The Technology Engineer for Application Security at PNC Financial Services Group concentrates on Java and .NET to identify, evaluate, and mitigate security risks across the software development lifecycle, while promoting secure coding practices. This onsite role is based in Lakewood, Colorado.
Responsibilities
- Demonstrate strong verbal and written communication abilities to convey security concepts clearly.
- Identify, evaluate, and mitigate application security risks throughout the full software development lifecycle (SDLC).
- Apply a software development background, preferably in Java and/or .NET, to security practice.
- Showcase hands-on software development experience with deep knowledge of application security requirements.
- Maintain practical awareness of the OWASP Top 10 web application risks and advise teams on effective mitigation techniques.
- Triaging and remediation of web application security vulnerabilities is essential.
- IAST familiarity is preferred though not mandatory.
- Experience in incident response related to application attacks is advantageous.
- Manually validate compensating controls to ensure vulnerabilities are addressed when direct remediation is not immediately possible.
- Collaborate with application and engineering teams to foster secure coding practices and strengthen overall security posture.
- Analyze and manually validate software vulnerabilities, distinguish legitimate threats from false positives, and coordinate remediation with affected teams.
- Leverage technical expertise to design, build, and maintain technology solutions; assist in selecting platforms and in integration and configuration.
- Contribute to the development of software components and hardware for new and emerging technology projects aligned with business objectives.
- Provide guidance to junior staff regarding common issues and best practices.
- Deliver systematic analysis of client requirements within a traceability framework and resolve functional problems encountered.
- Ensure the quality of project deliverables while maintaining compliance with applicable standards and processes.
Requirements
- Strong verbal and written communication skills.
- Ability to identify, evaluate, and mitigate application security risks across the SDLC.
- Software development background with preference for Java and/or .NET experience.
- Demonstrated software development experience with comprehensive knowledge of application security.
- Solid understanding of the OWASP Top 10 web application risks with ability to guide mitigation efforts.
- Proficiency in triaging and remediating web application security vulnerabilities.
- IAST familiarity is preferred.
- Experience in incident response related to application attacks.
- Capability to manually validate compensating controls to ensure issues are addressed when direct remediation is not immediately possible.
- Collaborative approach with application and engineering teams to improve secure coding practices.
- Ability to analyze and validate software vulnerabilities, differentiate true attacks from false positives, and coordinate remediation.
- Minimum 3+ years of relevant direct industry experience.
- In lieu of a degree, a comparable combination of education, certifications, and experience may be considered; a Bachelor's degree is listed as standard.
Technologies
Benefits
- Medical and prescription drug coverage with a Health Savings Account option
- Dental and vision coverage
- Life insurance for employees and spouses/children
- Short and long-term disability protection
- 401(k) plan with company match, pension and stock purchase options
- Dependent care reimbursement account
- Back-up child and elder care support
- Adoption, surrogacy, and doula reimbursement
- Educational assistance, including select programs fully paid
- Wellness program with financial incentives
- Maternity and parental leave
- Up to 11 paid holidays per year
- Up to 9 occasional absence days per year
- 15 to 25 vacation days per year, based on career level
Pay Transparency
- Base Salary: $86,250.00 – $158,125.00
- Salaries may vary by geographic location, market data, and individual skills, experience, and education. This role is incentive eligible, with pay based on company, business, and individual performance.
Application Window
This opening is typically posted for two business days from 07/14/2026, though the duration may be extended at management discretion.
Job Description
The role leverages technical knowledge and industry experience to design, build, and maintain technology solutions. It involves selecting appropriate platforms, integrating and configuring solutions, and developing software components and hardware for new and emerging technology projects aligned with business strategies. The position may provide guidance to junior staff and requires systematic analysis of client requirements within a traceability framework, resolution of functional problems, and ensuring deliverables meet quality standards and compliance with relevant processes.
Disability Accommodations
If you require an accommodation to participate in the application process, please email AccommodationRequest@pnc.com with "accommodation request" in the subject line and include your name, the job ID, and your preferred contact method in the body. Emails not related to accommodation requests will not receive responses. You may also call 877-968-7762 and say "Workday" for assistance. PNC provides reasonable accommodations to employment applicants and qualified individuals with disabilities to perform essential job functions.
Equal Employment Opportunity
PNC is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other legally protected characteristics.
California Residents
Refer to the California Consumer Privacy Act Privacy Notice to understand how PNC may use or disclose your personal information in our hiring practices.