application-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Cybersecurity Engineer - **Company:** ALLIANCE SOURCING NETWORK - **Location:** Chicago, IL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Cloud Platform System, Delivery Pipeline, Software Security, Infrastructure as Code (IaC), GWAPT, Information Technology, Devsecops, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.dice.com/job-detail/5681cb91-5af1-4c47-8701-63d71bb275b0 ## About the Role * Application Security: Deep understanding of vulnerabilities and remediation (OWASP, CWE/CVE, SANS 25). Broad Security Knowledge: Experience with enterprise security architecture, threat modeling, vulnerability assessment, risk analysis, defense in depth, SDLC, IAM, and API security. Cloud Security: Hands-on experience with MS Azure and/or AWS. Development Experience: Proficiency in one or more languages (Java, Python, .Net, JS, or equivalent). Automation & Scripting: Implementation of automation to streamline security processes. Certifications: Professional certification such as CISSP, CCSP, GWAPT, GWEB, or AWS Security Specialty. Technical Skills (Desired) Professional certifications (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB, etc.). Strong understanding and experience with information security technologies. AI Fluency is preferred., Excellent written and verbal communication skills. Demonstrated ability to communicate highly technical security concepts to non-security audiences. Ability to coordinate multiple teams in accomplishing process review and improvement., Bachelor's Degree in computer science or a related field with 8+ years in information security. Master's Degree with 6+ years of experience. ## Description The Lead Cybersecurity Engineer will be a key partner to development teams, focusing on integrating security into the software development lifecycle (SDLC). This role is responsible for the security engineering of cloud environments (AWS, Azure) and vulnerability management for both Infrastructure as Code (IaC) and application code. Key Contributions: Security by Design: Implementing and consulting on secure development practices. DevSecOps Integration: Integrating security into DevOps pipelines. Vulnerability Management: Managing and tracking security risks to remediation. Agile Collaboration: Working closely with development teams in an agile environment. o Analyzing, validating, and communicating on security defects from tools like CodeQL, Rapid7, penetration testing, and bug bounties. o Acting as a partner to software engineers by providing accurate information on vulnerabilities and remediation strategies. o Serving as a trusted advisor ("best friend") to software engineers, architects, and product owners. o Providing context-aware guidance to help teams make secure decisions and document their architectures. o Navigating review and approval processes for new features and issue remediation. o Enabling and monitoring automated defect detection tools (e.g., CodeQL, Rapid7) at the repository or application level. o Ensuring tools are configured and running according to established processes. 8. Security Test Onboarding & Management: o Collecting and communicating scope and access information for penetration testing. o Handling the output of these assessments through the defect management process. Accountable for a dedicated set of applications and works directly with their respective development teams. Part of a larger security engineering team that sets standards and best practices for collaboration with developers. Helps development teams identify security gaps and assists in creating solutions to ensure services are compliant with enterprise security requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)