What are the responsibilities and job description for the Cybersecurity Engineer 4 position at Cullerton Group?
Cullerton Group has a new opportunity for a Cybersecurity Engineer 4. The work will be done hybrid at the Chicago, IL; Peoria, IL; or Dallas, TX office, with Wednesdays currently required onsite. This position is expected to transition to five days onsite, so candidates must be local and prepared for full-time in-office work. This is a long-term position that can lead to permanent employment with our client. Compensation is up to $106/hour full benefits (vision, dental, health insurance, 401k, and holiday pay).
Job Summary
We are seeking a Lead Cybersecurity Engineer to strengthen secure-by-design practices across enterprise applications and cloud environments. This role will support secure software development lifecycle practices, application security testing, vulnerability management, and the integration of security into DevOps processes. The engineer will partner closely with developers, architects, product owners, and business leaders to identify security risks, recommend practical remediation strategies, and ensure applications meet enterprise security requirements.
Key Responsibilities
• Analyze, validate, communicate, and manage application security vulnerabilities identified through CodeQL, Rapid7, penetration testing, bug bounty programs, and other automated or manual sources.
• Advise software engineers, architects, product owners, and leaders on secure application design, remediation strategies, risk decisions, and security review processes.
• Enable and monitor automated security testing tools at the repository and application levels, including SCA, SAST, and DAST solutions.
• Coordinate penetration testing and security assurance assessments by collecting scope and access requirements and managing findings through remediation.
• Evaluate security risks across AWS and Azure environments, Infrastructure as Code, APIs, identities, and application development workflows.
• Perform threat modeling, vulnerability assessments, risk analysis, and defense-in-depth reviews throughout the software development lifecycle.
• Use scripting and automation to improve security processes, monitoring, defect tracking, and developer enablement.
• Maintain ownership of assigned applications and collaborate directly with development teams to resolve security gaps.
Required Qualifications
• Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field with at least eight years of information security experience; a master’s degree with at least six years of relevant experience may also qualify.
• Strong application security expertise, including vulnerability identification and remediation based on OWASP, CWE/CVE, and SANS Top 25 guidance.
• Experience with security architecture, threat modeling, vulnerability assessment, risk analysis, defense in depth, IAM, API security, and secure SDLC practices.
• Cloud security experience with AWS, Microsoft Azure, or both.
• Experience with application security tools and processes involving SCA, SAST, and DAST.
• Development experience with Java, Python, .NET, JavaScript, or a comparable programming language.
• Hands-on experience implementing security automation and scripting.
• Excellent written and verbal communication skills, including the ability to explain highly technical security concepts to non-security audiences.
• Ability to coordinate multiple technical teams and manage competing security priorities.
• Must be local to the Chicago, Peoria, or Dallas office and willing to transition to five days onsite when required.
Preferred Qualifications
• Professional certification such as CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB, AWS Solutions Architect, or AWS Certified Security.
• Experience securing web services, APIs, cloud-native applications, and Infrastructure as Code.
• Familiarity with CodeQL, Rapid7 Web Application Security, penetration testing, and bug bounty programs.
• AI fluency and an understanding of emerging AI-related security considerations.
• Demonstrated employment stability and experience supporting enterprise-scale security programs.
Why This Role?
This position offers the opportunity to lead meaningful application and cloud security initiatives within a large, global organization. You will work directly with engineering teams to improve secure development practices, reduce security risks, and influence how enterprise applications and services are designed. Cullerton Group provides a professional environment, comprehensive benefits, and strong potential for long-term career growth.