Remote | Chicago, IL; Peoria, IL; Dallas, TX; or Broomfield, CO | 12 Months | 2 Positions
Estimated Start Date: October 1, 2026
Work Arrangement: 100% remote; candidates must be local to one of the designated digital hubs in Chicago, Peoria, Dallas, or Broomfield
Duration: 12 months
Travel: Up to 25% as needed
Interview Process: One 60-minute virtual panel interview
We are seeking experienced AI Security Analysts / Application Security Engineers to help embed application security throughout the software development lifecycle and strengthen security across applications, APIs, cloud workloads, repositories, and supporting infrastructure.
This role combines hands-on application security and DevSecOps expertise with modern AI-assisted security practices. The ideal candidate will be comfortable performing security assessments, validating vulnerabilities, working directly with application code, driving remediation, and partnering with development and DevOps teams to improve security across multiple applications and technology stacks.
Define, execute, and continuously improve application security processes, standards, workflows, and Definition of Done criteria throughout the SDLC.
Perform AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure.
Execute and manage security scanning activities, including:
Source code analysis
SAST and SCA
Secret scanning
Dependency analysis
Infrastructure reviews
AI-driven security reviews
Analyze, validate, prioritize, and triage security findings based on exploitability, business impact, severity, compensating controls, and remediation requirements.
Drive vulnerabilities through the full remediation lifecycle, including backlog creation, ownership assignment, validation testing, retesting, evidence collection, and closure verification.
Identify and reduce security debt, dependency vulnerabilities, outdated libraries, open-source risks, and software supply chain exposure.
Perform hands-on security testing using tools and techniques such as Burp Suite, browser developer tools, API testing platforms, and secure code review.
Apply OWASP Top 10 and API Security Top 10 principles to identify and address application security risks.
Review and modify application code in Java and Python to validate vulnerabilities and assist with remediation.
Support remediation through code fixes, configuration changes, infrastructure updates, and compensating controls.
Use AI-assisted development and security tools responsibly to accelerate vulnerability analysis, threat modeling, code review, documentation, and remediation guidance.
Develop security metrics, coverage reporting, executive dashboards, and portfolio-level security insights.
Partner with architects, developers, DevOps engineers, Product Owners, and business stakeholders to communicate risk, prioritize remediation, and remove blockers.
Maintain security-related Agile work items, user stories, tasks, and defects within Scrum delivery processes.
Monitor emerging threats, AI-related security risks, evolving attack techniques, and vulnerability trends.
Promote a security-first culture through coaching, knowledge sharing, and documented best practices.
Bachelor's and/or Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience.
5–7 years of hands-on application security and/or DevSecOps experience.
Strong understanding of Secure SDLC, DevSecOps, Agile, and Scrum methodologies.
Hands-on experience with security tools and technologies including:
Burp Suite
GitHub Advanced Security
CodeQL
SAST
SCA
Secret scanning
Dependency analysis
CI/CD security tooling
Ability to read, analyze, test, and modify production application code in Java and Python to validate security findings and support remediation.
Strong knowledge of OWASP Top 10 and API Security Top 10.
Experience with authentication and authorization controls, secure coding principles, and common attack techniques.
Understanding of cloud security, identity and access management, and modern application architectures.
Experience performing vulnerability triage and validation based on exploitability, business impact, severity, and compensating controls.
Experience developing security metrics, coverage reporting, and executive dashboards.
Experience safely and effectively using AI-assisted development and security tools.
The ideal candidate is a hands-on application security professional who can do more than run security scans. This person should be able to determine whether findings are truly exploitable, understand application code, work directly with developers on remediation, and drive vulnerabilities through verified closure.
Candidates should also be comfortable operating independently across multiple applications and technology stacks while collaborating closely with engineering, DevOps, architecture, product, and business teams.
Excellent communication and stakeholder management
Strong presentation and documentation skills
Ability to work independently across multiple applications and teams
Strong analytical and problem-solving skills
Ability to balance security requirements with usability, operational impact, and business objectives
Strong collaboration and influencing skills
Ability to negotiate priorities and remove blockers
Coaching and knowledge-sharing skills
Comfortable working in an Agile/Scrum environment