What are the responsibilities and job description for the Senior Application Security Engineer position at 3Core Systems , Inc?
Initially hybrid with 1
day a week on Wednesday and will eventually 5 days onsite
Location : Chicago IL ,
Peoria IL or Dallas TX – local candidates only
Key skills : Experience with enterprise security architecture, threat
modeling, vulnerability assessment, risk analysis, defense in depth, SDLC, IAM,
and API security. Hands-on
experience with MS Azure and/or AWS.
New Senior Application
Security Engineer DevSecOps and Cloud Job in Chicago, IL.
Must Have
Skills/Attributes: API, AWS, Cucumber,
Java, Jenkins, Python, REST, SQL
Experience
Desired: Application Security
Expertise (8 yrs); Application Security Expertise (8 yrs); Proficiency in at
least one programming language such as Java, Python, .Net, JS, or equivalent.
(8 yrs)
Required Minimum
Education: Master’s Degree
Preferred
Education: Master’s Degree
Job Description
Education & Experience
• Bachelor's Degree in computer science or a related field with 8 years in
information security.
• Master's Degree with 6 years of experience.
Technical Skills (Required)
• Application Security: Deep understanding of vulnerabilities and
remediation (OWASP, CWE/CVE, SANS 25).
• Broad Security Knowledge: Experience with enterprise security architecture,
threat modeling, vulnerability assessment, risk analysis, defense in depth,
SDLC, IAM, and API security.
• Cloud Security: Hands-on experience with MS Azure and/or AWS.
• Development Experience: Proficiency in one or more languages (Java,
Python, .Net, JS, or equivalent).
• Automation & Scripting: Implementation of automation to streamline
security processes.
• Certifications: Professional certification such as CISSP, CCSP, GWAPT, GWEB,
or AWS Security Specialty.
Technical Skills (Desired)
• Professional certifications (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB,
etc.).
• Strong understanding and experience with information security technologies.
• AI Fluency is preferred.
The Lead Cybersecurity Engineer will be a key partner to development teams,
focusing on integrating security into the software development lifecycle
(SDLC). This role is responsible for the security engineering of cloud
environments (AWS, Azure) and vulnerability management for both Infrastructure
as Code (IaC) and application code.
Key Contributions:
• Security by Design: Implementing and consulting on secure development
practices.
• DevSecOps Integration: Integrating security into DevOps pipelines.
• Vulnerability Management: Managing and tracking security risks to
remediation.
• Agile Collaboration: Working closely with development teams in an agile
environment.
o Analyzing, validating, and communicating on security defects from tools like
CodeQL, Rapid7, penetration testing, and bug bounties.
o Acting as a partner to software engineers by providing accurate information
on vulnerabilities and remediation strategies.
o Serving as a trusted advisor ("best friend") to software engineers,
architects, and product owners.
o Providing context-aware guidance to help teams make secure decisions and
document their architectures.
o Navigating review and approval processes for new features and issue
remediation.
o Enabling and monitoring automated defect detection tools (e.g., CodeQL,
Rapid7) at the repository or application level.
o Ensuring tools are configured and running according to established processes.
8. Security Test Onboarding & Management:
o Collecting and communicating scope and access information for penetration testing.
o Handling the output of these assessments through the defect management
process.
• Accountable for a dedicated set of applications and works directly with their
respective development teams.
• Part of a larger security engineering team that sets standards and best
practices for collaboration with developers.
• Helps development teams identify security gaps and assists in creating
solutions to ensure services are compliant with enterprise security
requirements.
Soft Skills (Required)
• Excellent written and verbal communication skills.
• Demonstrated ability to communicate highly technical security concepts to
non-security audiences.
• Ability to coordinate multiple teams in accomplishing process review and
improvement.
Disqualifiers / Red Flags
• Choppy Tenure: Consistent job-hopping will not be considered.
• Location: Candidates must be local to the Chicago, Peoria, or Dallas offices;
non-local candidates will not be considered.