Senior Application Security Engineer

Cybersecurity Jobs

Deerfield (IL)

On-site

USD 91,000 - 143,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits
Onsite in Deerfield
Career development and mentoring

Job summary

Nutrien (Canada) Holdings ULC seeks a Senior Application Security Engineer to strengthen security across the software development lifecycle in Deerfield, IL. This onsite role focuses on leading vulnerability management, guiding risk‑based prioritization, and maturing application security across development, DevOps, and security teams.

The role requires hands‑on expertise with vulnerability management tools and security frameworks, plus strong collaboration with engineering and IT to drive secure

Qualifications

  • Bachelor's degree or higher in a related field preferred.
  • 6–8 years of related experience in security engineering or similar roles.
  • Strong understanding of vulnerability lifecycle, governance, and risk‑based prioritization.
  • Familiarity withISO 27001-2, ISO 31000, PCI DSS, OWASP ASVS, NIST frameworks, ITIL, COBIT.
  • Hands‑on experience with vulnerability tools (Qualys, Tenable, Snyk).
  • Experience with Agile development environments.

Responsibilities

  • Lead vulnerability management end‑to‑end, from assessment to remediation.
  • Guide risk‑based prioritization and stakeholder communications.
  • Mentor peers on secure development and remediation practices.
  • Collaborate with DevOps to implement vulnerability management across platforms.
  • Perform root‑cause analysis and define effective remediation strategies.
  • Provide leadership in security initiatives and metrics reporting.

Skills

Vulnerability management
Application security
Risk-based prioritization
Security frameworks
Incident response

Education

Bachelor's degree in Computer Science or related field

Tools

Python
Bash
Qualys
Tenable
Snyk
TruffleHog Pro

Job description

Nutrien (Canada) Holdings ULC is hiring a Senior Application Security Engineer in Deerfield, IL to strengthen application security across the software development lifecycle. In this onsite role, you will guide vulnerability identification and remediation practices, align teams around risk-based priorities, and help mature application security execution across development, DevOps, and security functions.

This position focuses on leading vulnerability management activities end to end, from assessment and prioritization through practical remediation outcomes in complex enterprise environments. You will also apply established security and risk frameworks to support decision-making and mentor peers on consistent application security practices.

What you’ll do
  • Build strong working relationships across application development, DevOps, cyber security, and IT to influence secure development outcomes with expert technical guidance
  • Lead vulnerability management, including prioritization, risk evaluation, progress tracking, and stakeholder communication
  • Monitor emerging business, technology, and cyber security trends and translate insights into improvements for development teams
  • Partner with engineering and DevOps teams to evaluate, implement, and optimize vulnerability management capabilities across people, process, and technology
  • Own and enhance core components of vulnerability management and application security solutions in complex enterprise environments
  • Conduct and oversee targeted vulnerability assessments to identify control gaps and assess the effectiveness of existing safeguards
  • Use security and risk frameworks such as ISO 27001-2, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, and MITRE ATT&CK to guide technical decisions and remediation priorities
  • Provide hands‑on expertise with vulnerability management and prioritization platforms to drive adoption of risk‑based remediation
  • Perform root cause analysis on vulnerabilities and work with development and platform teams to define effective solutions
  • Assess exploitability and business impact, then recommend remediation strategies that balance risk reduction with operational needs
  • Bring broad cyber security expertise spanning vulnerability management, privacy, incident response, governance, risk and compliance, enterprise security strategy, and security architecture
  • Lead and coordinate cyber security initiatives by shaping plans, driving execution, and communicating status to technical stakeholders and leadership
  • Mentor team members through technical guidance and support to build consistency in application security execution
  • Lead vulnerability identification, assessment, prioritization, and remediation across code, infrastructure, and applications, including technical direction on secure development, automation, and risk reduction
  • Act as a trusted escalation point for application and vulnerability management matters, partnering across teams to drive remediation and consistent execution across initiatives
  • Provide leadership continuity and decision support when the manager is out of office
Required qualifications
  • Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field is preferred
  • Minimum 6-8 years of related experience
  • Strong understanding of the vulnerability management lifecycle, governance, and risk‑based prioritization in enterprise environments
  • Deep familiarity with application security and risk frameworks including ISO 27001-2, ISO 31000, PCI DSS, OWASP ASVS, NIST frameworks, ITIL, COBIT, CVSSv4, and MITRE ATT&CK
  • Hands‑on experience with vulnerability management tools such as Qualys, Tenable, Snyk, and TruffleHog Pro
  • Experience working in Agile development environments
  • Strong understanding of operating systems (Windows, Unix, and MacOS), cloud concepts (including secure build images, ephemerál workloads, and cloud patching), and networking fundamentals
  • Strong application development background, including full‑stack application development and mobile development across iOS and Android
  • Experience developing metrics, dashboards, and risk reporting for technical teams and leadership
  • Experience with API security scanning and application security testing approaches
  • Ability to communicate complex technical issues clearly to engineers, senior leaders, and business stakeholders
  • Broad knowledge of cyber security practices including secure configuration management, data protection and privacy, security monitoring, incident response, governance, risk and compliance, patch management, and enterprise security architecture
  • Strong written and verbal communication skills with ability to influence senior management and cross‑functional stakeholders
  • Demonstrated ability to examine issues strategically and analytically, balancing technical depth with practical business outcomes
  • Advanced understanding of the use of AI in application development
  • Experience working in cloud and container environments
  • Penetration testing and application security experience
  • Automation and scripting experience such as Python or Bash
  • Deep experience in enterprise application development
Tech you may work with
  • ISO 27001-2, ISO 31000, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, OWASP ASVS, MITRE ATT&CK
  • Qualys, Tenable, Snyk, TruffleHog Pro
  • Agile, Windows, Unix, MacOS, iOS, Android, Python, Bash
Compensation and location
  • Location: Deerfield, IL (onsite)
  • Salary: USD 91,200 - 143,220 per year
Benefits
  • Comprehensive medical, dental, vision coverage
  • Life insurance
  • Disability coverage for positions working more than 30 hours per week
  • Retirement program with generous matching employer contributions
  • Paid vacation
  • Sick days and holidays
  • Paid personal and maternity/parental leaves
  • Employee and Family Assistance Program
  • Annual incentive plan participation
  • Long‑term incentive plan participation
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Boston (MA)

On-site
USD 140,000 - 200,000
Professional growth
Competitive USD-based compensation
Flextime
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2
IT Application Security Manager
IT Application Security Manager

Cybersecurity Jobs • Lakewood (CO)

Hybrid
USD 130,000 - 190,000
401(k) plan with matching
Medical, dental, and vision plans
Wellness program
+2
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • West Palm Beach (FL)

On-site
USD 120,000 - 170,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Jacksonville (FL)

On-site
USD 110,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

United States Digital Space LLC • Seattle (WA), San Francisco (CA)

On-site
USD 110,000 - 150,000