Cybersecurity Engineer IV Application Security

The AES Group

Chicago, UShybrid$90k-$93k/yrPosted Jul 22, 2026
Posting intelligenceActively listed

Skills

githubcicd

About the role

Role: Cybersecurity Engineer IV Application Security

Location: Chicago, IL | Peoria, IL | Dallas, TX - Hybrid (Currently onsite every Wednesday; expected to transition to 5 days/week onsite)

Let s create our future together at The AES Group!

About The AES Group:

The AES Group is a premier technology and engineering consulting company that has been bringing businesses and talent together for over 20 years to deliver innovative solutions that have the greatest positive impact on society. AES has helped over 40 business enterprises, including Fortune 500 companies, engage their customers, empower their employees, and transform their business operations with the power of cloud, data, AI, engineering, and other emerging technologies.

Position Overview

Seeking an experienced Cybersecurity Engineer IV specializing in Application Security to join its Security Engineering team. This is not a general cybersecurity role the primary focus is embedding security throughout the Software Development Lifecycle (SDLC) while partnering directly with software engineering teams.

The selected candidate will support external-facing, revenue-generating eCommerce and web applications, ensuring security is integrated from application design through deployment and production. This position is ideal for security professionals who have experience working alongside developers to build secure applications rather than performing security assessments after development is complete.

About the Team

The Security Engineering team partners closely with clients eCommerce Development organization to integrate security into every phase of application development. Engineers work directly with software developers, architects, and technical leaders to improve secure coding practices, identify vulnerabilities early, and implement scalable security solutions throughout the SDLC.

Top Skills

Application Security

Software Development Lifecycle (SDLC)

Secure Software Development

SAST & DAST

Security Governance

DevSecOps / CI-CD Security

Vulnerability Management

Secure Coding Practices

Software Development Background

Strong Communication & Stakeholder Management

Key Responsibilities

Partner with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC).

Embed Security by Design principles into application architecture and development.

Review and improve application security practices across enterprise web applications.

Identify, analyze, prioritize, and help remediate application security vulnerabilities.

Utilize and support security testing throughout the SDLC, including Static and Dynamic Application Security Testing (SAST/DAST).

Analyze application code when necessary to identify security risks and recommend remediation.

Collaborate with developers to implement secure coding practices.

Communicate security risks, findings, and recommendations to software engineers, technical leadership, and business stakeholders.

Provide guidance on secure software development, application security governance, and security best practices.

Support security integration within CI/CD pipelines and modern development workflows.

Educate development teams on application security principles and secure development methodologies.

Required Qualifications

Education & Experience

Bachelor's degree in Computer Science or a related technical field with 8+ years of Information Security experience

OR

Master's degree with 6+ years of Information Security experience

Senior candidates with significant Application Security experience are encouraged to apply.

Required Technical Qualifications

Application Security

Strong hands-on experience in Application Security.

Experience integrating security into modern Software Development Lifecycles.

Knowledge of secure software development practices.

Experience with application security governance.

Software Development Lifecycle (Highest Priority)

Candidates must demonstrate strong understanding of the complete SDLC, including:

Requirements gathering

Application architecture

Software development

Testing

Deployment

Production support

Application maintenance

Previous software development experience is highly desirable, as this role partners directly with development teams throughout the development lifecycle.

Security Testing

Experience with application security testing methodologies such as:

Static Application Security Testing (SAST)

Dynamic Application Security Testing (DAST)

Experience with any commercial security testing platform is acceptable.

Software Development

Preferred experience with:

Reading and understanding application source code

Working alongside software developers

Secure coding practices

Security integration within CI/CD pipelines

Source Control

Experience with GitHub or similar source control platforms.

Preferred Qualifications

Software development experience

Ability to review and analyze application source code

AI programming or AI model experience

Experience utilizing AI tools within software development

Familiarity with secure DevSecOps practices

Candidates with AI experience will receive additional consideration when technical qualifications are otherwise comparable.

Required Soft Skills

Excellent written and verbal communication skills

Ability to explain complex cybersecurity concepts to technical and non-technical audiences

Strong collaboration and stakeholder management skills

Experience working with software engineers, architects, and technical leadership

Strong presentation and interpersonal skills

Ability to influence security decisions across multiple teams

Ideal Candidate Profile

Successful candidates will have experience:

Embedding security throughout the Software Development Lifecycle

Working directly with software engineering teams

Supporting secure application development

Integrating security into CI/CD pipelines

Performing application security assessments

Helping developers understand and remediate vulnerabilities

Securing customer-facing web and eCommerce applications

Why Join This Team?

This role offers the opportunity to secure high-visibility, external-facing eCommerce platforms that directly support clients business and customer experience. You'll collaborate with development teams from concept through production, helping build secure, scalable applications that protect business-critical and revenue-generating systems.

Candidate Requirements

Required

Strong Application Security experience

Deep understanding of the Software Development Lifecycle (SDLC)

Secure software development expertise

Experience with SAST and DAST

Security governance experience

Ability to work directly with software developers

Excellent communication and stakeholder management skills

Preferred

Software development background

Source code review and analysis experience

GitHub experience

AI programming or AI model experience

DevSecOps experience

Compensation

This Security Engineer role pays $90k-$93k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.