
Application Security Engineer
- Chicago, IL
- Temporary
- Full-time
- Actively participate in development teams, implementing code fixes for AppSec vulnerabilities, spending a portion of time writing and reviewing remediation code to ensure secure and resilient applications.
- Perform vulnerability and penetration testing (Red - Offense), document security findings and focus on automation to aid inefficiencies with both testing and remediation of findings.
- Collaborate with developers to provide repetitive validation testing prior to production while allowing for a continuous cycle of development followed by application security assessments.
- Monitor the security community for public-facing security issues, as well as learn new tactics that can be used in testing.
- Collaborate in application projects and change management committees. Understand what is coming and how their projects can be more secure from the start.
- Follow a security review process to ensure an automated and repeatable process is managed. This can be through the use of dynamic and static code analysis resources.
- Use security standards, implementation configurations and common security frameworks to prepare for and manage bug bounty programs. Document delivery and implementation advances that meet defined service-level agreements (SLAs) and business metrics. Align with architects and development teams for a mission of secure design.
- Train developers and junior application security engineers on secure coding practices. Participate and lead security team meetings that facilitate secure design.
- Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects.
- Focus on application security that observes compliance such as Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), etc. – and privacy laws.
- Handle service and escalation tickets within SLA expectations.
- Develop security test plans from the architectural design. Identify deficiencies and make enhancements to ensure production is not impacted.
- Drive security efficiencies, enabling security team members to work on more advanced tasks.
- Conduct performance testing to stress the limitations of security solutions while ensuring business innovation and day-to-day processes are not negatively impacted.
- Bachelors Degree - Computer Science or related - Minimum
- Graduate Degree - Computer Science or related - Preferred
- 3 Years - Cybersecurity, application programming, compliance, risk management, network security engineering, threat modeling applications or related - Minimum
- 6 years - Cybersecurity, application programming, compliance, risk management, network security engineering, threat modeling applications or related
- Preferred: Security certifications GWAPT, CISSP, OSCP, or other similar
- Work from home up to 3 days a week
- Paid parental leave
- Employee discount programs
- Time off including paid personal and sick days
- 11 paid holidays
- Education reimbursement