waypointjobs

Cybersecurity Jobs

Senior Application Security Engineer

deerfield, IL

Check who can apply and the requirements below before continuing.

About this opportunity

Cybersecurity Jobs lists this Senior Application Security Engineer opportunity in deerfield, Illinois. Review the employer’s description below for duties, qualifications and application requirements.

Job description

Nutrien (Canada) Holdings ULC is hiring a Senior Application Security Engineer in Deerfield, IL to strengthen application security across the software development lifecycle. In this onsite role, you will guide vulnerability identification and remediation practices, align teams around risk-based priorities, and help mature application security execution across development, DevOps, and security functions.

This position focuses on leading vulnerability management activities end to end, from assessment and prioritization through practical remediation outcomes in complex enterprise environments. You will also apply established security and risk frameworks to support decision-making and mentor peers on consistent application security practices.

What you’ll do

Build strong working relationships across application development, DevOps, cyber security, and IT to influence secure development outcomes with expert technical guidance

Lead vulnerability management, including prioritization, risk evaluation, progress tracking, and stakeholder communication

Monitor emerging business, technology, and cyber security trends and translate insights into improvements for development teams

Partner with engineering and DevOps teams to evaluate, implement, and optimize vulnerability management capabilities across people, process, and technology

Own and enhance core components of vulnerability management and application security solutions in complex enterprise environments

Conduct and oversee targeted vulnerability assessments to identify control gaps and assess the effectiveness of existing safeguards

Use security and risk frameworks such as ISO 27001-2 , PCI DSS , NIST CSF 20 , ITIL , COBIT , CVSSv4 , OWASP , and MITRE ATT&CK to guide technical decisions and remediation priorities

Provide hands‑on expertise with vulnerability management and prioritization platforms to drive adoption of risk‑based remediation

Perform root cause analysis on vulnerabilities and work with development and platform teams to define effective solutions

Assess exploitability and business impact, then recommend remediation strategies that balance risk reduction with operational needs

Bring broad cyber security expertise spanning vulnerability management, privacy, incident response, governance, risk and compliance, enterprise security strategy, and security architecture

Lead and coordinate cyber security initiatives by shaping plans, driving execution, and communicating status to technical stakeholders and leadership

Mentor team members through technical guidance and support to build consistency in application security execution

Lead vulnerability identification, assessment, prioritization, and remediation across code, infrastructure, and applications, including technical direction on secure development, automation, and risk reduction

Act as a trusted escalation point for application and vulnerability management matters, partnering across teams to drive remediation and consistent execution across initiatives

Provide leadership continuity and decision support when the manager is out of office

Required qualifications

Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field is preferred

Minimum 6-8 years of related experience

Strong understanding of the vulnerability management lifecycle, governance, and risk‑based prioritization in enterprise environments

Deep familiarity with application security and risk frameworks including ISO 27001-2 , ISO 31000 , PCI DSS , OWASP ASVS , NIST frameworks, ITIL , COBIT , CVSSv4 , and MITRE ATT&CK

Hands‑on experience with vulnerability management tools such as Qualys , Tenable , Snyk , and TruffleHog Pro

Experience working in Agile development environments

Strong understanding of operating systems (Windows , Unix, and MacOS), cloud concepts (including secure build images, ephemerál workloads, and cloud patching), and networking fundamentals

Strong application development background, including full‑stack application development and mobile development across iOS and Android

Experience developing metrics, dashboards, and risk reporting for technical teams and leadership

Experience with API security scanning and application security testing approaches

Ability to communicate complex technical issues clearly to engineers, senior leaders, and business stakeholders

Broad knowledge of cyber security practices including secure configuration management, data protection and privacy, security monitoring, incident response, governance, risk and compliance, patch management, and enterprise security architecture

Strong written and verbal communication skills with ability to influence senior management and cross‑functional stakeholders

Demonstrated ability to examine issues strategically and analytically, balancing technical depth with practical business outcomes

Advanced understanding of the use of AI in application development

Experience working in cloud and container environments

Penetration testing and application security experience

Automation and scripting experience such as Python or Bash

Deep experience in enterprise application development

Tech you may work with

ISO 27001-2, ISO 31000, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, OWASP ASVS, MITRE ATT&CK

Qualys, Tenable, Snyk, TruffleHog Pro

Agile, Windows, Unix, MacOS, iOS, Android, Python, Bash

Compensation and location

Location: Deerfield, IL (onsite)

Salary: USD 91,200 - 143,220 per year

Benefits

Comprehensive medical, dental, vision coverage

Life insurance

Disability coverage for positions working more than 30 hours per week

Retirement program with generous matching employer contributions

Paid vacation

Sick days and holidays

Paid personal and maternity/parental leaves

Employee and Family Assistance Program

Annual incentive plan participation

Long‑term incentive plan participation

#J-18808-Ljbffr

Worksite address

deerfield, IL, 60063, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

MANTECH

WhatJobs

Principal Cyber Engineer

chantilly, VA

Salary not specified

MANTECH seeks a motivated, mission-focused Principal Cyber Engineer (Network Focus) to join our team in Chantilly, VA . In this role, you wil…

Last received from source 2026-10-09View job

MANTECH

WhatJobs

Senior Cyber Security Engineer

chantilly, VA

Salary not specified

MANTECH seeks a motivated, career and customer-oriented Senior Cyber Security Engineer to join our team in Chantilly, VA . You will play a vi…

Last received from source 2026-10-09View job

Edward Jones

WhatJobs

Engineer III - API Office

tempe, AZ

Salary not specified

This job posting is anticipated to remain open for 30 days, from 08-Oct-2026. The posting may close early due to the volume of applicants. Join …

Last received from source 2026-10-09View job

Amazon.com Services LLC - A57

WhatJobs

Senior Automation Engineer

suffolk, VA

Salary not specified

Operations is at the heart of Amazon’s business. We are known for our speed, accuracy, and exceptional service. Our buildings deliver tens of tho…

Last received from source 2026-10-09View job

Amazon Data Services, Inc.

WhatJobs

Data Center Controls Engineer, Deployment

fredericksburg, VA

Salary not specified

AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people…

Last received from source 2026-10-09View job