Senior Application Security Engineer DevSecOps and CICD

3Core Systems, Inc

Chicago, Northern (IL, KY)

Hybrid

USD 120,000 - 150,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

3Core Systems, Inc. is seeking a Senior Application Security Engineer to drive DevSecOps initiatives for multiple applications in a remote USA role. You will embed security into the SDLC, perform AI-assisted and traditional security assessments, and manage code and cloud security tooling across teams.

You will collaborate with architects, developers, and product owners to implement secure coding practices, establish metrics, and deliver secure software at scale.

Qualifications

  • 5-7 years of hands-on application security/DevSecOps experience.
  • Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding.
  • Experience with security tooling and reading production code in Java and Python.
  • Knowledge of OWASP Top 10, API Security Top 10, and secure coding principles.
  • Cloud security, IAM, and modern app architectures; AI-assisted development tools.

Responsibilities

  • Embed security into the SDLC by defining and improving standards and workflows.
  • Perform AI-assisted and traditional security assessments of applications, APIs, and cloud workloads.
  • Manage repository scanning coverage and triage findings by exploitability and impact.
  • Drive remediation from discovery through verified closure and reduce security debt.
  • Build security metrics and executive dashboards for leadership visibility.
  • Coach and promote a security-first culture across delivery teams.

Skills

Agile
API
Artificial Intelligence
Cloud
SDLC
Security
Vulnerability

Education

Bachelor's degree in CS/CS-related field
Master's degree

Tools

Burp Suite
GitHub Advanced Security
CodeQL
SAST
SCA
Secret scanning
Dependency analysis
CI/CD security tooling

Job description

Job Title: Senior Application Security Engineer DevSecOps and CICD
Location: Remote, USA
Must Have Skills/Attributes: Agile, API, Artificial Intelligence (AI), Cloud, SDLC, Security, Vulnerability
Experience Desired: Secure SDLC, DevSecOps, Agile, and Scrum methodologies (5-7 yrs); Security tooling (5-7 yrs); OWASP Top 10, API Security Top 10, authentication/authorization controls (5-7 yrs)

Required Minimum Education: Bachelor’s Degree

Preferred Education: Master’s Degree

Job Description
  • ***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***
Education Requirements:
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Preferred Education:
  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field
Required Skills for the Cybersecurity Engineer:
  • -5-7 years of hands-on application security/DevSecOps experience
  • - Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
  • - Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
  • - Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
  • - OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
  • - Cloud security, identity and access management, and modern application architectures
  • - Safe and effective use of AI-assisted development and security tools
  • - Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
  • - Security metrics, coverage reporting, and executive dashboard development
  • - Excellent communication, stakeholder management, presentation, and documentation skills
  • - Ability to work independently across multiple applications, teams, portfolios, and technology stacks
  • - Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
  • - Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
  • - Coaching and knowledge sharing — champions a security-first culture
  • - Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
  • - Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
  • - Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
  • - Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
  • - Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
  • - Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
  • - Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown:
  • Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
  • Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
  • Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
  • Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
  • Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
  • Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks find value in our e-mail notifications as you continue to consider options for your professional career.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Application Security Specialist
Application Security Specialist

Motion Recruitment • Greensboro (NC)

Hybrid
USD 100,000 - 130,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Irving (TX)

On-site
USD 138,000 - 173,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

Compunnel Inc. • Orlando (FL)

On-site
USD 80,000 - 120,000
Senior AppSec Engineer
Senior AppSec Engineer

Dream • United States

On-site
USD 120,000 - 160,000