×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer DevSecOps and CICD

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: 3Core Systems, Inc
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 120000 - 150000 USD Yearly USD 120000.00 150000.00 YEAR
Job Description & How to Apply Below

Job Title:

Senior Application Security Engineer Dev Sec Ops  and CICD

Location:

Remote, USA Must Have Skills/Attributes:
Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability Experience Desired:
Secure SDLC, Dev Sec Ops , Agile, and Scrum methodologies (5-7 yrs);
Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)

Required Minimum Education:

Bachelor’s Degree

Preferred Education:

Master’s Degree

Job Description
  • *** Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO**
    *
Education Requirements:
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Preferred Education:
  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Required Skills for the Cybersecurity Engineer:
  • -5-7 years of hands-on application security/Dev Sec Ops  experience
  • - Secure SDLC, Dev Sec Ops , Agile, and Scrum methodologies — strong working understanding
  • - Security tooling:
    Burp Suite, Git Hub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
  • - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
  • - Cloud security, identity and access management, and modern application architectures
  • - Safe and effective use of AI-assisted development and security tools
  • - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
  • - Security metrics, coverage reporting, and executive dashboard development
  • - Excellent communication, stakeholder management, presentation, and documentation skills
  • - Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
  • - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, Dev Ops, product owners, and business stakeholders
  • - Coaching and knowledge sharing — champions a security-first culture
  • - Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
  • - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
  • - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
  • - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
  • - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
  • - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown:
  • Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
  • Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
  • Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
  • Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
  • Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
  • Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks find value in our e-mail notifications as you continue to consider options for your professional career.
#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary