> Markdown version of [/jobs/ext/3050518-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3050518-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Caterpillar - **Location:** Peoria, IL, United States - **Experience:** Expert - **Salary:** $112,710.0 - $183,140.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Software Bug Management, CompTIA Security+, Cyber Security, DevOps, Open Web Application Security, Systems Development Life Cycle, Salesforce.Com, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Web Applications, Google Cloud, Enterprise Software Applications, Cloud Platform System, Software Security, Restful APIs, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3402966795&tx=KJ2929FFP&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Decision Making and Critical Thinking: Knowledge of the decision-making process and associated tools and techniques; ability to accurately analyze situations and reach productive decisions based on informed judgment. * Effective Communications: Understanding of effective communication concepts, tools and techniques; ability to effectively transmit, receive, and accurately interpret ideas, information, and needs through the application of appropriate communication behaviors. * Software Development Life Cycle: Knowledge of software development life cycle; ability to use a structured methodology for delivering and managing new or enhanced software products to the marketplace. * Software Integration Engineering : Knowledge of software integration processes and functions; ability to design, develop and maintain interfaces and linkage to alternative platforms and software packages. * Software Product Design/Architecture: Knowledge of software product design; ability to convert market requirements into the software product design. Top Candidates Will Have: * Experience as a software engineer (in any language or framework); prefer a focus on cybersecurity related issues * Experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect. * Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc. * Experience leveraging one or more of the following resources to support secure coding and decision-making: * OWASP Top 10 * MITRE Common Weakness Enumeration (CWE) Top 25 * OWASP Application Security Verification Standard (ASVS) * Other industry-standard best practice guides or frameworks * Experience building or supporting web applications and API's including Single Page Applications (SPA) and RESTful APIs. * Professional certifications in either cybersecurity or software engineering, such as: * Associate or Professional-level certifications from a major cloud provider (AWS, Azure, GCP, or Salesforce). * CompTIA Security+, Cloud+, CCSK, and/or other cybersecurity certifications. * ISC2 Certified Software Lifecycle Professional (CSLP) ## Description Join the Cybersecurity team of Cat Digital and build software solutions that drive automation and security into the application development lifecycle. You will have deep integration with applications as they move from an idea into a solution, integrating Security and DevOps practices and enabling delivery for Caterpillar Digital Applications. Be a part of the team that is using innovative solutions and methods to securely enable, build, and deploy modern applications and software., As a Senior Application Security Engineer, you will work as a technical engineer within a portfolio of related applications to guide software engineers on cybersecurity issues, influence security and prioritization decisions at the bug or story level, and act a trusted partner in their mission to deliver solutions securely. * Security Defect Management - Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it. * Engineering Consultin g - Serving as a "best friend" to software engineers, architects, product owners, and leaders, provide contextually-aware guidance to help these groups make good decisions, document those decisions and resulting architectures, and navigate relevant review & approval processes (where necessary) when implementing new features and remediating existing issues. * Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process. * Security Test Onboarding & Management - Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process. * Maturity Measurement - Consulting with software engineers on practices which will improve their application's security maturity according to scorecards and maturity models established by Cat Digital. * Correction of Error - Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across Cat Digital avoid similar mistakes in their own applications. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)