CybersecurityJobs.io
← Back to all jobs

Job Description

Wintrust Financial Corporation offers a security-focused environment where application protection, secure engineering practices, and continuous improvement are built into the SDLC. In this onsite Chicago role, you will help reduce risk across enterprise applications, APIs, and SaaS platforms while working with modern security tooling and AI-assisted engineering workflows. The role also includes benefits designed to support health, financial wellness, family needs, and professional growth.

What you’ll do

  • Lead application threat modeling, security architecture reviews, and manual code reviews, defining requirements for authentication, authorization, data protection, and secure design across web applications, APIs, and cloud-hosted services.
  • Implement and tune SAST and SCA with Checkmarx, and integrate DAST, secrets scanning, and risk-based security gates into CI/CD pipelines.
  • Support API discovery, posture assessment, security testing, and runtime monitoring using an enterprise API security toolset, investigating issues such as sensitive data exposure, broken authorization, and API abuse with application owners and security operations.
  • Design and implement AI-assisted SDLC workflows for code review, unit and integration test generation, security testing, vulnerability triage, and remediation, including human review and validation of AI-generated code and tests.
  • Drive vulnerability remediation using exploitability, exposure, and business impact, validate fixes, support incident response, and track testing coverage, remediation times, and recurring defects for risk and compliance reporting.
  • Coach developers on secure coding and maintain reusable security patterns and guidance, while evaluating AI workflow adoption, finding quality, test coverage, and time savings to improve both security and developer productivity.

What you’ll bring

  • 5-7 years of relevant experience (minimum 5 years).
  • Bachelor’s degree or equivalent; Computer Science or Cybersecurity preferred.
  • Preferred: application security, cybersecurity, and/or Artificial Intelligence certifications.
  • Experience in application security, secure development, or DevSecOps, including threat modeling, manual code review, API testing, vulnerability remediation, and Git-based CI/CD integration.
  • Ability to review Java, Apex, and/or Python code and build automation.
  • Knowledge of OWASP Top 10, API Security Top 10, ASVS, authentication, authorization, OAuth/OIDC, and secrets management.

Tools and technologies

  • Checkmarx
  • Akamai API Security
  • OWASP Top 10, API Security Top 10, ASVS
  • OAuth/OIDC
  • SAST, SCA, DAST
  • Git-based CI/CD
  • Java, Apex, Python

Benefits

  • Medical Insurance
  • Dental
  • Vision
  • Life insurance
  • Accidental death and dismemberment
  • Short-term and long term Disability Insurance
  • Parental Leave
  • Employee Assistance Program (EAP)
  • Traditional and Roth 401(k) with company match
  • Flexible Spending Account (FSA)
  • Employee Stock Purchase Plan at 5% discount
  • Critical Illness Insurance
  • Accident Insurance
  • Transportation and Commuting Benefits
  • Banking Benefits
  • Pet Insurance
  • Tuition reimbursement

Preferred experience

  • Experience implementing AI-assisted SDLC workflows for code review, test generation, security testing, and remediation, with measurable results.
  • Ability to apply human review, validate AI-generated code and tests, and protect sensitive data.
  • Experience with Checkmarx, Akamai API Security, or comparable tools.
  • Experience communicating risk and supporting regulated financial services.

Compensation

The estimated salary range for this role is $117,000 - $158,000 per year, along with eligibility to earn an annual bonus. Actual salaries may vary based on qualifications, skills, and experience.

Similar Jobs