Job Summary:
BOK Financial is a stable and financially strong organization focused on innovation and risk management. They are seeking an Application Security Engineer III to lead the enhancement of application security, implement security capabilities, and mentor junior engineers while ensuring compliance with regulatory requirements.
Responsibilities:
• You will lead the design and implementation of advanced application security architectures and controls across the SDLC, including secure CI/CD guardrails.
• You will conduct threat modeling and in-depth vulnerability assessments for applications and APIs, partnering with stakeholders to prioritize remediation.
• You will develop, tune, and maintain application security controls, including WAF/API policies and DAST/SAST/SCA/IaC scanning capabilities.
• You will oversee application-layer incident response, including triage, containment, and forensic/root cause analysis.
• You will evaluate and define security controls for AI/LLM-enabled features and integrations, including risks related to data protection, model trust, and misuse scenarios.
• You will leverage AI-enabled security tools to enhance detection, analysis, and response while validating outputs and protecting sensitive data.
• You will provide technical leadership by mentoring team members and leading initiatives through successful delivery with minimal oversight.
• You may perform other duties as assigned.
Qualifications:
Required:
• Bachelor’s degree in Information Security, Computer Science, or a related field
• 5+ years of experience in Cyber Security or a related technical discipline
• 7+ years of relevant experience may be considered in lieu of a degree
• Advanced expertise in configuring and optimizing application security tools (WAF, API security, DAST, SAST, IaC, SCA, SIEM/SOAR)
• Strong understanding of application threat intelligence and the ability to identify and mitigate both known and emerging attack vectors
• Proven experience leading application security incident response, including triage, containment, and root cause analysis
• Demonstrated ability to lead cross-functional initiatives involving development, DevOps, and risk teams
• Excellent analytical and problem-solving skills, with a structured approach to complex challenges
• Advanced scripting capabilities (e.g., Python, Bash, Go, PowerShell) to automate security processes and workflows
• Experience securing CI/CD pipelines and cloud-native applications across AWS, Azure, and GCP
• Strong knowledge of cryptography, TLS, secrets management (e.g., HashiCorp Vault), and key lifecycle management
• Ability to clearly communicate complex security concepts to both technical and non-technical stakeholders
• Experience leveraging data analysis tools (e.g., Splunk, Elasticsearch, Excel) to drive insights and metrics
• Deep understanding of application risk management principles and mitigation strategies
• Familiarity with AI/LLM security risks (e.g., prompt injection, data leakage, supply-chain risk) and practical implementation of controls
• Ability to use AI-assisted tools responsibly to enhance productivity while validating results and protecting sensitive information
Preferred:
• Master’s degree
• CISSP or equivalent certifications
Company:
BOK Financial offers financial services to consumers and businesses. Founded in 1910, the company is headquartered in Tulsa, USA, with a team of 1001-5000 employees. The company is currently Late Stage.