Principal Application Security Engineer

Cboe

Chicago (IL)

Hybrid

USD 150,000 - 230,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Cboe is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem.

You will partner with application, platform, and infrastructure teams to define secure-by-default patterns and drive implementation of security controls throughout the SDLC across microservices, APIs, and containerized workloads in both cloud and on-prem environments.

Qualifications

  • 12+ years of experience in application security or software engineering
  • Bachelor’s degree in Computer Science or related field
  • Certifications such as CSSLP, CKS, OSCP, or AWS/Azure Security Specialty preferred
  • Hands-on experience integrating DevSecOps tooling into CI/CD pipelines
  • Experience securing hybrid environments with workloads in public cloud and on-prem Kubernetes
  • Proficiency in at least one backend language (C++, Go, Java, C#, Python, Node.js)
  • Strong knowledge of Kubernetes security primitives (RBAC, namespaces, service accounts, pod security)
  • Excellent communication and leadership skills; able to drive alignment across stakeholders
  • Authorized to work in the United States without sponsorship now or in the future

Responsibilities

  • Own secure architecture reviews and threat modeling for new systems and major changes
  • Define secure-by-default architecture patterns for Kubernetes trust boundaries and API authorization
  • Mature and drive adoption of application and API security standards
  • Provide principal guidance for high-risk code and design changes
  • Influence engineering roadmaps and secure-by-default patterns across teams
  • Own Kubernetes workload security standards across multi-cluster environments
  • Set technical direction for RBAC, pod security controls, namespace isolation, and network policies
  • Develop and champion secure coding guidance and reusable patterns
  • Lead security design during incident response and post-incident improvements
  • Drive secure adoption of AI-enabled development and security capabilities
  • Provide architecture and risk guidance for AI implementations and integrations
  • Govern data boundaries, permissions, and approved AI data usage patterns

Skills

Application security
Security leadership
DevSecOps
Threat modeling
Kubernetes security
CI/CD security
Cloud security
Secure coding guidance

Education

B.S. in Computer Science or Information Security

Tools

SAST tooling
SCA tooling
IaC scanning
Container scanning
Kubernetes security tooling

Job description

  • Cboe’s Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem
  • In this role, you will partner closely with application, platform, and infrastructure teams to define secure-by-default architecture patterns, shape strategic security direction, and drive implementation of security controls throughout the software development lifecycle (SDLC) across microservices, APIs, and containerized workloads operating in both public cloud and on-premises Kubernetes environments
  • You will operate as a principal-level individual contributor with broad technical influence, accountable for setting direction in complex or ambiguous situations, making high-impact architectural decisions, and driving consistent security outcomes across multiple teams and platforms
  • This role requires deep hands-on expertise, strong systems thinking, and the ability to influence engineering practices, standards, and priorities at scale while serving as a trusted technical leader for both security and engineering stakeholders
  • This position reports to the Senior Manager, Application and Cloud Security
  • Own secure architecture reviews and threat modeling for new systems and major changes, establishing architectural direction for Kubernetes trust boundaries, secure service-to-service communication, and API authorization models across the environment
  • Define, mature, and drive adoption of application and API security standards, including authentication and authorization patterns, input validation requirements, and mitigations for common vulnerability classes such as SSRF, injection, and access control flaws
  • Provide principal-level guidance for high-risk code and design changes, resolving complex security tradeoffs and driving remediation approaches that are durable, scalable, and aligned to engineering realities
  • Act as a senior technical partner to engineering leadership, influencing roadmaps, architecture decisions, and secure-by-default design patterns across the organization
  • Own Kubernetes workload security standards across multi-cluster environments, setting technical direction for RBAC, pod security controls, namespace isolation, network policies, secrets management, and platform guardrails
  • Establish and continuously evolve the container image security strategy, including secure base image standards, vulnerability management expectations, SBOM practices, and deployment controls that prevent risky configurations from reaching production
  • Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines, ensuring SAST, SCA, secret scanning, container scanning, and IaC scanning are integrated through high-signal workflows that scale across engineering teams with minimal developer friction
  • Own the strategy for risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service level expectations, and metrics that demonstrate measurable reduction in security risk over time
  • Develop and champion secure coding guidance, reusable security patterns, and enablement programs that raise engineering capability and create lasting improvements in how teams design and build software
  • Lead security design support during incident response and post-incident follow-through, translating lessons learned into durable architectural, control, and guardrail improvements that prevent recurrence
  • Own the secure adoption of AI-enabled development and security capabilities, establishing patterns and guardrails for secure code review, automated assessments, and process improvements throughout the SDLC
  • Provide principal-level architecture and risk guidance for AI implementations and integrations, shaping secure design decisions, control expectations, and review practices for emerging use cases
  • Drive governance and technical controls to define, monitor, and enforce data boundaries, permissions, and approved usage patterns for AI-related data access

12+ years of experience in application security, product security, or software engineering, including significant experience shaping architecture, setting standards, and driving security outcomes across complex production environmentsBachelor’s degree in Computer Science, Information Security, or related field preferredExperience directly writing and delivering production software as a software engineerRelevant certifications preferred (e.g., CSSLP, CKS, OSCP, AWS/Azure Security Specialty)Hands-on experience integrating DevSecOps tooling (SAST, SCA, secret scanning, IaC/container scanning) into CI/CD pipelinesExperience securing hybrid environments with workloads running in both public cloud (EKS, AKS, GKE) and on-prem Kubernetes platformsProven ability to read, write, and review production-grade code in at least one modern backend language (e.g., C++, Go, Java, C#, Python, Node.js), with the judgment to guide secure engineering decisions in high-impact systemsStrong working knowledge of Kubernetes security primitives (RBAC, namespaces, service accounts, pod security) and container build practicesExceptional communication, influence, and technical leadership skills, with a demonstrated ability to drive alignment, establish direction, and own outcomes across engineering, platform, and security stakeholdersCandidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal AppSec Architect: Kubernetes & API Security
Principal AppSec Architect: Kubernetes & API Security

Cedar Cares, Inc • Chicago (IL)

On-site
USD 164,000 - 212,000
Medical Coverage
Prescription Drug Coverage
Dental Coverage
+8
Principal Application Security Engineer
Principal Application Security Engineer

Cedar Cares, Inc • Chicago (IL)

On-site
USD 164,000 - 212,000
Medical Coverage
Prescription Drug Coverage
Dental Coverage
+8
Senior Application Security Engineer & Architect
Senior Application Security Engineer & Architect

Cboe Global Markets, Inc. • Chicago (IL)

Hybrid
USD 164,000 - 212,000
Medical Coverage
Prescription Drug Coverage
Dental Coverage
+8
Principal AppSec Architect: Secure, Scalable Systems
Principal AppSec Architect: Secure, Scalable Systems

Cboe • Chicago (IL)

Hybrid
USD 150,000 - 230,000
Senior Security Application Engineer
Senior Security Application Engineer

Bitgo • Palo Alto (CA)

Hybrid
USD 180,000 - 240,000
Company-paid medical, dental, and vis​
Catered lunches, snacks, coffee
Caltrain passes
+5
Principal Application Security Engineer
Principal Application Security Engineer

Cboe Global Markets, Inc. • Chicago (IL)

Hybrid
USD 164,000 - 212,000
Medical Coverage
Prescription Drug Coverage
Dental Coverage
+8
Application Security (AppSec) / DevSecOps Engineer
Application Security (AppSec) / DevSecOps Engineer

Zoho • United States

Remote
USD 83,000 - 152,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Leader
Application Security Leader

RELX International • Richmond (VA)

On-site
USD 150,000 - 190,000
Product Security Engineer
Product Security Engineer

Stellar IT Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 200,000