Cboe
Principal Application Security Engineer
Chicago, IL · Principal
No sponsorship$164k-$212kDetected 30 days ago
PythonJavaGoC++C#Node.jsCode ReviewAWSAzureKubernetesCI/CDCybersecurityIncident ResponseLeadershipCommunicationCollaboration
About the role
- Cboe's Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem.
- This role requires deep hands-on expertise, strong systems thinking, and the ability to influence engineering practices, standards, and priorities at scale while serving as a trusted technical leader for both security and engineering stakeholders.
Responsibilities
- Own secure architecture reviews and threat modeling for new systems and major changes, establishing architectural direction for Kubernetes trust boundaries, secure service-to-service communication, and API authorization models across the environment
- Provide principal-level guidance for high-risk code and design changes, resolving complex security tradeoffs and driving remediation approaches that are durable, scalable, and aligned to engineering realities
- Act as a senior technical partner to engineering leadership, influencing roadmaps, architecture decisions, and secure-by-default design patterns across the organization
- Own Kubernetes workload security standards across multi-cluster environments, setting technical direction for RBAC, pod security controls, namespace isolation, network policies, secrets management, and platform guardrails
- Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines, ensuring SAST, SCA, secret scanning, container scanning, and IaC scanning are integrated through high-signal workflows that scale across engineering teams with minimal developer friction
- Own the strategy for risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service level expectations, and metrics that demonstrate measurable reduction in security risk over time
- Develop and champion secure coding guidance, reusable security patterns, and enablement programs that raise engineering capability and create lasting improvements in how teams design and build software
- Lead security design support during incident response and post-incident follow-through, translating lessons learned into durable architectural, control, and guardrail improvements that prevent recurrence
- Own the secure adoption of AI-enabled development and security capabilities, establishing patterns and guardrails for secure code review, automated assessments, and process improvements throughout the SDLC.
- Provide principal-level architecture and risk guidance for AI implementations and integrations, shaping secure design decisions, control expectations, and review practices for emerging use cases.
Nice to have
- Bachelor's degree in Computer Science, Information Security, or related field preferred
- Relevant certifications preferred (e.g., CSSLP, CKS, OSCP, AWS/Azure Security Specialty)
Skills
- This position reports to the Senior Manager, Application and Cloud Security.
Compensation
- Salary Ranges (applicable for US locations only)
Benefits
- We value the total wellbeing of our people - including health, financial, personal and social wellness.
- We believe standard benefits like health insurance and fair pay are given at any organization.
- Medical Coverage
- Prescription Drug Coverage
- Additional Medical Benefit
- Dental Coverage
- Vision Coverage
- 401K or Pension Company Match
- Retirement Savings Plan
- Employee Stock Purchase Plan (ESPP)
- Voluntary & Additional Benefits
Equal opportunity
- We're proud to be an equal opportunity employer do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or veteran status.
- We are committed to fostering a workplace where all individuals are valued and respected.
- This position is not eligible for visa sponsorship.
- Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.
Visa & Work Authorization
- This position is not eligible for visa sponsorship.
This listing is sourced directly from Cboe's careers page and normalized into a canonical job model.