
Principal Application Security Engineer
Cboe Global Markets4 days ago
Base Salary
$164k - $212k/yr
Responsibilities
- Own secure architecture reviews and threat modeling for new systems and major changes, including Kubernetes trust boundaries, service-to-service communication, and API authorization models.
- Define and drive adoption of application and API security standards covering authentication, authorization, input validation, SSRF, injection, and access control flaws.
- Provide technical leadership on high-risk code and design changes and influence engineering roadmaps, architecture decisions, and secure-by-default patterns.
- Own Kubernetes workload security standards for RBAC, pod security, namespace isolation, network policies, secrets management, and platform guardrails.
- Establish container image security strategy, including secure base images, vulnerability management, SBOM practices, and deployment controls.
- Drive DevSecOps guardrails in CI/CD pipelines, including SAST, SCA, secret scanning, container scanning, and IaC scanning.
- Own risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service levels, and metrics.
- Develop secure coding guidance, reusable security patterns, and engineering enablement programs.
- Lead security design support during incident response and post-incident improvement efforts.
- Own security patterns, governance, and technical controls for AI-enabled development, security capabilities, and AI-related data access.
Requirements
- 12+ years of experience in application security, product security, or software engineering, including significant experience shaping architecture, setting standards, and driving security outcomes in complex production environments.
- Direct experience writing and delivering production software as a software engineer.
- Bachelor’s degree in Computer Science, Information Security, or a related field is preferred.
- Relevant certifications such as CSSLP, CKS, OSCP, or AWS/Azure Security Specialty are preferred.
- Ability to read, write, and review production-grade code in at least one modern backend language, including C++, Go, Java, C#, Python, or Node.js.
- Strong knowledge of Kubernetes security primitives, including RBAC, namespaces, service accounts, and pod security, as well as container build practices.
- Hands-on experience integrating DevSecOps tooling such as SAST, SCA, secret scanning, and IaC or container scanning into CI/CD pipelines.
- Experience securing hybrid environments using public cloud platforms such as EKS, AKS, and GKE and on-premises Kubernetes platforms.
- Exceptional communication, influence, and technical leadership skills, with the ability to drive alignment and own outcomes across engineering, platform, and security stakeholders.
Benefits
- Medical, prescription drug, dental, and vision coverage.
- 401K or pension with company match, spending accounts, life and AD&D insurance, retirement savings plan, and employee stock purchase plan.
- Voluntary and additional benefits and paid time off.
- Four days per week in the office.
- The position is not eligible for visa sponsorship; candidates must be authorized to work in the United States without current or future employer sponsorship.
About Cboe Global Markets
Cboe Global Markets operates exchanges and market infrastructure for options, equities, futures, FX, ETPs, and digital assets used by brokers, banks, and institutional and retail investors. Its revenue comes from transaction and listing fees, market data and index licensing (including VIX and SPX), and related services. Founded in 1973 and headquartered in Chicago, it runs Cboe Options and Cboe Futures exchanges as well as European trading venues.