Alliant Credit Union Logo

Alliant Credit Union

Application Security Engineer (Perm - Hybrid or Remote)

Sorry, this job was removed Sorry, this job was removed at 06:01 p.m. (CST) on Thursday, Apr 24, 2025
Remote
Hybrid
Hiring Remotely in Chicago, IL
113K-160K Annually
Remote
Hybrid
Hiring Remotely in Chicago, IL
113K-160K Annually

The Application Security Engineer will be responsible for validating application services that are designed and implemented with high security standards. Analyze the security (Red - Offense) of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Address legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. Communicate with technical and leadership teams to ensure a focus on risk mitigation to allow for business continuity. Assess applications for weaknesses and find resolutions before they can be abused and the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. Recommend programmatic controls, and monitor and manage secure development practices to address modern day issues.
Responsibilities

  • Perform vulnerability and penetration testing (Red - Offense), document security findings and focus on automation to aid inefficiencies with both testing and remediation of findings.
  • Collaborate with developers to provide repetitive validation testing prior to production while allowing for a continuous cycle of development followed by application security assessments.
  • Monitor the security community for public-facing security issues, as well as learn new tactics that can be used in testing.
  • Collaborate in application projects and change management committees. Understand what is coming and how their projects can be more secure from the start.
  • Follow a security review process to ensure an automated and repeatable process is managed. This can be through the use of dynamic and static code analysis resources.
  • Use security standards, implementation configurations and common security frameworks to prepare for and manage bug bounty programs. Document delivery and implementation advances that meet defined service-level agreements (SLAs) and business metrics. Align with architects and development teams for a mission of secure design.
  • Train developers and junior application security engineers on secure coding practices. Participate and lead security team meetings that facilitate secure design.
  • Engage in information security projects that evaluate existing security infrastructure and propose changes as defined by security leadership and architects.
  • Focus on application security that observes compliance such as Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), etc. - and privacy laws.
  • Handle service and escalation tickets within SLA expectations.
  • Develop security test plans from the architectural design. Identify deficiencies and make enhancements to ensure production is not impacted.
  • Drive security efficiencies, enabling security team members to work on more advanced tasks.
  • Conduct performance testing to stress the limitations of security solutions while ensuring business innovation and day-to-day processes are not negatively impacted.


Education:

  • Bachelors Degree - Computer Science or related - Minimum
  • Graduate Degree - Computer Science or related - Preferred


Years of Experience:

  • 3 Years - Cybersecurity, application programming, compliance, risk management, network security engineering, threat modeling applications or related - Minimum


In Lieu of Education:

  • 6 years - Cybersecurity, application programming, compliance, risk management, network security engineering, threat modeling applications or related


License/Certifications/Training:

  • Preferred: Security certifications GWAPT, CISSP, OSCP, or other similar


Compensation & Benefits:
Typical hiring range:‏‏‎ ‎$113,000‏‏‎ ‎-‏‏‎ ‎$159,550 Annually. Actual compensation will be determined using factors such as experience, skills & knowledge.
Additional Compensation: Annual performance bonus
Benefits: Alliant provides a benefits package including health care, vision, dental, and 401k with employer match.
Additional Benefits:

  • Work from home up to 3 days a week
  • Paid parental leave
  • Employee discount programs
  • Time off including paid personal and sick days
  • 11 paid holidays
  • Education reimbursement


*Note that eligibility and cost of benefits can vary depending on the number of regularly scheduled hours, and job status such as regular full-time, regular part-time, or temporary employment.
Adhere to and ensure compliance of all business transactions with policy and process of the Bank Secrecy Act. Ensures compliance with all applicable state and federal laws, company procedures and policies. Maintains integrity and ethics in all actions and conversations with or regarding credit union members and their accounts; complies with Privacy Act directives.
The responsibilities listed do not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice.

Similar Jobs at Alliant Credit Union

3 Days Ago
Remote
Hybrid
Chicago, IL, USA
113K-160K Annually
Mid level
113K-160K Annually
Mid level
Fintech • Financial Services
The Application Security Engineer validates applications against security standards, conducts vulnerability testing, collaborates with developers, and trains them on secure coding practices.
Top Skills: Dynamic Code AnalysisPenetration TestingStatic Code AnalysisVulnerability Testing
3 Days Ago
Remote
Hybrid
Chicago, IL, USA
113K-160K Annually
Mid level
113K-160K Annually
Mid level
Fintech • Financial Services
The Application Security Engineer validates applications against security standards, conducts vulnerability testing, collaborates with developers, and trains them on secure coding practices.
Top Skills: Dynamic Code AnalysisPenetration TestingStatic Code AnalysisVulnerability Testing
87K-123K Annually
Senior level
Fintech • Financial Services
The CRA Advisor implements and maintains Alliant's Fair & Responsible Banking program, advises on compliance, and analyzes lending activity under the IL CRA.
Top Skills: Cra WizHmda

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account