Senior Application Security Engineer
Senior
Application Security
Bug Bounty
Cloud Platforms
Cybersecurity Tools
Data Security
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Offensive Security
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Security Testing Tools
Software Composition Analysis
Software Security
Software Supply Chain Security
Solution Architecture
Static Application Security Testing
Job Description
Join Caterpillar’s Cybersecurity team within Cat Digital to strengthen how application development and delivery are secured across a portfolio of related applications. As a senior application security engineer, you will work alongside software engineers and technical leaders to identify, validate, and remediate security defects, while helping teams improve their security maturity through tooling, guidance, and structured review processes.
Role focus
- Guide software engineers on securing application development and delivery within Cat Digital.
- Support security defect management, security consulting, tool enablement, security test onboarding, maturity measurement, and correction of error reports.
Responsibilities
- Analyze, validate, communicate, and consult on security defects found through automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, and bug bounty activities.
- Act as a close technical partner to software engineers, architects, product owners, and leaders by providing context-aware guidance that supports good decision-making, documenting decisions and resulting architectures, and navigating relevant review and approval processes when implementing new features or remediating existing issues.
- Enable and monitor automated defect detection tooling (including CodeQL and Rapid7) at the repository or application level according to the established process.
- Collect and communicate required scope and access information for penetration testing and security assurance assessments, and process the outputs through the organization’s Defect Management Process.
- Consult with software engineers on practices that improve application security maturity based on Cat Digital scorecards and maturity models.
- In partnership with software engineers, author corrections to error reports that help engineers and architects across Cat Digital avoid similar mistakes.
- Work as a technical engineer within a portfolio of related applications to influence security and prioritization decisions at the bug or story level while helping teams deliver solutions securely.
Required background
- Knowledge of decision-making processes and the associated tools and techniques, with the ability to analyze situations and make productive, informed judgments.
- Understanding of effective communication concepts and techniques to transmit, receive, and accurately interpret ideas and needs.
- Knowledge of the software development life cycle and the ability to use structured methodology for delivering and managing new or enhanced software products.
- Knowledge of software integration processes and functions, including designing, developing, and maintaining interfaces and linkages to alternative platforms and software packages.
- Knowledge of software product design, including translating market requirements into product design.
- Experience as a software engineer in any language or framework, with a preference for cybersecurity-related focus.
- Experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
- Experience analyzing and remediating security findings from automated and manual sources including SAST, DAST, penetration testing, and SCA.
- Experience leveraging secure coding and decision-making resources including OWASP Top 10, MITRE CWE Top 25, and OWASP ASVS, plus other industry-standard best-practice guides or frameworks.
- Experience building or supporting web applications and APIs, including SPA and RESTful APIs.
- Professional certifications in cybersecurity or software engineering, such as major cloud provider associate/professional certifications, CompTIA Security+, Cloud+, CCSK, and/or ISC2 Certified Software Lifecycle Professional (CSLP).
Technologies you may work with
- CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty
- Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- OWASP Top 10, MITRE Common Weakness Enumeration (CWE) Top 25, OWASP Application Security Verification Standard (ASVS)
- AWS, Azure, GCP, Salesforce
- Single Page Applications (SPA), RESTful APIs
- CompTIA Security+, Cloud+, CCSK, ISC2 Certified Software Lifecycle Professional (CSLP)
Location and eligibility details
- Based in Chicago, IL (onsite)
- The candidate can be based in Chicago, IL; Peoria, IL; or Dallas, TX
- Relocation assistance: NOT available
- Visa sponsorship: NOT available
Compensation
- Salary range: USD 112,710 - 183,140 per year
- Compensation and benefits may vary based on job level, market location, knowledge, skills, and performance
Benefits
- Medical, dental, and vision benefits*
- Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
- 401(k) savings plans*
- Health Savings Account (HSA)*
- Flexible Spending Accounts (FSAs)*
- Health Lifestyle Programs*
- Employee Assistance Program*
- Voluntary Benefits and Employee Discounts*
- Career Development*
- Incentive bonus*
- Disability benefits
- Life Insurance
- Parental leave
- Adoption benefits
- Tuition Reimbursement
- Benefits also apply to part-time employees
Posting and screening
- Posting dates: September 22, 2026 - October 4, 2026
- Employment is conditioned on successful completion of a drug screen