Jobs › Companies › Cboe Global Markets › Principal Application Security Engineer

Sobre este puesto de Principal Application Security Engineer en Cboe Global Markets

Cboe Global Markets · Presencial · Chicago, IL

Job Description:

Building trusted markets — powered by our people 

At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world. 

We’re building meaningful ways to support professional and personal development while strengthening the trust we’ve earned as a global market leader. Our teams are empowered to share ideas, actively pursue them and bring on a challenge. As champions of internal mobility and access to opportunity, we encourage our people to “go for it” and equip our managers with the training to coach their teams to the next level. We strive to provide employees a safe space to network, share ideas and create opportunities.  

To support strong partnership and team connection, this role follows a four day in office work model.

Location Overview

Cboe HQ is located in the historic Old Post Office district, it’s a landmark that blends classic architecture with modern amenities. The building features expansive spaces with high ceilings and large windows, offering an abundance of natural light and panoramic views of the city skyline and the Chicago River.

With its prime location in the heart of downtown, the OPO Building provides easy access to major transportation hubs, including Union Station and multiple CTA lines, making it convenient for commuters. The building is home to a variety of amenities, including restaurants, a fitness center, and collaborative workspaces, creating a vibrant and dynamic work environment in one of Chicago's most iconic areas.

Role Overview

Cboe’s Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our hybrid engineering ecosystem. In this role, you will partner closely with application, platform, and infrastructure teams to define secure-by-default architecture patterns, shape strategic security direction, and drive implementation of security controls throughout the software development lifecycle (SDLC) across microservices, APIs, and containerized workloads operating in both public cloud and on-premises Kubernetes environments.

You will operate as a principal-level individual contributor with broad technical influence, accountable for setting direction in complex or ambiguous situations, making high-impact architectural decisions, and driving consistent security outcomes across multiple teams and platforms. This role requires deep hands-on expertise, strong systems thinking, and the ability to influence engineering practices, standards, and priorities at scale while serving as a trusted technical leader for both security and engineering stakeholders.

This position reports to the Senior Manager, Application and Cloud Security.

Your responsibilities will be:

Application & API Security

  • Own secure architecture reviews and threat modeling for new systems and major changes, establishing architectural direction for Kubernetes trust boundaries, secure service-to-service communication, and API authorization models across the environment
  • Define, mature, and drive adoption of application and API security standards, including authentication and authorization patterns, input validation requirements, and mitigations for common vulnerability classes such as SSRF, injection, and access control flaws
  • Provide principal-level guidance for high-risk code and design changes, resolving complex security tradeoffs and driving remediation approaches that are durable, scalable, and aligned to engineering realities
  • Act as a senior technical partner to engineering leadership, influencing roadmaps, architecture decisions, and secure-by-default design patterns across the organization

Kubernetes, Container & DevSecOps Security

  • Own Kubernetes workload security standards across multi-cluster environments, setting technical direction for RBAC, pod security controls, namespace isolation, network policies, secrets management, and platform guardrails
  • Establish and continuously evolve the container image security strategy, including secure base image standards, vulnerability management expectations, SBOM practices, and deployment controls that prevent risky configurations from reaching production
  • Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines, ensuring SAST, SCA, secret scanning, container scanning, and IaC scanning are integrated through high-signal workflows that scale across engineering teams with minimal developer friction

Software Vulnerability Management & Security Enablement

  • Own the strategy for risk-based software vulnerability management, including triage, exploitability assessment, remediation priorities, service level expectations, and metrics that demonstrate measurable reduction in security risk over time
  • Develop and champion secure coding guidance, reusable security patterns, and enablement programs that raise engineering capability and create lasting improvements in how teams design and build software
  • Lead security design support during incident response and post-incident follow-through, translating lessons learned into durable architectural, control, and guardrail improvements that prevent recurrence

AI Implementation Security

  • Own the secure adoption of AI-enabled development and security capabilities, establishing patterns and guardrails for secure code review, automated assessments, and process improvements throughout the SDLC.
  • Provide principal-level architecture and risk guidance for AI implementations and integrations, shaping secure design decisions, control expectations, and review practices for emerging use cases.
  • Drive governance and technical controls to define, monitor, and enforce data boundaries, permissions, and approved usage patterns for AI-related data access.

The ideal candidate has

  • 12+ years of experience in application security, product security, or software engineering, including significant experience shaping architecture, setting standards, and driving security outcomes across complex production environments
  • Experience directly writing and delivering production software as a software engineer
  • Bachelor's degree in Computer Science, Information Security, or related field preferred
  • Relevant certifications preferred (e.g., CSSLP, CKS, OSCP, AWS/Azure Security Specialty)
  • Proven ability to read, write, and review production-grade code in at least one modern backend language (e.g., C++, Go, Java, C#, Python, Node.js), with the judgment to guide secure engineering decisions in high-impact systems
  • Strong working knowledge of Kubernetes security primitives (RBAC, namespaces, service accounts, pod security) and container build practices
  • Hands-on experience integrating DevSecOps tooling (SAST, SCA, secret scanning, IaC/container scanning) into CI/CD pipelines
  • Experience securing hybrid environments with workloads running in both public cloud (EKS, AKS, GKE) and on-prem Kubernetes platforms
  • Exceptional communication, influence, and technical leadership skills, with a demonstrated ability to drive alignment, establish direction, and own outcomes across engineering, platform, and security stakeholders

Benefits and Perks

We value the total wellbeing of our people – including health, financial, personal and social wellness. We believe standard benefits like health insurance and fair pay are given at any organization. Still, you should know what we offer:

  • Medical Coverage
  • Prescription Drug Coverage
  • Additional Medical Benefit
  • Dental Coverage
  • Vision Coverage
  • 401K or Pension Company Match
  • Spending Accounts
  • Life and AD&D Insurance
  • Retirement Savings Plan
  • Employee Stock Purchase Plan (ESPP)
  • Voluntary & Additional Benefits
  • Paid Time Off

More About Cboe Global Markets

We’re reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We’re investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed.

We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We’re an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.

Learn more about life at Cboe on LinkedIn and Cboe.com.

Equal Employment Opportunity

We’re proud to be an equal opportunity employer do not discriminate against any employee or applicant for employment based on any legally protected characteristic, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or veteran status. We are committed to fostering a workplace where all individuals are valued and respected.

#LI-CP1


 

This position is not eligible for visa sponsorship. Candidates must be legally authorized to work in the United States without the need for employer sponsorship now or in the future.

 

 

Salary Ranges (applicable for US locations only)

At Cboe, we are committed to providing a competitive, transparent, and market‑informed total rewards program. The anticipated base salary range for this role is $163,625-$211,750, with actual compensation determined by job‑related factors such as skills, relevant experience, education, internal alignment, and location.

 

 

This role may also be eligible for annual incentive compensation and, where applicable, participation in Cboe's long-term equity programs.

Additional information about Cboe's total rewards program, including benefits and other compensation components, can be found here: Total Rewards at CBOE.​
 


 

Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.

¿Listo para postularte en Cboe Global Markets?
Postúlate en Cboe Global Markets

Cómo se compara este salario de Application Security

Este puesto paga $187,688/yr — en línea con el rango típico para los puestos de Application Security.

$121,602 la mediana de $187,688 $265,600

Rango típico $138,260–$261,000/yr, a partir de 7 ofertas comparables de Application Security en JobsRadar (salario anualizado en USD). Ver datos salariales de Application Security →

Sobre Cboe Global Markets

Cboe is always looking for intelligent, innovative and hard-working individuals. Our success is based on our talented team of industry and technology professionals, which we believe is the strongest in the industry, and we pride ourselves on hiring the best and brightest. Cboe Global Markets is an Equal Opportunity Employer. For more information, please click the following links: Equal Employment Opportunity is The Law (in English) Equal Employment Opportunity is The Law (in Spanish) Equal Employment Opportunity is The Law (Supplement) E-Verify Participation Poster (English & Spanish) Right to Work Poster (English) Right to Work Poster (Spanish)

Ver todos los empleos en Cboe Global Markets →

Empleos similares

CG
Engineer, Application Security
Cboe Global Markets
⚡ Postúlate pronto Chicago, IL Presencial $102,850–$133,100
● Nuevo 👁 Visto ✓ Postulado hace 2d
Ripple
Senior Staff Security Engineer, Product Security
Ripple
⚡ Postúlate pronto Chicago, Illinois, United Stat... Presencial $220,000–$300,000
● Nuevo 👁 Visto ✓ Postulado hace 2d
Ripple
Senior Staff Security Engineer, Product Security
Ripple
⚡ Postúlate pronto New York, NY, United States Presencial $224,000–$300,000
● Nuevo 👁 Visto ✓ Postulado hace 2d
Ripple
Senior Staff Security Engineer, Product Security
Ripple
⚡ Postúlate pronto San Francisco, CA, United Stat... Presencial $232,000–$310,000
● Nuevo 👁 Visto ✓ Postulado hace 2d
Beyond Finance
Senior Application Security Engineer
Beyond Finance
⚡ Postúlate pronto Remote · restringido por ubicación $140,000–$165,000
● Nuevo 👁 Visto ✓ Postulado hace 3sem
Ann & Robert H. Lurie Children's Hospital of Chicago
IT Systems Engineer Sr - Application Security
Ann & Robert H. Lurie Children's Hospital of Chicago
⚡ Postúlate pronto Streeterville, Chicago, IL Presencial $93,600–$154,440
● Nuevo 👁 Visto ✓ Postulado hace 1 mes
Ascensus
Application Security Engineer, Information Security
Ascensus
⚡ Postúlate pronto Dresher, PA Presencial
● Nuevo 👁 Visto ✓ Postulado hace 5h
TraceLink, Inc
Product Security Engineer, Senior
TraceLink, Inc
⚡ Postúlate pronto APAC - India - Pune Presencial
● Nuevo 👁 Visto ✓ Postulado hace 6h
RB
Senior Software Engineer, Application Security (Global Security)
RBC
⚡ Postúlate pronto 16 YORK ST:TORONTO Presencial
● Nuevo 👁 Visto ✓ Postulado hace 7h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Cboe Global Markets

Ver todos los empleos en Cboe Global Markets →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis