1

Appsec Jobs in Chicago, IL (NOW HIRING)

Strong understanding of Security Operations (SecOps)/Application Security (AppSec) and modern development environments * Ability to navigate complex enterprise environments and engage with security ...

Senior Security Engineer

Chicago, IL

$118K - $161K/yr

The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting and building security practices across the ...

Senior Sales Engineer

Chicago, IL · On-site

$155 - $190/hr

Strong understanding of Security Operations (SecOps)/Application Security (AppSec) and modern development environments * Ability to navigate complex enterprise environments and engage with security ...

Senior Machine Learning Engineer

Schaumburg, IL · On-site

$120K - $159K/yr

Proactively identify and resolve issues/bugs, ensuring AppSec vulnerabilities are identified and corrected, working closely with Application Security and CCOE teams. * Drive the adoption of best ...

Senior Machine Learning Engineer

Schaumburg, IL · On-site

$120K - $159K/yr

Proactively identify and resolve issues/bugs, ensuring AppSec vulnerabilities are identified and corrected, working closely with Application Security and CCOE teams. * Drive the adoption of best ...

Proactively identify and resolve issues/bugs, ensuring AppSec vulnerabilities are identified and corrected, working closely with Application Security and CCOE teams. * Drive the adoption of best ...

Showing results 21-33

Appsec information

Is Appsec entry level?

Application security (AppSec) roles can be entry-level or require experience, depending on the position. Entry-level AppSec jobs typically focus on basic security practices, vulnerability assessments, and may require foundational knowledge of networking, coding, or security tools. More advanced roles often demand prior experience, certifications, or specialized skills.

Is application security in demand?

Application security (AppSec) professionals are in high demand due to increasing cyber threats and the widespread adoption of digital services. Organizations seek skilled experts to identify vulnerabilities, implement security measures, and ensure compliance, often requiring knowledge of security tools, coding, and certifications like CISSP or CEH.

What is the difference between Appsec vs Security Analyst?

AspectAppsecSecurity Analyst
Required CredentialsCertifications like CISSP, CEH, OSCP; knowledge of secure codingCertifications such as Security+, CISSP; threat analysis skills
Work EnvironmentDevelopment teams, secure coding practices, application testingMonitoring security systems, incident response, risk assessment
Employer & Industry UsageTech companies, software firms, organizations with application security needsAll industries, including finance, healthcare, government, focusing on security monitoring

Appsec professionals focus on securing applications through secure coding, testing, and vulnerability management, while Security Analysts monitor and respond to security threats across systems. Both roles require security certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What job categories do people searching Appsec jobs in Chicago, IL look for?

The top searched job categories for Appsec jobs in Chicago, IL are:

Infographic showing various Appsec job openings in Chicago, IL as of August 2026, with employment types broken down into 90% Full Time, 4% Part Time, and 6% Contract. Highlights an 72% Physical, 6% Hybrid, and 22% Remote job distribution.

Senior Application Security Engineer

1 point system

Chicago, IL • On-site

$60.50 - $80.75/hr

Contractor

Re-posted 18 days ago


Job description

Job Description:

Key Responsibilities

Secure Software Development Lifecycle LeadershipLead the integration of security controls into CI/CD pipelines, including static analysis, software composition analysis, dynamic testing, secrets management, and container security workflows.
Define and continuously improve application security quality gates and review procedures in alignment with Modern Engineering SDLC practices.
Lead the integration of application security controls into CI/CD pipelines, including SAST, SCA, DAST, secrets detection, and container security, with automated gating and scalable DevSecOps workflows.
Define and continuously improve application security quality gates and review processes aligned to Modern Engineering SDLC standards, including risk based thresholds, exception handling, and audit ready documentation.
Provide expert guidance on secure architectures and design patterns, advising engineering teams on security tradeoffs for cloud native, microservices, and API driven solutions 
Secure Coding Standards & GovernanceOwn the development, maintenance, and enforcement of enterprise secure coding standards.
Align secure coding governance with established Bank technology standards, including SDLC, secure development expectations, and code review procedures.
Ensure teams understand and implement secure-by-default development practices throughout all project phases.
Deep expertise with Static Application Security Testing (SAST) platforms, including scan configuration, custom rule or query tuning, results triage, risk based prioritization, and disciplined false positive suppression with documented justification. - Preferred: Experience with Checkmarx SAST / Checkmarx ONE, including custom query (CxQL) tuning and enterprise scale result management.
Strong experience with Software Composition Analysis (SCA) tools, covering open source dependency analysis, license compliance, vulnerability assessment, policy configuration, and developer focused remediation guidance. - Preferred: Hands on experience with Checkmarx SCA in CI/CD integrated environments.
Proficiency with Infrastructure as Code (IaC) security scanning across technologies such as Terraform, CloudFormation, Kubernetes, and Helm, including rule tuning and remediation recommendations aligned with cloud security best practices. - Preferred: Experience using Checkmarx KICS for IaC and container configuration scanning.
Hands on experience with Dynamic Application Security Testing (DAST), including scan configuration, authentication handling, API scanning, vulnerability validation, and false positive management.
Demonstrated ability to analyze, validate, and contextualize findings across SAST, SCA, IaC, and DAST tools, translating technical results into clear, actionable, and risk informed remediation guidance for development teams.
Extensive experience integrating application and cloud security tooling into CI/CD pipelines, implementing security gates, and aligning scan outcomes with modern DevSecOps workflows. - Preferred: Experience integrating Checkmarx platforms with CI/CD pipelines and broader cloud or application security ecosystems.
Advanced Secure Code ReviewsPerform deep-dive manual and automated secure code reviews for complex, high-risk applications and services.
Identify systemic vulnerabilities and recommend structural code and design improvements.
Serve as the primary escalation point for security concerns raised during code review or pipeline security scans.
Proven background in secure code reviews, vulnerability root-cause analysis, and validating fixes across multiple languages and frameworks.
Proficiency in one or more programming languages (e.g., Java, C#, Python, TypeScript) with a strong understanding of modern application architectures including microservices, APIs, containers, and cloud native platforms.
Threat Modeling & Application Risk AssessmentsLead threat modeling sessions for new and existing applications, cloud-native architectures, and major platform initiatives.
Assess application architectures for security gaps and recommend compensating or preventative controls.
Partner with engineering, Cloud, Architecture, and DevOps teams to embed security into design decisions.
Vulnerability Management & Security AdvisoryOwn remediation guidance for high- and critical-severity findings across AppSec scanners, third‑party assessments, and internal reviews.
Influence prioritization decisions by applying expert judgment to business risk, architectural impact, and threat landscape considerations.
Support program-level improvements to vulnerability lifecycle management across engineering teams.
Technical Leadership & MentoringProvide coaching and mentoring to Application Security Engineers, developers, and DevOps staff, consistent with expectations for senior Bank engineers.
Advocate for secure engineering practices across teams and promote a strong security culture within the SDLC.
Contribute to enterprise communities of practice, working groups, and secure development initiatives.
Required Qualifications6–8 years of experience in application security, software engineering, product security, or DevOps with a strong security focus, consistent with senior engineer expectations.
Deep expertise in secure software design principles, threat modeling methodologies, and enterprise application security controls.
Extensive experience with CI/CD security integration and DevSecOps tooling (SAST, SCA, DAST, secrets management, container security).
Demonstrated experience performing and leading secure code reviews and providing actionable remediation guidance.
Proficiency in one or more programming languages (e.g., Java, C#, Python, TypeScript) and familiarity with modern application architectures (microservices, containers, APIs, cloud-native).