> Markdown version of [/jobs/ext/1928784-principal-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1928784-principal-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Application Security Engineer - **Company:** Chicago Board Options Exchange - **Location:** Chicago, IL, United States - **Salary:** $163,625.0 - $211,750.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing Security, Cyber Security, Computer Networks, Data Validation, Data Security, Software Design Patterns, Python (Programming Language), Key Management, Node.Js, Systems Development Life Cycle, Role-Based Access Control, Secure Coding, Software Engineering, Software Vulnerability Management, Software Security, Backend, Containerization, Kubernetes, Information Technology, Devsecops, Static Application Security Testing, Golang, Microservices - **Published:** August 5, 2026 - **Apply:** https://www.dice.com/job-detail/d03a59c4-b1f3-4b7b-826d-6cb6a98b74bc ## About the Role * 12+ years of experience in application security, product security, or software engineering, including significant experience shaping architecture, setting standards, and driving security outcomes across complex production environments * Experience directly writing and delivering production software as a software engineer * Bachelor's degree in Computer Science, Information Security, or related field preferred * Relevant certifications preferred (e.g., CSSLP, CKS, OSCP, AWS/Azure Security Specialty) * Proven ability to read, write, and review production-grade code in at least one modern backend language (e.g., C++, Go, Java, C#, Python, Node.js), with the judgment to guide secure engineering decisions in high-impact systems * Strong working knowledge of Kubernetes security primitives (RBAC, namespaces, service accounts, pod security) and container build practices * Hands-on experience integrating DevSecOps tooling (SAST, SCA, secret scanning, IaC/container scanning) into CI/CD pipelines * Experience securing hybrid environments with workloads running in both public cloud (EKS, AKS, GKE) and on-prem Kubernetes platforms * Exceptional communication, influence, and technical leadership skills, with a demonstrated ability to drive alignment, establish direction, and own outcomes across engineering, platform, and security stakeholders ## Description Cboe's Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem. In this role, you will partner closely with application, platform, and infrastructure teams to define secure-by-default architecture patterns, shape strategic security direction, and drive implementation of security controls throughout the software development lifecycle (SDLC) across microservices, APIs, and containerized workloads operating in both public cloud and on-premises Kubernetes environments. You will operate as a principal-level individual contributor with broad technical influence, accountable for setting direction in complex or ambiguous situations, making high-impact architectural decisions, and driving consistent security outcomes across multiple teams and platforms. This role requires deep hands-on expertise, strong systems thinking, and the ability to influence engineering practices, standards, and priorities at scale while serving as a trusted technical leader for both security and engineering stakeholders. This position reports to the Senior Manager, Application and Cloud Security. Your responsibilities will be: Application & API Security * Own secure architecture reviews and threat modeling for new systems and major changes, establishing architectural direction for Kubernetes trust boundaries, secure service-to-service communication, and API authorization models across the environment * Define, mature, and drive adoption of application and API security standards, including authentication and authorization patterns, input validation requirements, and mitigations for common vulnerability classes such as SSRF, injection, and access control flaws * Provide principal-level guidance for high-risk code and design changes, resolving complex security tradeoffs and driving remediation approaches that are durable, scalable, and aligned to engineering realities * Act as a senior technical partner to engineering leadership, influencing roadmaps, architecture decisions, and secure-by-default design patterns across the organization Kubernetes, Container & DevSecOps Security * Own Kubernetes workload security standards across multi-cluster environments, setting technical direction for RBAC, pod security controls, namespace isolation, network policies, secrets management, and platform guardrails * Establish and continuously evolve the container image security strategy, including secure base image standards, vulnerability management expectations, SBOM practices, and deployment controls that prevent risky configurations from reaching production * Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines, ensuring SAST, SCA, secret scanning, container scanning, and IaC scanning are integrated through high-signal workflows that scale across engineering teams with minimal developer friction Software Vulnerability Management & Security Enablement * Own the strategy for risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service level expectations, and metrics that demonstrate measurable reduction in security risk over time * Develop and champion secure coding guidance, reusable security patterns, and enablement programs that raise engineering capability and create lasting improvements in how teams design and build software * Lead security design support during incident response and post-incident follow-through, translating lessons learned into durable architectural, control, and guardrail improvements that prevent recurrence AI Implementation Security * Own the secure adoption of AI-enabled development and security capabilities, establishing patterns and guardrails for secure code review, automated assessments, and process improvements throughout the SDLC. * Provide principal-level architecture and risk guidance for AI implementations and integrations, shaping secure design decisions, control expectations, and review practices for emerging use cases. * Drive governance and technical controls to define, monitor, and enforce data boundaries, permissions, and approved usage patterns for AI-related data access., At Cboe, we are committed to providing a competitive, transparent, and market-informed total rewards program. The anticipated base salary range for this role is $163,625-$211,750, with actual compensation determined by job-related factors such as skills, relevant experience, education, internal alignment, and location. This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Super scaling for the Super Bowl: How to survive 30 million users hitting your backend in 30 minutes](https://www.wearedevelopers.com/videos/100356-super-scaling-for-the-super-bowl-how-to-survive-30-million-users-hitting-your-backend-in-30-minutes) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)