Security Engineer, Application Security
Chicago, Cook County, Illinois, 60290, USA
Listed on 2026-07-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Staff Security Engineer, Application Security
Chicago or Remote*
We are seeking a Staff Security Engineer to help scale and mature our security program. This highly hands‑on role involves owning key security domains and initiatives, working closely with engineering to ensure systems are secure by design, and driving impactful automation and secure developer practices.
In this role you will- Own key security domains such as vulnerability management, application security, API security, and supply chain security.
- Improve security coverage, prioritization, and remediation workflows.
- Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
- Provide actionable, pragmatic guidance that helps teams ship securely.
- Develop and improve security tooling and automation to reduce manual effort.
- Implement and tune tools for SAST, SCA, DAST, dependency security, and container security.
- Leverage AI/LLMs where appropriate to improve triage, detection, and review processes.
- Triage and prioritize vulnerabilities using risk‑based approaches.
- Partner with teams to ensure timely remediation of critical issues.
- Help define and improve SLAs, metrics, and reporting.
- Conduct threat modeling, design reviews, and security assessments.
- Contribute to incident response and post‑mortems for security events.
- Identify and help remediate systemic risks.
- 7+ years of experience in Application Security, Product Security, or Security Engineering.
- Strong hands‑on experience with threat modeling and secure design.
- Experience with vulnerability management and application security tooling.
- Experience working in cloud‑native environments such as AWS and GCP.
- Experience integrating security into CI/CD pipelines and developer workflows.
- Ability to write code in Python, Go, or similar languages for automation and tooling.
- Strong ability to work cross‑functionally with engineering teams.
- Experience scaling security in a high‑growth or late‑stage startup.
- Familiarity with AI‑driven security workflows or automation.
- Background in API security, data protection, or multi‑tenant systems.
- Experience with bug bounty programs and penetration testing.
- Security certifications such as CISSP.
The salary range for this role is $ – $ USD, with an annual target bonus of 12%. Bonus performance is split 50% individual and 50% company/team.
Additional compensation includes a 401(k) plan with a company match up to 3.5% of employee contributions, 23 days of paid time off per year (plus possible additional days), and seven paid holidays.
LocationThis role is based in Chicago, IL. Remote flexibility may be considered for exceptional candidates in selected states.
Hybrid- In‑office Tuesday through Thursday; remote work Monday and Friday.
- 20 additional flex remote days annually.
- 5 company‑wide office‑optional weeks tied to major holidays.
- Generous PTO.
- 7 paid holidays annually plus 5 conditional holidays.
- 1 service day annually.
- 401(k) with 3.5% company match.
- Life and disability insurance covered 100% by Ninja Trader.
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity workplace.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).