CDW
Posted 1w ago

Principal Application Security Engineer

CDW
United States or Illinois
$172k-$240k/yrRemoteFull Time
Responsibilities
  • leading code reviews
  • driving remediation
  • defining standards
Requirements
  • 10+ years in application security engineering
  • With deep expertise in secure architecture
  • Coding
  • Vulnerability analysis
  • Threat modeling
  • API security
  • CI/CD controls, and modern application technology stacks
Technical tools mentioned
C#JavaPythonJavaScriptTypeScriptGoSASTSCADASTIaCSBOMTerraformAzureAWSGCPAkamaiWAFLLM

Job description

Job Summary

Join CDW and help secure the software, platforms, and services that support more than 250,000 customers across enterprise, government, education, and healthcare. As part of CDW’s Global Information Security team, you will help shape how application security is embedded into engineering at scale—partnering across development, platform engineering, SRE, and DevOps to reduce risk while enabling delivery. 

As a Principal Application Security Engineer, you will serve as a senior technical leader and trusted advisor who helps influence secure engineering practices across the enterprise. You will bring deep hands-on application security expertise while enabling teams to adopt scalable patterns, controls, and guardrails across applications, APIs, and software delivery pipelines. This role is ideal for someone who can move fluidly between strategy and execution—shaping direction, building trust through influence, and diving into technical detail when needed. 

What you will do

  • Lead high-impact secure code reviews, threat models, and secure design assessments for applications, APIs, and shared services—translating technical risk into clear guidance for engineers, technical leaders, and business stakeholders. 
  • Drive the design, integration, and continuous improvement of application security controls across CI/CD platforms, workflows, and environments in close partnership with engineering, DevOps, and platform teams. 
  • Identify control gaps, coverage weaknesses, and sources of engineering friction across the software delivery lifecycle, and drive practical remediation through automation, platform improvements, and secure-by-design patterns. 
  • Define, advocate for, and build secure coding standards, reference architectures, playbooks, tooling, and automations that scale application security without slowing delivery. 
  • Serve as a senior technical partner to engineering teams by influencing design decisions, guiding remediation strategy, and helping embed security into how software is built and deployed. 
  • Advance CDW’s approach to securing AI-enabled development and applications by evaluating emerging risks, defining practical guardrails, and promoting responsible use of AI as a force multiplier for engineering and security outcomes. 
  • Provide deep subject matter expertise in API security, including authentication and authorization models, protections, monitoring, and secure integration patterns across modern application ecosystems. 
  • Partner with web and platform teams to design, deploy, and tune application-layer protections such as WAF rules and policies. 

What we expect of you

  • 10+ years of experience in Application Security Engineering, including hands-on work embedding security into software design, development, and delivery practices. 
  • Deep, hands-on expertise in secure application architecture and design, secure coding practices, code-level vulnerability analysis, and threat modeling. 
  • Background in software engineering, application development, or architecture, with the ability to engage credibly at the design, code, build, or runtime levels. 
  • Strong command of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns, including OWASP Top 10 classes, injection, deserialization, SSRF, insecure design, access control issues, and dependency risk. 
  • Hands-on experience securing applications built in one or more modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar. 
  • Strong experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms, including technologies such as SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain security controls. 
  • Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation while moving fluidly between enterprise patterns and code-level detail. 
  • Strong written and verbal communication skills with the ability to influence engineers, platform teams, and senior stakeholders through technical credibility, sound judgment, and partnership. 
  • Strong sense of ownership and accountability, with the ability to balance hands-on technical execution with mentoring others, raising standards, and driving organization-wide improvements in application security. 
  • Experience defining standards, playbooks, secure reference architectures, or scalable practices that can be adopted broadly across engineering organizations. 
  • Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance, a plus.
  • Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI or LLM-based capabilities, a plus.
  • Familiarity with Zero Trust, secure platform engineering, and policy-as-code approaches, a plus.
  • Prior experience serving as an Application Security Champion, Security Champion, embedded security lead, principal engineer, or senior engineer responsible for driving security within product or application teams, a plus.
  • Experience with runtime application protection, exploit prevention, threat detection technologies, and abuse case analysis, a plus.
  • Experience influencing secure development practices across decentralized or federated engineering organizations, including driving adoption through partnership, standards, and enablement, a plus. 
  • Experience defining and using application security metrics, maturity measures, or risk-based reporting to prioritize improvements and demonstrate impact, a plus.
  • Experience designing security controls for cloud-native and distributed systems running in Azure, AWS, or GCP, a plus.
  • Experience designing, deploying, or tuning Akamai protections, a plus.
  • Experience with reviewing and securing IaC (Terraform or similar), a plus.

Pay range: $172,000 – 240,000 depending on experience and skill set.
Annual bonus target 15% subject to terms and conditions of plan.
Benefits overview: https://cdw.benefit-info.com/
Salary ranges may be subject to geographic differentials.

CDW is committed to being an AI-fluent organization

We’re looking for people who bring curiosity, a learner’s mindset, and a willingness to engage with ever-evolving technology and tools. We value adopting AI as a partner, openness to experimentation, and a shared interest in learning together on AI. Our goal is to create a culture where AI enhances—not replaces—human creativity and decision-making. You don’t need to be an expert today; what matters is your readiness to explore, adapt, and grow with us as we integrate AI responsibly and effectively into our work.

Additionally, CDW is committed to fostering an equitable, transparent, and respectful hiring process for all applicants. During our application process, our goal is to understand your experience, strengths, skills, and qualifications. As an AI forward company, we see AI not just as a tool, but as a catalyst for new ways of thinking, creating, and communicating. We encourage candidates to embrace an AI mindset, one that’s curious, adaptive, and ready to explore what’s possible. We welcome thoughtful use of AI to expand your perspective and elevate how you share your story, while ensuring your application remains rooted in your own background, judgment, and voice.

About Us

CDW is a Fortune 500 technology solutions provider that helps businesses, government, education, and healthcare organizations achieve what’s possible through technology. What makes CDW different isn’t just what we do—it’s how we do it. At CDW we act as one—building trust, speaking candidly, and working together to achieve more. We play to win—focusing on what matters most and delivering for our customers. And we think forward—staying curious, moving fast, and continuously learning. We believe meaningful work happens when people feel supported, heard, and empowered to contribute. That’s why we think of ourselves as coworkers, not just employees—working together to solve complex challenges and deliver real impact for our customers and communities.

 

As a full‑stack, full‑lifecycle technology partner, CDW brings deep expertise, strong relationships, and broad industry knowledge to help turn ideas into outcomes. When you join CDW, you become part of a collaborative environment where your work matters, your growth is supported, and your contributions help shape what’s next.

Together, we deliver the full promise of what technology can do. Together, we Make Amazing Happen.

 

CDW is an equal opportunity employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status or any other basis prohibited by state and local law.       

About CDW

Public U.S. multi-brand IT solutions provider serving business, government, education, and healthcare customers.

Similar jobs

Application Security Engineer roles in Illinois
6d
Save
Mark Applied
Hide
Application Security Engineer
Fort Meade or Pensacola or Mechanicsburg or Columbus or San Antonio or Ford Island or Belleville or Oklahoma City or Ogden
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years supporting DoD enterprise architecture, F5 BIG-IP design and administration, proxy break-and-inspect solutions, AWS, TLS/mTLS, Secret clearance, and HS diploma/GED.
F5 BIG-IP, AWS, Office 365, Microsoft Teams, RDP, SSH, CLI, NIST 800-53, FIPS, DoD STIG, FedRAMP, Linux, UNIX, TLS, Mutual TLS, Public Key Infrastructure (PKI)
3w
Save
Mark Applied
Hide
IT Systems Engineer Sr - Application Security
Chicago, Illinois, United States
$94k-$154k/yr OnsiteFull Time
Ann & Robert H. Lurie Children's Hospital of Chicago
Ann & Robert H. Lurie Children's Hospital of Chicago: Regional pediatric hospital providing comprehensive medical care and research.
3+ YOEBachelor's degree or equivalent experience; 3–7+ years in application security, cybersecurity, or enterprise application support; expertise in application security controls, vulnerability management, IAM, OWASP, and enterprise integrations.
Qualys, Qualys WAS, Metasploit, SAST, DAST, WAF, OWASP Top 10, CIS Controls and Benchmarks, SSO, OAuth
1mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Irvine or North Chicago
$110k-$209k/yr HybridFull Time
AbbVie
AbbVieNYSE: ABBV: Global biopharmaceutical discovering and delivering innovative medicines.
5+ YOEExperience in application security, implementing and supporting SAST/DAST/IAST/SCA, CI/CD integration, cloud (AWS/Azure), IaC (Terraform/CloudFormation); strong secure coding knowledge (Java, Node.js); effective communicator.
SAST, DAST, IAST, SCA, CI/CD, AWS, Azure, Terraform, CloudFormation, Snyk, Endor Labs, Python
1mo
Save
Mark Applied
Hide
Staff Security Application Engineer
Chicago or Scottsdale or San Francisco or New York City
$149k-$218k/yr HybridFull Time
Early Warning Services
Early Warning Services: U.S. bank-owned fintech and consumer reporting agency providing identity, fraud-risk, and real-time payment solutions to financial institutions.
8+ YOE8+ years network security experience with 5+ years in proxy and DLP; hands-on with Microsoft Defender, Palo Alto Prisma Access, Netskope; scripting (PowerShell, Python); experience with compliance and control testing.
Microsoft Defender, Palo Alto Prisma Access, Netskope, PowerShell, Python
2mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Seattle or Los Angeles or San Francisco or California or Colorado or Connecticut or Delaware or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or Nevada or New Jersey or New York or Rhode Island or Virginia or Washington or Washington DC or United States
$141k-$259k/yr OnsiteFull Time
Nordstrom
NordstromNew York Stock Exchange: JWN: Fashion specialty retailer offering apparel, footwear, and accessories.
4+ YOE4+ years in application security or related field; experience shipping security tooling and automation; expert threat modeling, security design review, and manual code review; fluent reading/writing code in Java, Kotlin, C#, or Python; cloud-native and LLM/AI security knowledge.
Java, Kotlin, C#, Python, SAST, SCA, DAST, secrets scanning, GitHub Advanced Security, JFrog Artifactory, AWS, GCP, Azure, Kubernetes, LLM
2mo
Save
Mark Applied
Hide
Advisor, Application Security Engineer
Chicago, Illinois, United States
$100k-$186k/yr HybridFull Time
Epsilon
Epsilon: Epsilon is a global marketing-data, consumer-analytics, and marketing-technology serving brands.
10+ YOEBS/MS in Computer Science, 10+ years experience, software development and CI/CD experience, application security testing (SAST/DAST/MAST/RAST/IAST), vulnerability management, OWASP Top 10/CWE knowledge, cloud and web/app security, threat modeling, network security, and cryptography.
CI/CD, SAST, DAST, MAST, RAST, IAST, OWASP Top 10, CWE 25, WAF, Micro-segmentation
2y
Save
Mark Applied
Hide
Advisor, Application Security Engineer
Chicago, Illinois, United States
$100k-$186k/yr OnsiteFull Time
Epsilon
Epsilon: Global marketing-data, consumer-analytics, and marketing-technology serving brands.
10+ YOEBS/MS in CS or similar, 10+ years experience, software development background, CI/CD and application security testing (SAST/DAST/IAST/etc), vulnerability management, OWASP/CWE knowledge, cloud and API security, threat modeling.
CI/CD, SAST, DAST, MAST, RAST, IAST, OWASP Top 10, CWE 25, WAF, API security
9mo
Save
Mark Applied
Hide
Senior Application Security Engineer
Chicago, Illinois, United States
$130k-$180k/yr HybridFull Time
Tempus AI
Tempus AINASDAQ: TEM: AI-enabled precision medicine and health technology.
5+ YOE5+ years in penetration testing; healthcare/regulatory experience preferred; strong security principles; security tools (Burp Suite, Snyk, Metasploit, Nmap); programming in Python/JavaScript/TypeScript; cloud security (AWS, Azure, GCP); data privacy knowledge (HIPAA/GDPR).
Burp Suite, Snyk, Metasploit, Nmap, Python, JavaScript/TypeScript, AWS, Azure, GCP