Junior Application Security Engineer

AbbVie

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Salary
$84,500–$162,000 / yr
Posted
9 days ago
Freshness
Confirmed live yesterday
Closes
Sep 1, 2126

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $177k
This role $123k
$69k most similar roles pay here $231k

This role pays less than 91% of similar roles. Most pay $145,700–$208,800 — the shaded band above. At the midpoint, this role pays about $123k versus about $177k for comparable roles.

Based on 240 similar postings.

Employer

About AbbVie

AbbVie is a global biopharmaceutical company focused on discovering and delivering innovative medicines and solutions in immunology, oncology, neuroscience, and eye care. Its products include Humira, Skyrizi, and Rinvoq.

AbbVie currently has 297 open roles on FindRole.

Listed pay typically runs $109,500–$208,500 across 271 roles with salary data.

Most-posted roles

View all roles at AbbVie

At a glance

TL;DR · Junior Application Security Engineer

As a Junior Application Security Engineer on the Information Security team, you will support and enhance inline code testing and reporting processes. You will be responsible for implementing and maintaining Application Security Testing tools including SAST, DAST, IAST, and SCA to identify vulnerabilities during the software development lifecycle. Additionally, you will manage Application Security Posture Management tools to centralize findings, integrate security tooling into CI/CD pipelines, and provide first-line support to developers regarding false positives and remediation guidance. The role requires proficiency in application security principles like OWASP Top 10, secure coding practices in Java and Node.js, and experience with containerization and cloud environments. You will also utilize Python for automation and manage tools such as Snyk and Endor Labs to resolve security risks across diverse development environments and business units.

What you'll do

  • Implement and maintain SAST, DAST, IAST, and SCA tools to identify code and dependency vulnerabilities.
  • Manage Application Security Posture Management (ASPM) tools to centralize and deduplicate security findings.
  • Integrate security testing tools directly into Continuous Integration and Continuous Deployment (CI/CD) pipelines.
  • Provide first-line support to developers by resolving false positives and providing remediation guidance.
  • Triage security risks at scale across various application development environments and business units.
  • Develop detailed reports regarding security findings and ongoing remediation efforts.
  • Evangelize secure development practices and communicate technical risks to both technical and non-technical stakeholders.

What we're looking for

  • Bachelor’s Degree and 5 years' experience; or Master's Degree and 4 years' experience.
  • Experience in application security and software development.
  • Experience implementing, administering, and supporting application security tooling such as SAST, DAST, IAST, and SCA.
  • Knowledge of secure coding practices across multiple programming languages, especially Java and Node.js.
  • Experience integrating security testing into CI/CD pipelines.
  • Knowledge of application security principles and common vulnerabilities like OWASP Top 10 and CWE.
  • Experience supporting developers with assessing and mitigating application security test findings.
  • Excellent written and oral English communication skills, including experience coaching junior engineers.
  • Experience implementing tooling to consolidate findings from multiple sources (preferred).
  • Experience administering Snyk and Endor Labs (preferred).
  • Experience integrating Cloud Security Posture Management (CSPM) tooling with application security pipelines (preferred).
  • Experience automating workflows via programming and scripting languages such as Python (preferred).
  • Experience building logging into DevSecOps pipelines to gain insights into pipeline performance (preferred).
  • Experience collaborating with vulnerability and risk management partners (preferred).

More like this

Similar roles

Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Senior Application Security Engineer

LPL Financial

Fort Mill, NC +5 32 days ago $100,631$167,787
Application Security OWASP Top 10 DevSecOps CI/CD IAST Burpsuite Postman Synopsys BlackDuck J-Frog PrismaCloud C# Java HTML CSS React Angular
5+ yrs exp Hybrid

Senior Application Security Engineer

Upstart

Remote (Canada) 7 days ago $166,900$230,900
Application Security Threat Modeling SAST DAST SCA CI/CD Python Java Go Ruby API Security Microservices GraphQL REST GenAI Secrets Management Cloud-Native AWS CISSP CSSLP CCSP
5+ yrs exp Remote

Application Security Engineer

State Street

Quincy, MA +4 14 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp