
Senior Application Security Specialist
- 🇺🇸 United States
- On-site
- Senior
- 22 hours ago
- AI
- Threat Modeling
- SAST
- DAST
- CI/CD
- triage
- Incident Response
- DevSecOps
- Git
- Java
- Apex
- Python
- OWASP
- OAuth
- OIDC
- Secrets Management
- Health insurance
- Pension
Wintrust provides community and commercial banking, specialty finance and wealth management services through its 16 bank charters and nine non-bank businesses. Wintrust delivers the sophisticated solutions of a large bank while staying true to therelationship-focused, personalized service of our community banking roots. We serve clients in all 50 states with more than 200 branch banking locations in Illinois, southwestern Florida, northwestern Indiana, west Michigan and southern Wisconsin and commercial banking offices in Chicago, Denver, Milwaukee, Grand Rapids, Mich., and in key branch banking locations throughout Illinois. Our people are the heart of our business and we are proud to rank consistently as a top place to work. Wintrust is a $66 billion financial institution based in Rosemont, Illinois, and listed on the NASDAQ Global Select Market under the symbol “WTFC.”
Why join us?
- An award-winning culture! We are rated a Top Workplace by the Chicago Tribune (past 10 years) and Employee Recommended award by the Globe & Mail (past 6 years)
- Competitive pay and discretionary or incentive bonus eligible
- Comprehensive benefit package including medical, dental, vision, life, a 401k plan with a generous company match and tuition reimbursement to name a few
- Promote from within culture
Â
Why join this team?
- This position has the opportunity to interface with and have a positive impact on multiple areas of Wintrust's business
- We hold ourselves accountable to high standards, share wins, operate ethically, and have fun
Â
 Position Summary:
The Senior Application Security Specialist leads the design, implementation, and continuous improvement of security across enterprise applications, APIs, and SaaS platforms. This role partners with development teams to embed security throughout the software development life cycle (SDLC), reduce application risk, and implement AI-assisted engineering workflows aligned with enterprise security and regulatory requirements.
Â
 Essential Responsibilities:
- Lead application threat modeling, security architecture reviews, and manual code reviews. Define requirements for authentication, authorization, data protection, and secure design across web applications, APIs, and cloud-hosted services.
- Implement and tune static application security testing (SAST) and software composition analysis (SCA) with Checkmarx. Integrate dynamic testing (DAST), secrets scanning, and risk-based security gates into continuous integration and delivery (CI/CD) pipelines.
- Support API discovery, posture assessment, security testing, and runtime monitoring with enterprise API security toolset. Investigate sensitive data exposure, broken authorization, and API abuse with application owners and security operations.
- Design and implement AI-assisted SDLC workflows for code review, unit and integration test generation, security testing, vulnerability triage, and remediation. Establish human review, source-code and data protection, and validation of AI-generated code and tests.
- Drive application vulnerability remediation based on exploitability, exposure, and business impact. Validate fixes, support incident response, and track testing coverage, remediation times, and recurring defects to support risk and compliance reporting.
- Coach developers on secure coding and maintain reusable security patterns and guidance. Evaluate AI workflow adoption, finding quality, test coverage, and time savings to improve security and developer productivity.
Qualifications:
- 5-7 years of relevant experience
- Bachelor’s degree or equivalent; Computer Science or Cybersecurity preferred
- Application security, cybersecurity, and/or Artificial Intelligence certifications preferred
- Required experience: Experience in application security, secure development, or DevSecOps, including threat modeling, manual code review, API testing, vulnerability remediation, and Git-based CI/CD integration. Ability to review Java, Apex and/or Python code and build automation. Knowledge of OWASP Top 10, API Security Top 10, ASVS, authentication, authorization, OAuth/OIDC, and secrets management.
- Preferred experience: Experience implementing AI-assisted SDLC workflows for code review, test generation, security testing, and remediation, with measurable results. Ability to apply human review, validate AI-generated code and tests, and protect sensitive data. Experience with Checkmarx, Akamai API Security, or comparable tools. Experience communicating risk and supporting regulated financial services
Benefits
Medical Insurance • Dental • Vision • Life insurance • Accidental death and dismemberment • Short-term and long term Disability Insurance • Parental Leave • Employee Assistance Program (EAP) • Traditional and Roth 401(k) with company match • Flexible Spending Account (FSA) • Employee Stock Purchase Plan at 5% discount • Critical Illness Insurance • Accident Insurance • Transportation and Commuting Benefits • Banking Benefits • Pet InsuranceÂ
Compensation
The estimated salary range for this role is $117,000- $158,000, along with eligibility to earn an annual bonus. Actual salaries may vary based on several factors, such as a candidate’s qualifications, skills and experience.
From our first day in business, Wintrust has been proud to serve a variety of unique communities and people from all walks of life. Â To build a company that reflects the communities we serve, we believe that fostering a unique and inclusive workplace where everyone feels valued and empowered to succeed will support our ongoing success. Â Wintrust Financial Corporation, including community banking and financial services subsidiaries, is an Equal Opportunity Employer. Â All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.
Senior Application Security Specialist · Town Bank, N.A.