обновлено 6 дней назад
Principal Application Security Engineer (Cybersecurity)
163 625 - 211 750$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Application Security Engineer (Cybersecurity): Providing senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across a hybrid engineering ecosystem with an accent on Kubernetes, API security, and DevSecOps integration. Focus on defining secure-by-default architecture patterns, driving vulnerability management strategies, and securing AI implementations within a high-stakes financial infrastructure environment.
Location: Chicago, Illinois, United States; four days in office. Candidates must be legally authorized to work in the United States without current or future employer sponsorship.
Salary: $163,625–$211,750 base salary annually, with potential annual incentive compensation and long-term equity participation.
Company
provides financial market infrastructure, tradable products, and trading, clearing, and investment solutions.
What you will do
- Lead secure architecture reviews and threat modeling for microservices, APIs, Kubernetes workloads, and major system changes.
- Define application and API security standards covering authentication, authorization, input validation, and common vulnerability classes.
- Set security direction for Kubernetes clusters, containers, RBAC, namespace isolation, network policies, secrets, and platform guardrails.
- Integrate SAST, SCA, secret scanning, container scanning, and IaC scanning into scalable CI/CD workflows.
- Own risk-based software vulnerability management, remediation priorities, service levels, metrics, and incident follow-through.
- Establish secure adoption patterns, governance, permissions, and data boundaries for AI-enabled development and security capabilities.
Requirements
- 12+ years of experience in application security, product security, or software engineering, including architecture and security leadership in complex production environments.
- Production software development experience and the ability to read, write, and review code in a modern backend language such as C++, Go, Java, C#, Python, or Node.
- Strong knowledge of Kubernetes security primitives, container build practices, and hybrid public-cloud and on-premises Kubernetes environments.
- Hands-on experience integrating DevSecOps security tooling into CI/CD pipelines.
- Exceptional communication, influence, and technical leadership skills across engineering, platform, and security stakeholders.
- U.S. work authorization without employer visa sponsorship is required.
Nice to have
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- CSSLP, CKS, OSCP, AWS Security Specialty, or Azure Security Specialty certification.
Culture & Benefits
- Four days per week in the Chicago office to support team connection and collaboration.
- Medical, prescription drug, dental, vision, life, and AD&D coverage.
- 401(k) or pension company match and retirement savings plan.
- Spending accounts, employee stock purchase plan, paid time off, and additional voluntary benefits.
- Leadership programs, career development initiatives, and internal mobility opportunities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Application Security Engineer (AI)
100 000 - 130 000$
9 дней назад
Staff Security Engineer (AI)
235 000 - 305 000$
6 дней назад
Secure Software Engineer (AI)
100 000 - 150 000$
6 дней назад
Security Engineer (Application Security)
120 000 - 140 000$
Roblox
6 дней назад
Senior Security Software Engineer, Application Security
269 170 - 326 060$
Datadog
9 дней назад
Senior Software Engineer - Source Security (CI/CD Security)
192 000 - 240 000$