Senior IT Systems Engineer, Application Security

Ann & Robert H. Lurie Children's Hospital of Chicago

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Salary
$93,600–$154,440 / yr
Posted
35 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $174k
This role $124k
$79k most similar roles pay here $229k

This role pays less than 87% of similar roles. Most pay $145,000–$203,750 — the shaded band above. At the midpoint, this role pays about $124k versus about $174k for comparable roles.

Based on 240 similar postings.

Employer

About Ann & Robert H. Lurie Children's Hospital of Chicago

Ann & Robert H. Lurie Children''s Hospital of Chicago is a nationally ranked pediatric hospital providing comprehensive care across more than 70 specialties, affiliated with Northwestern University Feinberg School of Medicine. Industry: Pediatric Healthcare

Ann & Robert H. Lurie Children's Hospital of Chicago currently has 5 open roles on FindRole.

Most-posted roles

View all roles at Ann & Robert H. Lurie Children's Hospital of Chicago

At a glance

TL;DR · Senior IT Systems Engineer, Application Security

IT Systems Engineer Sr - Application Security serves as a technical authority for application and integration risk within a complex healthcare environment. The role involves implementing, validating, and maintaining security controls across the entire application stack, including database, middleware, web server, API, and presentation layers. You will manage a portfolio of over 250 commercial and third-party applications by identifying vulnerabilities, enforcing authentication and authorization models like SSO and OAuth, and managing secrets and encryption. Key responsibilities include remediating risks found through Qualys, Metasploit, SAST/DAST tools, and configuration reviews while ensuring secure-by-default deployments. Required skills include expertise in OWASP Top 10, CIS Controls, and network security elements like WAFs and firewalls. The position requires a deep understanding of credential management and the ability to translate technical risks into business impacts for stakeholders.

What you'll do

  • Implement, validate, and maintain security controls across database, middleware, web server, API, and presentation layers.
  • Manage application and integration risks for over 250 commercial and third-party applications.
  • Identify and remediate vulnerabilities in third-party applications, APIs, system integrations, and automated file transfers.
  • Secure internet-facing applications by identifying exposed access points and prioritizing high-risk entry vectors.
  • Enforce standardized security controls for authentication, authorization, credential management, encryption, and secure communication patterns.
  • Partner with vendors and internal owners to eliminate insecure configurations and excessive access permissions.
  • Evaluate and secure applications throughout their entire lifecycle from procurement through ongoing operations.
  • Drive the remediation of vulnerabilities identified through scanning tools like Qualys and other security testing methods.

What we're looking for

  • Bachelor's Degree in Computer Science, Information Security, Information Systems, or related field, or equivalent work experience.
  • 3–7+ years of experience in application security, cybersecurity, or enterprise application support.
  • Strong understanding of application-layer attack paths, including credential compromise, integration abuse, API exploitation, and external exposure risks.
  • Deep knowledge of authentication/authorization models (SSO, OAuth), encryption, data protection, and secure communication patterns.
  • Familiarity with OWASP Top 10, IAM concepts, CIS Controls, and Benchmarks.
  • Experience with vulnerability scanning and testing tools such as Qualys, Metasploit, SAST/DAST, and configuration analysis tools.
  • Experience in large enterprise environments with multiple commercial applications and integrations (preferred).
  • Experience within a healthcare provider environment (desirable); security certifications like CISSP, CSSLP, GWAPT, CASE, CEH, or OSCP are beneficial (preferred).

More like this

Similar roles

Junior Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Senior Application Security Engineer

LPL Financial

Fort Mill, NC +5 32 days ago $100,631$167,787
Application Security OWASP Top 10 DevSecOps CI/CD IAST Burpsuite Postman Synopsys BlackDuck J-Frog PrismaCloud C# Java HTML CSS React Angular
5+ yrs exp Hybrid

Application Security Engineer

Leidos

Ashburn, VA 60 days ago $107,900$195,050
Application Security SAST DAST SCA SDLC Machine Learning Artificial Intelligence Container Security Anchore Kubernetes Rancher Cloudera Salt Ansible CI/CD Elasticsearch GitLab
8+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Senior Application Security Engineer

AbbVie

Irvine, CA 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp