Engineer, Application Security
Job Description
Join Cboe’s Cybersecurity team as an Application Security Engineer focused on securing containerized services running on Kubernetes.
Responsibilities
- Partner with engineering teams to strengthen the security posture of containerized services on Kubernetes
- Participate in secure design reviews and threat modeling for new features, services, and APIs
- Conduct code-level security reviews and provide developers clear, actionable remediation guidance
- Integrate and operate application security tooling within CI/CD pipelines, including:
- SAST
- Dependency and container image scanning (SCA)
- Secret detection
- Validate and triage security findings by distinguishing true risk from false positives and helping prioritize remediation based on impact
- Improve container image security practices, including secure base image usage, dependency hygiene, and attack surface reduction
- Help define and apply secure coding and deployment standards for Kubernetes workloads, APIs, and service-to-service communication
- Support incident response and post-incident reviews by helping analyze root causes and contributing to preventative fixes
- Continuously build application and Kubernetes security skills through hands-on work and mentorship from senior team members
Requirements
- 2+ years of professional experience in software engineering, application security, or a closely related role
- Bachelor’s degree in Computer Science, Information Security, or a related field
- Hands-on software development experience, including building, testing, and deploying production services, with comfort reading and modifying existing codebases
- Experience building and running Docker/OCI containers, including understanding container images, layers, and runtime behavior
- Familiarity with Kubernetes, including deploying or supporting applications and working with core primitives (pods, deployments, services, ingress) and security basics (RBAC, namespaces, service accounts)
- Working knowledge of common web and API vulnerabilities and secure coding practices (including authentication/authorization issues, injection, SSRF)
- Proficiency in at least one backend programming language (Go, Java, C#, Python, or Node.js) plus experience with modern CI/CD workflows and Git-based development
- Exposure to application security tooling such as SAST, dependency or container image scanning, or secret scanning tools
- Bachelor’s degree preferred
Technologies
- Kubernetes
- Docker
- OCI
- SAST
- SCA
- Secret detection
- RBAC
- Namespaces
- Service accounts
- Pods
- Deployments
- Services
- Ingress
- Go
- Java
- C#
- Python
- Node.js
- CI/CD
- Git
Benefits
- Fair and competitive salary and incentive compensation packages with an upside for overachievement
- Generous paid time off: vacation, personal days, sick days, and annual community service days
- Health, dental and vision benefits, including access to telemedicine and mental health services
- 2:1 401(k) match, up to 8% match immediately upon hire
- Discounted Employee Stock Purchase Plan
- Tax Savings Accounts for health, dependent and transportation
- Employee referral bonus program
- Volunteer opportunities to support community involvement
- Paid Tuition assistance and education opportunities
- Generous charitable giving company match
- Paid parental leave and fertility benefits
Location
- Chicago, IL (onsite)
Compensation
- Base salary range (US locations only): $102,850-$133,100 per year
- Actual compensation determined by job-related factors including skills, relevant experience, education, internal alignment, and location
- May be eligible for annual incentive compensation and participation in Cboe long-term equity programs where applicable
Role overview: Works closely with application and platform engineering teams to design, build, and deploy secure containerized services on Kubernetes, applying security fundamentals within defined processes and with guidance from senior engineers. Reports to the Manager, Cybersecurity.