1

Checkmarx Jobs in Illinois (NOW HIRING)

Senior Application Security Engineer

Chicago, IL · On-site

$60.50 - $80.75/hr

Experience with Checkmarx SAST / Checkmarx ONE, including custom query (CxQL) tuning and enterprise scale result management. Strong experience with Software Composition Analysis (SCA) tools, covering ...

Lead DevOps Engineer

Chicago, IL · On-site

$54.25 - $74.50/hr

Integrate "shift-left" security tools (Checkmarx, SonarQube, Prisma Cloud) * Align DevOps processes with Agile delivery and support ADO configurations * Provide technical leadership, mentoring, and ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Help operationalize Wiz, Checkmarx, JFrog/Xray, AppScan, Prisma Cloud, GCP Model Armor, and related security capabilities. * Support Azure/GCP/AWS cloud security controls, policy development ...

Lead Devops Engineer

Chicago, IL · On-site

$54.50 - $74.50/hr

... Checkmarx, SonarQube, PrismaCloud. • Identify and implement opportunities for automation, standardization, and process enhancements. • Provide technical guidance and mentoring to software deliver ...

Sr. Cloud DevOps Engineer

Chicago, IL · On-site

$134K - $172K/yr

... Checkmarx, CAST scans. • Experience with continuous integration and test-driven development practices, test automation and tools. • Empowered self-starter comfortable to take the lead and manage ...

Sr. DevOps Engineer

Chicago, IL · On-site

$54.50 - $74.50/hr

... Checkmarx, CAST scans. • Experience with continuous integration and test-driven development practices, test automation and tools. • Empowered self-starter comfortable to take the lead and manage ...

Senior Devops Engineer

Chicago, IL · On-site

$134K - $172K/yr

... Checkmarx, SonarQube, PrismaCloud. • Work in an Agile/Scrum environment; planning, estimating, and completing tasks on time. • Liaison with Agile Delivery Process teams to support necessary ...

Integrate different security solutions like Checkmarx using Azure CICD. * Analyze the requirements and prepare technical specifications and detail level design documents. * Drive the Design ...

Experience with DevOps and RE tools chain like Sonar, Nexus, Jenkins, uDeploy, Git, Splunk, Dynatrace, Terraform, AppScan, Checkmarx, CA DevTest * Experience with cross browser testing - Browser ...

Integrate different security solutions like Checkmarx using Azure CICD. * Analyze the requirements and prepare technical specifications and detail level design documents. * Drive the Design ...

Checkmarx information

See Illinois salary details

$16

$49

$81

How much do checkmarx jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for checkmarx in Illinois is $49.50, according to ZipRecruiter salary data. Most workers in this role earn between $42.40 and $59.42 per hour, depending on experience, location, and employer.

What is Checkmarx?

Checkmarx is a software security platform that specializes in application security testing. It helps developers and security teams identify vulnerabilities in their code through automated static and interactive application security testing (SAST and IAST). Checkmarx integrates with development pipelines to scan source code, open-source libraries, and APIs, enabling teams to find and fix security issues early in the software development lifecycle. The platform supports a wide range of programming languages and frameworks, making it a popular choice for organizations focused on secure software development.

What are the key skills and qualifications needed to thrive as a Checkmarx application security engineer?

To thrive as a Checkmarx Application Security Engineer, you need a solid understanding of secure software development, vulnerability assessment, and application security principles, often supported by a degree in computer science or related field. Experience with the Checkmarx SAST platform, knowledge of CI/CD pipelines, and relevant certifications such as CISSP or CEH are typically required. Strong analytical thinking, communication skills, and the ability to work collaboratively with development teams make someone stand out in this position. These skills are vital for effectively identifying and mitigating security risks in the software development lifecycle, ensuring robust protection of organizational assets.

What are some common challenges faced by professionals working with Checkmarx in an application security role?

Professionals working with Checkmarx often encounter challenges such as integrating the tool into existing CI/CD pipelines, managing false positives in scan results, and maintaining clear communication between security and development teams. Staying up-to-date with evolving vulnerabilities and ensuring that all codebases are consistently scanned can also be demanding. However, these challenges are typically addressed through strong collaboration, continuous learning, and leveraging Checkmarx's robust reporting and integration features.

What is the difference between Checkmarx vs SAST Developer?

AspectCheckmarxSAST Developer
CredentialsSecurity certifications, coding knowledgeSecurity certifications, coding knowledge
Work EnvironmentSecurity teams, development teamsDevelopment teams, security teams
Industry UsageApplication security testing toolsDeveloping and integrating SAST tools
Search IntentCompare security tools and rolesRoles involving static application security testing

Checkmarx professionals focus on using security testing tools like Checkmarx to identify vulnerabilities, while SAST Developers develop and maintain static application security testing (SAST) tools and integrations. Both roles require security and coding expertise but differ in their primary focus—one on utilizing security solutions, the other on creating them.

What cities in Illinois are hiring for Checkmarx jobs?

Cities in Illinois with the most Checkmarx job openings:

Infographic showing various Checkmarx job openings in Illinois as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 57% Physical, 15% Hybrid, and 28% Remote job distribution, with an average salary of $102,966 per year, or $49.5 per hour.

Senior Application Security Engineer

1 point system

Chicago, IL • On-site

$60.50 - $80.75/hr

Contractor

Re-posted 25 days ago


Job description

Job Description:

Key Responsibilities

Secure Software Development Lifecycle LeadershipLead the integration of security controls into CI/CD pipelines, including static analysis, software composition analysis, dynamic testing, secrets management, and container security workflows.
Define and continuously improve application security quality gates and review procedures in alignment with Modern Engineering SDLC practices.
Lead the integration of application security controls into CI/CD pipelines, including SAST, SCA, DAST, secrets detection, and container security, with automated gating and scalable DevSecOps workflows.
Define and continuously improve application security quality gates and review processes aligned to Modern Engineering SDLC standards, including risk based thresholds, exception handling, and audit ready documentation.
Provide expert guidance on secure architectures and design patterns, advising engineering teams on security tradeoffs for cloud native, microservices, and API driven solutions 
Secure Coding Standards & GovernanceOwn the development, maintenance, and enforcement of enterprise secure coding standards.
Align secure coding governance with established Bank technology standards, including SDLC, secure development expectations, and code review procedures.
Ensure teams understand and implement secure-by-default development practices throughout all project phases.
Deep expertise with Static Application Security Testing (SAST) platforms, including scan configuration, custom rule or query tuning, results triage, risk based prioritization, and disciplined false positive suppression with documented justification. - Preferred: Experience with Checkmarx SAST / Checkmarx ONE, including custom query (CxQL) tuning and enterprise scale result management.
Strong experience with Software Composition Analysis (SCA) tools, covering open source dependency analysis, license compliance, vulnerability assessment, policy configuration, and developer focused remediation guidance. - Preferred: Hands on experience with Checkmarx SCA in CI/CD integrated environments.
Proficiency with Infrastructure as Code (IaC) security scanning across technologies such as Terraform, CloudFormation, Kubernetes, and Helm, including rule tuning and remediation recommendations aligned with cloud security best practices. - Preferred: Experience using Checkmarx KICS for IaC and container configuration scanning.
Hands on experience with Dynamic Application Security Testing (DAST), including scan configuration, authentication handling, API scanning, vulnerability validation, and false positive management.
Demonstrated ability to analyze, validate, and contextualize findings across SAST, SCA, IaC, and DAST tools, translating technical results into clear, actionable, and risk informed remediation guidance for development teams.
Extensive experience integrating application and cloud security tooling into CI/CD pipelines, implementing security gates, and aligning scan outcomes with modern DevSecOps workflows. - Preferred: Experience integrating Checkmarx platforms with CI/CD pipelines and broader cloud or application security ecosystems.
Advanced Secure Code ReviewsPerform deep-dive manual and automated secure code reviews for complex, high-risk applications and services.
Identify systemic vulnerabilities and recommend structural code and design improvements.
Serve as the primary escalation point for security concerns raised during code review or pipeline security scans.
Proven background in secure code reviews, vulnerability root-cause analysis, and validating fixes across multiple languages and frameworks.
Proficiency in one or more programming languages (e.g., Java, C#, Python, TypeScript) with a strong understanding of modern application architectures including microservices, APIs, containers, and cloud native platforms.
Threat Modeling & Application Risk AssessmentsLead threat modeling sessions for new and existing applications, cloud-native architectures, and major platform initiatives.
Assess application architectures for security gaps and recommend compensating or preventative controls.
Partner with engineering, Cloud, Architecture, and DevOps teams to embed security into design decisions.
Vulnerability Management & Security AdvisoryOwn remediation guidance for high- and critical-severity findings across AppSec scanners, third‑party assessments, and internal reviews.
Influence prioritization decisions by applying expert judgment to business risk, architectural impact, and threat landscape considerations.
Support program-level improvements to vulnerability lifecycle management across engineering teams.
Technical Leadership & MentoringProvide coaching and mentoring to Application Security Engineers, developers, and DevOps staff, consistent with expectations for senior Bank engineers.
Advocate for secure engineering practices across teams and promote a strong security culture within the SDLC.
Contribute to enterprise communities of practice, working groups, and secure development initiatives.
Required Qualifications6–8 years of experience in application security, software engineering, product security, or DevOps with a strong security focus, consistent with senior engineer expectations.
Deep expertise in secure software design principles, threat modeling methodologies, and enterprise application security controls.
Extensive experience with CI/CD security integration and DevSecOps tooling (SAST, SCA, DAST, secrets management, container security).
Demonstrated experience performing and leading secure code reviews and providing actionable remediation guidance.
Proficiency in one or more programming languages (e.g., Java, C#, Python, TypeScript) and familiarity with modern application architectures (microservices, containers, APIs, cloud-native).