AbbVie logo

Junior Application Security Engineer

AbbVie
August 22, 2026
Remote friendly (North Chicago, IL)
United States
$84,500 - $162,000 USD yearly
IT
Responsibilities:
- Implement and maintain Application Security Testing (AST) tools (SAST, DAST, IAST, SCA) to identify code and dependency vulnerabilities during the software development lifecycle.
- Implement and maintain Application Security Posture Management (ASPM) tools to centralize and deduplicate findings from multiple solutions and integrate into software development processes.
- Provide first-line support: resolve false positives, guide remediation, and evaluate security exception requests.
- Integrate security tooling with Continuous Integration/Continuous Deployment (CICD) pipelines.
- Develop detailed reports on security findings and remediation efforts.
- Demonstrate high proficiency across technologies and platforms related to application security, software design/development, containerization, and cloud environments.
- Communicate security risks and evangelize secure development practices to development teams and management.
- Understand and triage vulnerabilities/security risks at scale across disparate application environments and business units.

Required Qualifications:
- Bachelor’s degree and 5 years’ experience; or Master’s degree and 4 years’ experience.
- Experience in application security and software development.
- Experience implementing/administering/supporting application security tooling (SAST/DAST/IAST/SCA).
- Knowledge of secure coding practices across multiple languages (esp. Java, Node.js).
- Experience integrating security testing into CI/CD pipelines.
- Knowledge of application security principles and common vulnerabilities (e.g., OWASP Top 10, CWE) and mitigations.
- Experience supporting developers in assessing and mitigating security findings.
- Ability to communicate technical findings to technical and non-technical stakeholders.
- Ability to function as a principal engineer; generate original technical ideas/strategies; creative problem-solving; champion new technologies.
- Excellent written/oral English; able to present at leading scientific/technical conferences.
- Experience coaching/supporting junior engineers.

Preferred:
- Consolidate application security findings across multiple sources; integrate with workflows and tracking systems.
- Administer Snyk and Endor Labs.
- Integrate Cloud Security Posture Management (CSPM) tooling with application security pipelines.
- Automate workflows using Python.
- Build logging into DevSecOps pipelines for performance insights.
- Collaborate with vulnerability/risk management partners on risk acceptance processes.