Principal Application Security Engineer

Cedar Cares, Inc

Chicago (IL)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Coverage
401K or Pension with Company Match
Employee Stock Purchase Plan (ESPP)

Job summary

Cedar Cares, Inc is seeking a Principal Application Security Engineer to lead technical security initiatives and embed scalable security across their engineering ecosystem. This role involves ensuring secure architecture reviews, defining standards for application and API security, and driving best practices in cloud and container security.

The ideal candidate will have over 12 years of relevant experience in application security, demonstrate strong technical leadership, and have a comprehensive understanding of security in hybrid environments.

Qualifications

  • 12+ years of experience in application security, product security, or software engineering.
  • Direct experience writing and delivering production software.
  • Proven ability to read, write, and review production-grade code.

Responsibilities

  • Drive implementation of security controls throughout the software development lifecycle.
  • Own secure architecture reviews and threat modeling for new systems.
  • Develop and champion secure coding guidance and reusable security patterns.

Skills

Application Security
API Security
Kubernetes Security
DevSecOps
Coding in modern backend languages

Education

Bachelor's degree in Computer Science or Information Security

Tools

DevSecOps tooling (SAST, SCA)
Kubernetes

Job description

Role Overview:
Cboe’s Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem. You will partner closely with application, platform, and infrastructure teams to define secure-by-default architecture patterns, shape strategic security direction, and drive implementation of security controls throughout the software development lifecycle across microservices, APIs, and containerized workloads in public cloud and on‑premises Kubernetes environments.

Responsibilities
  • Application & API Security
    • Own secure architecture reviews and threat modeling for new systems and major changes, establishing architectural direction for Kubernetes trust boundaries, secure service-to-service communication, and API authorization models.
    • Define, mature, and drive adoption of application and API security standards, including authentication and authorization patterns, input validation requirements, and mitigations for common vulnerability classes such as SSRF, injection, and access control flaws.
    • Provide principal-level guidance for high-risk code and design changes, resolving complex security tradeoffs and driving remediation approaches that are durable, scalable, and aligned to engineering realities.
    • Act as a senior technical partner to engineering leadership, influencing roadmaps, architecture decisions, and secure-by-default design patterns across the organization.
  • Kubernetes, Container & DevSecOps Security
    • Own Kubernetes workload security standards across multi-cluster environments, setting technical direction for RBAC, pod security controls, namespace isolation, network policies, secrets management, and platform guardrails.
    • Establish and continuously evolve the container image security strategy, including secure base image standards, vulnerability management expectations, SBOM practices, and deployment controls that prevent risky configurations from reaching production.
    • Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines, ensuring SAST, SCA, secret scanning, container scanning, and IaC scanning are integrated through high-signal workflows that scale across engineering teams with minimal developer friction.
  • Software Vulnerability Management & Security Enablement
    • Own the strategy for risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service level expectations, and metrics that demonstrate measurable reduction in security risk over time.
    • Develop and champion secure coding guidance, reusable security patterns, and enablement programs that raise engineering capability and create lasting improvements in how teams design and build software.
    • Lead security design support during incident response and post-incident follow-through, translating lessons learned into durable architectural, control, and guardrail improvements that prevent recurrence.
  • AI Implementation Security
    • Own the secure adoption of AI-enabled development and security capabilities, establishing patterns and guardrails for secure code review, automated assessments, and process improvements throughout the SDLC.
    • Provide principal-level architecture and risk guidance for AI implementations and integrations, shaping secure design decisions, control expectations, and review practices for emerging use cases.
    • Drive governance and technical controls to define, monitor, and enforce data boundaries, permissions, and approved usage patterns for AI-related data access.
Qualifications
  • 12+ years of experience in application security, product security, or software engineering, including significant experience shaping architecture, setting standards, and driving security outcomes across complex production environments.
  • Direct experience writing and delivering production software as a software engineer.
  • Bachelor’s degree in Computer Science, Information Security, or a related field preferred.
  • Relevant certifications preferred (CSSLP, CKS, OSCP, AWS/Azure Security Specialty).
  • Proven ability to read, write, and review production-grade code in at least one modern backend language (C++, Go, Java, C#, Python, Node.js), with the judgment to guide secure engineering decisions in high-impact systems.
  • Strong working knowledge of Kubernetes security primitives (RBAC, namespaces, service accounts, pod security) and container build practices.
  • Hands‑on experience integrating DevSecOps tooling (SAST, SCA, secret scanning, IaC/container scanning) into CI/CD pipelines.
  • Experience securing hybrid environments with workloads running in both public cloud (EKS, AKS, GKE) and on‑prem Kubernetes platforms.
  • Exceptional communication, influence, and technical leadership skills, with a demonstrated ability to drive alignment, establish direction, and own outcomes across engineering, platform, and security stakeholders.
Benefits & Perks
  • Medical Coverage
  • Prescription Drug Coverage
  • Additional Medical Benefit
  • Dental Coverage
  • Vision Coverage
  • 401K or Pension with Company Match
  • Spending Accounts
  • Life and AD&D Insurance
  • Retirement Savings Plan
  • Employee Stock Purchase Plan (ESPP)
  • Voluntary & Additional Benefits
  • Paid Time Off
Equal Employment Opportunity

We’re proud to be an equal opportunity employer and do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or veteran status. We are committed to fostering a workplace where all individuals are valued and respected.

Location & Work Model

Location: Chicago, Illinois (Cboe HQ at the historic Old Post Office district). This role follows a four‑day in‑office work model.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer
Principal Application Security Engineer

Cboe Global Markets • Chicago (IL)

Hybrid
USD 163,000 - 212,000
Medical Coverage
401K or Pension Company Match
Employee Stock Purchase Plan (ESPP)
+1
Engineer, Application Security
Engineer, Application Security

Cboe Global Markets • Chicago (IL)

On-site
USD 102,000 - 134,000
Competitive salary
Health benefits
401(k) match
+4
Engineer, Application Security
Engineer, Application Security

Cedar Cares, Inc • Chicago (IL)

On-site
USD 102,850 - 133,100
Competitive salary
Incentive compensation
Generous paid time off
+6
Principal Security Engineer
Principal Security Engineer

Cboe Global Markets • Overland Park (KS)

Hybrid
USD 148,000 - 193,000
Generous paid time off
Flexible, hybrid work environment
Health, dental and vision benefits
+2
Sr. Information Security Engineer (Systems Engineer)
Sr. Information Security Engineer (Systems Engineer)

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 100,000 - 130,000
Generous paid time off
Health, dental, and vision benefits
401(k) match
+2
Sr. Information Security Engineer (Systems Engineer)
Sr. Information Security Engineer (Systems Engineer)

Cboe Global Markets • Overland Park (KS)

On-site
USD 119,000 - 154,000
Health benefits
401(k) match
Tuition assistance
+1
Principal Application Security Architect
Principal Application Security Architect

Cboe Global Markets • Chicago (IL)

Hybrid
USD 163,000 - 212,000
Medical Coverage
401K or Pension Company Match
Employee Stock Purchase Plan (ESPP)
+1
Senior Engineer - Threat Hunting
Senior Engineer - Threat Hunting

Cedar Cares, Inc • Chicago (IL)

On-site
USD 130,900 - 169,400
Generous paid time off
Health, dental, and vision coverage
401(k) match up to 8%
+2
Infrastructure Engineer
Infrastructure Engineer

Cboe Global Markets • Chicago (IL)

On-site
USD 126,000 - 164,000
Health, dental and vision benefits
Generous paid time off
2:1 401(k) match
Infrastructure Engineer
Infrastructure Engineer

Cboe Global Markets • Kansas City (MO)

Hybrid
USD 114,000 - 149,000
Health, dental and vision benefits
401(k) match, up to 8%
Paid parental leave