Talent.com
No longer accepting applications
Senior Application Security Engineer (Hybrid - US)

Senior Application Security Engineer (Hybrid - US)

EnergySolutionsChicago, IL, United States
3 days ago
Job type
  • Full-time
Job description

Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus on the big impacts. And we believe that market-based programs can be a powerful force to deliver large-scale energy, carbon, and water-use savings. Since 1995, we've harnessed that power to offer proven, performance-based solutions for our utility, government, and institutional customers.

Summary :

We are seeking a Senior Application Security Engineer who will work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms. This role is primarily focused on execution and consulting but should be familiar with roadmap and strategy and contribute where appropriate. Must have the ability to read, review, and make recommendations on secure Django / Python patterns.

Responsibilities :

  • Contribute to the application security roadmap for our internal applications-prioritize risks and sequence work across codebases, application layer, and DevOps.
  • Consult with engineers to communicate requirements, create actionable tickets / acceptance criteria, and drive adoption.
  • Conduct pull request reviews focused on security, provide guidance on refactors, and approve / deny with clear rationale.
  • Serve as a steward for SAST / scanning : review static code scan results, triage findings, eliminate noise, and drive remediation with owners.
  • Build reference implementations in Django / Python (i.e. authentication patterns, input validation, secrets handling, rate limiting, geo-based access) without direct responsibility for production feature development.
  • Map SOC 2 / NIST to engineering work : translate requirements into stories, controls, and automated evidence in CI / CD.
  • Threat modeling & architecture : navigate libraries / architectures and document secure patterns (ADRs / RFCs) that teams follow.
  • Oversee security related tasks in the Software Delivery Life Cycle (SDLC) to ensure software development activities remain in compliance.
  • Collaborate with software developers and code base leads.
  • Act as a liaison between technical requirements from the business (i.e. security, privacy, compliance) and development teams.
  • Participate as a subject matter expert in security architecture, including new designs and design reviews.
  • Recommend application security improvements based on best practices, OWASP standards and other web application security frameworks.
  • Review architecture and compliance-related code changes for security impact.
  • Ensure compliance with all company security policies and standards.
  • Manage and maintain all security related tickets, including recommendations, testing, and validation.

Qualifications :

  • Minimum of 5 years' experience in application security experience.
  • Practice and implementation with Django / Python with a clear application-security focus (production experience and impact, not theory).
  • Engineering background (software or DevOps / SRE) with the ability to read / modify code, review PRs, and build PoCs.
  • Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
  • Experience embedding secure SDLC into Git-based workflows and CI / CD (pre-commit, pipeline gates, policy-as-code).
  • Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
  • Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging / monitoring).
  • Clear, persuasive communication (verbal and written) and prioritization.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Excellent interpersonal and negotiation skills.
  • Preferred Qualifications :

  • Bachelors degree in Computer Science or equivalent work experience preferred.
  • CISSP, GIAC, Security+, AWS Security and other related security certifications.
  • Prior experience reporting to or partnering with a security architect, or being the app-sec lead in a smaller org.
  • Strong organizational skills and attention to detail.
  • Strong analytical and problem-solving skills.
  • Ability to prioritize tasks according to severity
  • Ability to adapt to the needs of the organization
  • Proficient in AWS Security services (I.E. Cloud watch, Guard Duty)
  • The salary range for this role is $119,100 - $147,400 / annually, with a target compensation of $119,000 to $131,600 based on experience and qualifications.

    Compensation is commensurate with experience and includes a generous retirement package. Energy Solutions provides an excellent benefits package including medical, dental and vision insurance, other pre-tax contribution plans and an Employee Stock Ownership Plan (ESOP).

    AI Use

    At Energy Solutions we believe in the importance of authentic interactions and equitable opportunities. We base our candidate selection on one's own skills, knowledge, and experience. To ensure the integrity and fairness of our interview process, the use of artificial intelligence (AI) tools (including Generative AI) or other means to generate or assist with responses during interviews is strictly prohibited. This practice supports our commitment to create a transparent and equitable space where skills, knowledge and experience skills can truly shine.

    Equal Opportunity Employer

    Energy Solutions is an affirmative action-equal opportunity employer and prohibits discrimination and harassment of any type. We afford equal employment opportunities to employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristics protected by law. Energy Solutions conforms to the spirit as well as to the letter of all applicable laws and regulations.

    Office Locations and a Remote Workforce

    Energy Solutions operates as a predominantly remote workforce with offices insix different locations. Employees who reside within 40 miles of an office (except New York) will be assigned to that location, though in-office attendance requirements may vary by team. At this time, we are not accepting applications from candidates residing in the following states : Delaware, Kentucky, Mississippi, Montana, Nebraska, North Dakota, and Wyoming.

    Background Check Information

    Information will be requested to perform the compulsory background check. A drug screen and authorization to work in the U.S. indefinitely are preconditions of employment. Energy Solutions is an equal opportunity employer.

    Reasonable Accommodations

    Energy Solutions is committed to providing access and reasonable accommodation for individuals with disabilities. If you require accommodations in completing this application, interviewing, and / or completing any pre-employment testing, or otherwise participating in the employee selection process, please email accommodation@energy-solution.com.

    Privacy Notice for Job Applicants

    Create a job alert for this search

    Application Security Engineer • Chicago, IL, United States

    Related jobs
    • Promoted
    Senior Product Security Offensive Engineer

    Senior Product Security Offensive Engineer

    iManageChicago, IL, US
    Full-time
    We offer a flexible working policy that supports a healthy balance between personal and professional well-being.This role requires in-office presence on Tuesdays & Thursdays to collaborate, con...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    RAPPChicago, IL, United States
    Full-time
    RAPP Chicago is looking for a Security Engineer to join our award-winning Technology team.We are RAPP - world leaders in activating growth with precision and empathy at scale.As a global, next-gene...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Border Patrol Agent

    Border Patrol Agent

    U.S. Customs and Border ProtectionWinthrop Harbor, IL, US
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 21 hours ago
    • Promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityChicago, IL, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. Security Engineer - Hybrid Opportunity (Based in West Des Moines, IA)

    Sr. Security Engineer - Hybrid Opportunity (Based in West Des Moines, IA)

    The Mutual GroupChicago, IL, US
    Full-time
    We’re looking for a seasoned Senior Security Engineer with 5–10 years of hands-on experience in cybersecurity, with a strong focus on AWS cloud environments. This role demands a deep com...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Cyber Warfare Technician

    Cyber Warfare Technician

    U.S. NavyRiverdale, IL, US
    Full-time +1
    To be eligible to enlist in the U.Navy, candidates must be between the ages of 18-34.As a Cryptologic Technician, you are one of the worlds greatest problem-solvers. Were looking for people with sha...Show moreLast updated: 21 hours ago
    • Promoted
    Manager, Product Security Engineering

    Manager, Product Security Engineering

    Code Red PartnersMundelein, IL, US
    Permanent
    Code Red is Partnered with a fast-growing startup.They are a software company in the healthtech space.Series D round of funding, located in San Francisco, New York City, + Seattle.Product Security ...Show moreLast updated: 2 days ago
    • Promoted
    Senior Application Security Engineer (Hybrid - US)

    Senior Application Security Engineer (Hybrid - US)

    Energy SolutionsChicago, IL, United States
    Full-time
    Interested in joining a growing company where you will work with talented colleagues, enhance a supportive and energetic culture, and be part of the climate solution? At Energy Solutions, we focus ...Show moreLast updated: 16 days ago
    • Promoted
    Controls Engineer

    Controls Engineer

    CyberCodersPortage, IN, US
    Full-time
    Location : Onsite in Portage, IN.We are seeking a highly skilled Controls Engineer to join our team.The ideal candidate will be responsible for designing, developing, and implementing control system...Show moreLast updated: 3 days ago
    • Promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityChicago, IL, United States
    Full-time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...Show moreLast updated: 30+ days ago
    • Promoted
    Application Security Engineer

    Application Security Engineer

    TEKsystemsChicago, IL, United States
    Full-time
    Must be able to go onsite in Dallas, TX or Chicago, IL •.As a Lead Cybersecurity Engineer, you will be responsible for understanding and contributing to Security by Design practices, secure applicat...Show moreLast updated: 27 days ago
    • Promoted
    Senior Enterprise Security Engineer

    Senior Enterprise Security Engineer

    FlexportChicago, IL, US
    Full-time
    At Flexport, we believe global trade can move the human race forward.That's why it's our mission to make global commerce so easy there will be more of it. We're shaping the future of a $...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Security Engineer / Analyst

    Senior Information Security Engineer / Analyst

    KonnectITChicago, IL, US
    Full-time
    Senior Information Security Engineer / Analyst.The ideal candidate will have advanced expertise in.IPS / IDS, vulnerability management, incident response, risk and security assessments, and scripting...Show moreLast updated: 30+ days ago
    • Promoted
    Mixed Signal Design Engineer

    Mixed Signal Design Engineer

    Griffin Global Systems, Inc.Mundelein, IL, US
    Full-time
    NO H1B OR STUDENT VISA CANDIDATES FOR THIS ROLE.Required experience & education : .MS or PhD in Electrical Engineering with emphasis in analog / mixed-signal integrated circuit design.IC developmen...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    U.S. Border Patrol Agent

    U.S. Border Patrol Agent

    U.S. Customs and Border ProtectionHighwood, IL, US
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show moreLast updated: 21 hours ago
    • Promoted
    Application Engineer

    Application Engineer

    Trumpf, Inc.Chicago, IL, United States
    Full-time
    As a family-run, high-tech company with nearly 19,000 employees at 71 locations worldwide, we are looking for forward thinkers with unconventional ideas and drive to join our team.Our company cultu...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer - Cloud Security

    Security Engineer - Cloud Security

    RelativityChicago, IL, United States
    Full-time
    We are looking for a talented and passionate Security Engineer, Cloud Security to join our team.In this role, you will design, build, and maintain software solutions that enable our internal teams ...Show moreLast updated: 30+ days ago
    • Promoted
    Senior IT Security Analyst

    Senior IT Security Analyst

    Busey BankJoliet, IL, United States
    Full-time
    The Senior IT Security Analyst is responsible for managing activities relating to monitoring and responding to security events. The analyst is responsible for monitoring application, host, and netwo...Show moreLast updated: 19 days ago