Engineer, Application Security
$78.21k - $114.65kKeHE Distributors
Why Work for KeHE? Full-time Pay Range: $78,210.00/Yr. - $114,648.00/Yr. Shift Days: , Shift Time: Benefits on Day 1 Health/Rx Dental Vision Flexible and health spending accounts (FSA/HSA) Supplemental life insurance 401(k) Paid time off Paid sick time Short term & long term disability coverage (STD/LTD) Employee stock ownership (ESOP) Holiday pay for company designated holidays Overview At KeHE, we’re obsessed with creating solutions, unboxing potential, and serving others – and it all starts with you. As an employee-owned distributor of natural and organic, specialty, and fresh products, we’re committed to making a positive impact and scaling our success together. With a culture that fosters development and opportunity, you’ll be embarking on a career that’s moving forward. When you join KeHE, you’re becoming part of a team that is a force for good Primary Responsibilities The Application Security Engineer (AppSec) reduces application and software risk by embedding security into the secure software development lifecycle (SSDLC). This role partners closely with engineering, infrastructure, and product teams to design secure architectures, perform threat modeling, implement security testing and CI/CD controls, and drive remediation of vulnerabilities. As the organization's AI adoption expands across business and engineering teams, the incumbent will help evaluate and shape security practices for emerging AI and agentic tools, including GenAI assessments and guardrail development as these programs mature. The role develops practical security standards, builds and operates a vulnerability operations function, improves developer enablement through reusable patterns and automation, and supports investigations related to application vulnerabilities, insecure configurations, or software supply chain risk. As with all positions at KeHE Distributors, all actions and responsibilities are expected to align with KeHE's Mission, Vision, and Values. Essential Functions DUTIES, TASKS AND RESPONSIBILITIES: Secure SDLC Integration: Partner with software engineering teams to embed security activities (design, build, test, deploy, operate) into the SDLC, including performing threat modeling and security design reviews. Standards & Patterns: Define, maintain, and promote "secure-by-default" coding standards, reusable security control patterns, and templates to scale consistent security practices. AppSec Tooling & Automation: Implement, operate, and continuously tune application security testing tools (SAST, DAST, SCA, secrets, containers, IaC) within CI/CD pipelines to ensure high-signal, actionable feedback. Risk-Based Vulnerability Management: Triage, validate, and prioritize application security findings based on business impact and exposure; track remediation SLAs, verify fixes, and document risk acceptances or compensating controls. Modern Architecture & Platform Security: Provide security guidance on modern architectures (APIs, microservices, cloud, serverless), focusing on identity/access management (RBAC, least privilege, token handling), rate limiting, and secure configurations. Supply Chain & Secrets Reduction: Mitigate software supply chain risks through strict dependency governance and secure artifact management, while driving improvements in secrets management to eliminate hard-coded credentials. Incident Response Support: Assist Security Operations and engineering teams with investigating AppSec incidents (e.g., exposed secrets, exploits), and lead post-incident reviews to implement preventative guardrails. Governance, Risk, & Compliance: Provide control evidence to support compliance audits and evaluate the security posture of third-party/vendor-integrated applications. Developer Enablement & Culture: Foster a strong security culture by delivering security training, hosting office hours, publishing developer-friendly documentation, and demonstrating company core values. AI & Agentic Tool Security: Oversee security for GenAI, RAG, and agentic tools by conducting OWASP LLM/Agentic Top 10 assessments, enforcing per-tool security checklists (blast-radius and data boundaries), and owning the security sign-off for POC-to-production decisions Other duties and projects as assigned. Minimum Requirements, Qualifications, Additional Skills, Aptitude SKILLS, KNOWLEDGE AND ABILITIES: Strong understanding of application security fundamentals and common vulnerability classes (e.g., OWASP Top 10) and secure coding practices. Experience conducting threat modeling and security design reviews; ability to identify abuse cases, trust boundaries, and mitigations. Hands-on experience with application security testing methodologies and tools (SAST/DAST/SCA, secrets scanning); ability to interpret results and drive remediation. Experience integrating security checks into CI/CD pipelines and developer workflows; familiarity with Git-based workflows and modern build/release practices. Ability to prioritize findings using risk context (asset criticality, exposure, exploitability, data sensitivity). Strong written and verbal communication skills; ability to translate security requirements into practical engineering actions. Experience securing cloud-native applications (AWS preferred; Azure exposure a plus) and modern architectures (APIs, containers, microservices, serverless). Familiarity with container and IaC security concepts (image scanning, Kubernetes security concepts, Terraform/CloudFormation scanning). Scripting/automation skills (Python, PowerShell, or similar) to improve scale and reduce manual work. Familiarity with secrets management tooling and practices (vaults, key management, rotation workflows). Familiarity with secure SDLC governance and control mapping to common frameworks (NIST CSF, CIS Controls, NIST 800-53). EDUCATION AND EXPERIENCE: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related field; or equivalent practical experience. 3–8+ years of experience in application security, secure software engineering, DevSecOps, or software development with significant security responsibilities. PHYSICAL REQUIREMENTS: This position operates in a hybrid working environment, with in-person presence preferred Tuesday, Wednesday, and Thursday (remote work available Monday and Friday, as business needs allow). Ability to work in a standard office environment which requires sitting and viewing monitor(s) for extended periods of time, operating Requisition ID 2026-29461 Equal Employer Opportunity Statement KeHE Distributors provides equal employment opportunities to all employees and applicants for employment and prohibits all forms of discrimination and harassment on the basis of race, color, religion or faith, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training as well as the administration of all Human Resources and Talent Acquisition processes. #J-18808-Ljbffr
- ...KeHE Distributors, LLC is seeking an Application Security Engineer to integrate security into the secure software development lifecycle. This role entails close collaboration with engineering and product teams to implement security testing and drive the remediation of...ApplicationFlexible hours
- ...moving forward. When you join KeHE, you’re becoming part of a team that is a force for good Responsibilities The Application Security Engineer (AppSec) reduces application and software risk by embedding security into the secure software development lifecycle (SSDLC...ApplicationWork at officeRemote workMonday to Friday
- ...Lead Engineer, Cloud Security Primary Location : Oak Brook, Illinois V-Soft Consulting is currently hiring for a Lead Engineer... ...based security events. Partner with Engineering, and Application Development teams to embed security into CI/CD pipelines....ApplicationCurrently hiringLocal area
$91k - $146k
...technology company located in Lisle, IL is seeking a skilled Software Engineer to join their CyberSecurity & Compliance team. The role involves developing and maintaining high-quality applications using Agile practices to create scalable RESTful APIs. Candidates should...Application- ...expertise in Microsoft SQL Server and Azure SQL services. Responsibilities include ensuring database performance and security while collaborating with application development teams. A Bachelor's degree is preferable, along with skills in T-SQL coding and database performance...Application
- ...The Senior Cyber Security Analyst position will provide security strategies, implement security initiatives, and respond to security... .... Protect Client on-premises and Cloud systems, networks, and applications against all security breaches. Act as a technical point of contact...ApplicationWork experience placementRemote work
$65 - $85 per hour
...level Type: Contract-to-Hire Primary Function: The Enterprise Applications & Integration Lead will be responsible for all operational and... ...eCommerce platform, Graphics pre-press applications & workflow engines, Store profile, Concur, Docuware, etc.) and will be...ApplicationContract workRemote work- ..., WPF, CSS, SAS. Design, develop, create and modify computer applications software and/or specialized utility programs. Analyze user needs... ..., Datastage). Qualifications Must have Master’s degree in Engineering, Computer Science or Information Systems or Bachelor’s degree...ApplicationRelocationShift work
- ...coordination of a diverse set of stakeholders, both internal and external, whom contribute to the design and development of Client's Kiosk #Application. This position may also be asked to take a leadership role on assignments and acts as a primary point of contact with...Application
- ...AWS Solutions Architects Experience in design & implementation experience with distributed applications, experience in networking; infrastructure or database architecture. Experience with “on-premise to cloud” migrations or IT transformations. Experience architecting/...Application
$125k - $140k
...If you are unable to complete this application due to a disability, contact this employer to... ...highly skilled and hands‑on Senior Network Engineer to support and drive our continued... ...designing, implementing, maintaining, and securing all aspects of our network infrastructure...ApplicationFull timeTemporary workFlexible hours$155k - $175k
...Staff Software Engineer, Platform Hybrid: In Office Every Thursday in Elmhurst, IL Required. Join MedSpeed and help deliver health!... ...architecting across multiple services, not just within a single application). Deep .NET expertise: C#, ASP.NET Core. Extensive production...ApplicationFor contractorsWork at officeFlexible hours$155k - $175k
...Description Staff Software Engineer, Platform Hybrid: In Office Every Thursday in... ...multiple services, not just within a single application) ~ Deep .NET expertise: C#, ASP.NET... ...requests personal information outside of our secure application process. All position...ApplicationFor contractorsWork at officeFlexible hours- ...process. Keen eye for design and attention to detail. ***Please include samples of your work or portfolio when submitting your application*** Compensation & Benefits Very competitive base salary along with an aggressive commission program. Full Benefits Package:...ApplicationFull timeTemporary workWork at officeFlexible hours
- ...project governance, UX/UI, multi-platform applications, quality assurance/testing, cloud... ...Veritas. Experience with Hosted UC engineering and operations would be a plus. Application... ...are aligned to the architectural and security guidelines • Experience architecting...ApplicationH1bLocal area
- ...looking for a Senior .Net Full Stack Developer to create scalable applications. This role encompasses back-end development with .NET Core and... ...developing APIs, optimizing SQL performance, and ensuring security compliance. The ideal candidate will have over 10 years in enterprise...Application
$65.52 - $101.56 per hour
...factors. Position Highlights: Position: Enterprise Security Architect Location: Skokie, IL Full Time Hours:... ...with IT Security, Enterprise Architecture, and technical and application engineering teams, as well as various clinical and non-clinical stakeholders...ApplicationHourly payFull timePart timeFor contractorsLocal areaMonday to Friday- ...Qualifications Requirements Familiarity with AI and generative AI tools (e.g., Copilot, ChatGPT, or similar) and their practical application in requirements gathering, analysis, documentation, and process improvement. Working knowledge of marketing concepts and end-...ApplicationLocal areaRemote workShift work
$114.52k - $130.76k
Job Summary: The Information Security Administrator III has overall responsibility for the administration of the Information Security... ...key infrastructure (PKI). Ensure compliance with all applicable internal and external Information Security requirements through...ApplicationTemporary workLocal areaFlexible hours- ...client interview at Oak Brook, IL – Office location Job Description Looking to add a Principal Full Stack Engineer who has experience developing enterprise applications using OO Design, Microservices architecture, SOLID Design principals and experience in leading team of...ApplicationContract workWork at officeLocal areaFlexible hours
$101.54k - $139.62k
...Application Analyst Sr. The Application Analyst, Sr for the Contact Center and My Account position within Gas Technology Services will have overall responsibility for helping to refine requirements and create functional and technical designs for custom applications to...ApplicationFull timeWork at officeLocal areaFlexible hours- 4 days ago Be among the first 25 applicants Bachelor’s degree in computer science, Information Technology, or a related field. Minimum of 10 years of experience in data integration and ETL development. Minimum of 7 years of hands-on experience with Informatica Intelligent...ApplicationFull time
- ...AWS Solutions Architects Experience in design and implementation of distributed applications, networking, infrastructure, or database architecture. Experience with on‑premise to cloud migrations or IT transformations. Experience architecting and operating solutions built...Application
- ...Intune, Autopilot, compliance policies, application deployment, update rings, and full... ...across recurring administrative tasks. Security and Compliance Partnership Partner with... ...documentation, and automation as core engineering practices. Direct access to leadership....ApplicationFull time
- ...Network Consultant Engineer, Oak Brook, IL The Network Consultant Engineer is a full time permanent position. Looking for well-rounded... ...on more challenging help desk issues (desktop, software applications, user endpoint issues, workstation migrations, hardware, internet...ApplicationPermanent employmentFull timeRemote work
- ...interiors and office furniture desired, but not required. Must be proficient in AutoCAD. Must be well-versed in Microsoft Office applications including PowerPoint, Excel and Word. Previous CRM experience & proficiency strongly preferred (i.e. NetSuite, Salesforce,...ApplicationWork at office
- ...Responsibilities: Engage and deploy client projects across ServiceNow applications (e.g., IRM, SecOps, etc.), ensuring high-quality delivery.... ...Bachelor's degree in Computer Science, Information Systems, Engineering, or related field preferred. ~ Willingness to travel as...Application
$155.55k - $160k
...aligned with business goals. - Design scalable, secure, and cost-effective cloud solutions. - Evaluate... ...related to Legacy modernization, migration of applications and infrastructure to hybrid cloud, Engineered cloud, etc. - Ensure optimal performance of cloud...Application- ...Forward Deployed Engineer IFS is a billion-dollar revenue company with 7000+ employees on all continents. Our leading AI technology... ..., Pinecone, Weaviate, etc.) ~ Familiarity with building LLM applications, RAG systems, or conversational AI workflows ~ Experience...ApplicationFor contractorsWorldwideFlexible hours
$43.89k - $48.28k
...and an online portfolio or resume links that reflect your social media and digital content development skills (required at time of application) Strong writing and editing skills with attention to detail Familiarity with existing and emerging social media platform...ApplicationCasual workInternshipH1bWork at officeWork visaMonday to FridayShift workAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Engineer, Application Security. Be the first to apply!
- application team lead Naperville, IL
- app Naperville, IL
- oracle apps technical consultant Naperville, IL
- senior application administrator Naperville, IL
- cash application representative Naperville, IL
- cash applications coordinator Naperville, IL
- app support Naperville, IL
- director of enterprise application services Naperville, IL
- director enterprise applications Naperville, IL
- cash application clerk Naperville, IL


