Senior Application Security Engineer

3Core Systems , IncBerwyn, IL
Hybrid

About The Position

The Lead Cybersecurity Engineer will be a key partner to development teams, focusing on integrating security into the software development lifecycle (SDLC). This role is responsible for the security engineering of cloud environments (AWS, Azure) and vulnerability management for both Infrastructure as Code (IaC) and application code. The Senior Application Security Engineer will be accountable for a dedicated set of applications and works directly with their respective development teams. This role is part of a larger security engineering team that sets standards and best practices for collaboration with developers. The engineer will help development teams identify security gaps and assist in creating solutions to ensure services are compliant with enterprise security requirements.

Requirements

  • Bachelor's Degree in computer science or a related field with 8+ years in information security.
  • Master's Degree with 6+ years of experience.
  • Deep understanding of vulnerabilities and remediation (OWASP, CWE/CVE, SANS 25).
  • Experience with enterprise security architecture, threat modeling, vulnerability assessment, risk analysis, defense in depth, SDLC, IAM, and API security.
  • Hands-on experience with MS Azure and/or AWS.
  • Proficiency in one or more languages (Java, Python, .Net, JS, or equivalent).
  • Implementation of automation to streamline security processes.
  • Professional certification such as CISSP, CCSP, GWAPT, GWEB, or AWS Security Specialty.
  • Excellent written and verbal communication skills.
  • Demonstrated ability to communicate highly technical security concepts to non-security audiences.
  • Ability to coordinate multiple teams in accomplishing process review and improvement.
  • API
  • AWS
  • Cucumber
  • Java
  • Jenkins
  • Python
  • REST
  • SQL
  • Application Security Expertise (8 yrs)
  • Proficiency in at least one programming language such as Java, Python, .Net, JS, or equivalent. (8 yrs)

Nice To Haves

  • Professional certifications (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB, etc.).
  • Strong understanding and experience with information security technologies.
  • AI Fluency is preferred.

Responsibilities

  • Implementing and consulting on secure development practices.
  • Integrating security into DevOps pipelines.
  • Managing and tracking security risks to remediation.
  • Working closely with development teams in an agile environment.
  • Analyzing, validating, and communicating on security defects from tools like CodeQL, Rapid7, penetration testing, and bug bounties.
  • Acting as a partner to software engineers by providing accurate information on vulnerabilities and remediation strategies.
  • Serving as a trusted advisor to software engineers, architects, and product owners.
  • Providing context-aware guidance to help teams make secure decisions and document their architectures.
  • Navigating review and approval processes for new features and issue remediation.
  • Enabling and monitoring automated defect detection tools (e.g., CodeQL, Rapid7) at the repository or application level.
  • Ensuring tools are configured and running according to established processes.
  • Collecting and communicating scope and access information for penetration testing.
  • Handling the output of these assessments through the defect management process.
  • Accountable for a dedicated set of applications and works directly with their respective development teams.
  • Helping development teams identify security gaps and assisting in creating solutions to ensure services are compliant with enterprise security requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service