> Markdown version of [/jobs/ext/2565515-it-systems-engineer-sr-application-security](https://www.wearedevelopers.com/jobs/ext/2565515-it-systems-engineer-sr-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Systems Engineer Sr - Application Security - **Company:** Ann Inc. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $93,600.0 - $154,440.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Services, Automation of Tests, Cyber Security, Information Systems, Databases, Middleware, File Transfer, Web Servers, Identity and Access Management, Network Security, OAuth, Open Web Application Security, Data Streaming, Systems Integration, Software Vulnerability Management, Wireless Access Point, Enterprise Software Applications, Software Security, GWAPT, Information Technology, Metasploit, Integration Frameworks, CIS Benchmarks, Qualys, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ac89a8074b1f8e7f ## About the Role * Strong understanding of application-layer attack paths including credential compromise, integration abuse, API exploitation, and external exposure risks. * Deep knowledge of authentication and authorization models such as SSO, OAuth, service accounts, and secure integration patterns. * Expertise in encryption and data protection across application and integration workflows. * Experience in complex enterprise environments with large commercial application portfolios. * Strong familiarity with OWASP Top 10, common exploitation techniques, IAM concepts, and secrets/credential lifecycle management. * Knowledge of CIS Controls and Benchmarks as they apply to application security. * Experience with vulnerability scanning and testing tools such as Qualys, Qualys WAS, Metasploit, SAST/DAST, and configuration/exposure analysis tools. * Understanding of network and edge security including WAFs, firewalls, segmentation, and internet-facing exposure. * Ability to drive cross-functional remediation across technical and non-technical stakeholders. * Strong analytical and prioritization skills in a risk-based environment. * Excellent communication skills with the ability to translate technical risk into business impact., * Bachelor's Degree in Computer Science, Information Security, Information Systems, or related field, or equivalent work experience. * 3-7+ years of experience in application security, cybersecurity, or enterprise application support. * Experience working in large enterprise environments with multiple commercial applications and integrations preferred. * Experience within a healthcare provider environment is desirable. * Security certifications such as CISSP, CSSLP, GWAPT, CASE, CEH, OSCP or equivalent are beneficial but not required. Education Bachelor's Degree ## Description TheApplication Security Engineer is a hands-on technical role responsible for implementing, validating, and maintaining security controls across all tiers of the hospital's application stack, including database, middleware, web server, API, and presentation layers. The engineer ensures applications, integrations, and supporting components are securely configured, monitored, and aligned with enterprise security standards. This role works directly with infrastructure, vulnerability management, and vendors to identify, remediate, and prevent application-layer risks. The engineer performs hands-on validation, troubleshooting, and configuration enforcement to ensure secure-by-default application deployments across the enterprise. Essential Job Functions: * Serve as the central authority for application and integration risk by applying consistent security standards across a portfolio of more than 250 commercial and third-party applications. * Identify and reduce application-layer risk across third-party applications, APIs, system integrations, automated file transfers, and service accounts. * Interface with application vendors, application owners, and other departments as needed. * Assess and secure internet-facing applications by identifying exposed access points and prioritizing remediation of high-risk entry vectors. * Enforce standardized security controls for authentication, authorization, credential and secret management, encryption, and secure communication patterns. * Partner with application owners and vendors to eliminate insecure configurations, excessive access, credential misuse, and other security issues. * Evaluate and secure applications throughout their lifecycle including procurement, implementation, integration, and ongoing operations. * Support third-party risk management by assessing vendor integrations, data flow methods, and exposure points. * Drive remediation of application vulnerabilities identified through vulnerability scanning (e.g., Qualys), configuration reviews, and security testing of externally facing systems. * Improve visibility and governance over application security posture by tracking exposure trends, risk reduction, and remediation progress. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)