Lurie Children's Hospital

IT Systems Engineer Sr - Application Security

Lurie Children's Hospital · Chicago, Illinois, United States · $94K–$154K/yr

Hospitals and Health Care · 1,001-5,000 employees

Yesterday
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineer is responsible for implementing, validating, and maintaining security controls across the hospital's application stack, including databases, APIs, and web servers. They will identify and remediate application-layer risks while partnering with vendors and internal teams to ensure secure-by-default deployments.

What they look for

Application security Vulnerability management Authentication models Authorization models SSO OAuth Encryption Data protection OWASP Top 10 IAM Qualys SAST DAST WAF Firewalls Risk assessment

Requirements

Candidates must have a Bachelor's degree in a relevant field and 3-7+ years of experience in application security or cybersecurity. Strong knowledge of authentication models, vulnerability scanning tools, and application-layer attack paths is required.

Benefits

Medical insurance Dental insurance Vision insurance Employer paid group term life and disability Health Savings Account Flexible Spending Accounts Paid Time Off Paid Holidays Paid Parental Leave 403(b) retirement plan Supplemental Life insurance Accidental Death and Dismemberment insurance Critical Illness coverage Accident coverage Hospital Indemnity coverage Tuition assistance Student loan servicing and support Adoption benefits Backup Childcare and Eldercare Employee Assistance Program

Full description

Ann & Robert H. Lurie Children’s Hospital of Chicago provides superior pediatric care in a setting that offers the latest benefits and innovations in medical technology, research and family-friendly design. As the largest pediatric provider in the region with a 140-year legacy of excellence, kids and their families are at the center of all we do. Ann & Robert H. Lurie Children’s Hospital of Chicago is ranked in all 10 specialties by the U.S. News & World Report.

Location

680 Lake Shore Drive

Job Description

The Application Security Engineer is a hands‑on technical role responsible for implementing, validating, and maintaining security controls across all tiers of the hospital’s application stack, including database, middleware, web server, API, and presentation layers. The engineer ensures applications, integrations, and supporting components are securely configured, monitored, and aligned with enterprise security standards.

This role works directly with infrastructure, vulnerability management, and vendors to identify, remediate, and prevent application‑layer risks. The engineer performs hands‑on validation, troubleshooting, and configuration enforcement to ensure secure‑by‑default application deployments across the enterprise.

Essential Job Functions:

  • Serve as the central authority for application and integration risk by applying consistent security standards across a portfolio of more than 250 commercial and third‑party applications.
  • Identify and reduce application‑layer risk across third‑party applications, APIs, system integrations, automated file transfers, and service accounts.
  • Interface with application vendors, application owners, and other departments as needed.
  • Assess and secure internet‑facing applications by identifying exposed access points and prioritizing remediation of high‑risk entry vectors.
  • Enforce standardized security controls for authentication, authorization, credential and secret management, encryption, and secure communication patterns.
  • Partner with application owners and vendors to eliminate insecure configurations, excessive access, credential misuse, and other security issues.
  • Evaluate and secure applications throughout their lifecycle including procurement, implementation, integration, and ongoing operations.
  • Support third‑party risk management by assessing vendor integrations, data flow methods, and exposure points.
  • Drive remediation of application vulnerabilities identified through vulnerability scanning (e.g., Qualys), configuration reviews, and security testing of externally facing systems.
  • Improve visibility and governance over application security posture by tracking exposure trends, risk reduction, and remediation progress.

Knowledge, Skills and Abilities:

  • Strong understanding of application‑layer attack paths including credential compromise, integration abuse, API exploitation, and external exposure risks.
  • Deep knowledge of authentication and authorization models such as SSO, OAuth, service accounts, and secure integration patterns.
  • Expertise in encryption and data protection across application and integration workflows.
  • Experience in complex enterprise environments with large commercial application portfolios.
  • Strong familiarity with OWASP Top 10, common exploitation techniques, IAM concepts, and secrets/credential lifecycle management.
  • Knowledge of CIS Controls and Benchmarks as they apply to application security.
  • Experience with vulnerability scanning and testing tools such as Qualys, Qualys WAS, Metasploit, SAST/DAST, and configuration/exposure analysis tools.
  • Understanding of network and edge security including WAFs, firewalls, segmentation, and internet‑facing exposure.
  • Ability to drive cross‑functional remediation across technical and non‑technical stakeholders.
  • Strong analytical and prioritization skills in a risk‑based environment.
  • Excellent communication skills with the ability to translate technical risk into business impact.

Education and Experience

  • Bachelor’s Degree in Computer Science, Information Security, Information Systems, or related field, or equivalent work experience.
  • 3–7+ years of experience in application security, cybersecurity, or enterprise application support.
  • Experience working in large enterprise environments with multiple commercial applications and integrations preferred.
  • Experience within a healthcare provider environment is desirable.
  • Security certifications such as CISSP, CSSLP, GWAPT, CASE, CEH, OSCP or equivalent are beneficial but not required.

Education

Bachelor's Degree

Pay Range

$93,600.00-$154,440.00 Salary

At Lurie Children’s, we are committed to competitive and fair compensation aligned with market rates and internal equity, reflecting individual contributions, experience, and expertise. The pay range for this job indicates minimum and maximum targets for the position. Ranges are regularly reviewed to stay aligned with market conditions. In addition to base salary, Lurie Children’s offer a comprehensive rewards package that may include differentials for some hourly employees, leadership incentives for select roles, health and retirement benefits, and wellbeing programs. For more details on other compensation, consult your recruiter or click the following link to learn more about our benefits.

Benefit Statement

For full time and part time employees who work 20 or more hours per week we offer a generous benefits package that includes:

Medical, dental and vision insurance

Employer paid group term life and disability

Employer contribution toward Health Savings Account

Flexible Spending Accounts

Paid Time Off (PTO), Paid Holidays and Paid Parental Leave

403(b) with a 5% employer match

Various voluntary benefits:

  • Supplemental Life, AD&D and Disability
  • Critical Illness, Accident and Hospital Indemnity coverage
  • Tuition assistance
  • Student loan servicing and support
  • Adoption benefits
  • Backup Childcare and Eldercare
  • Employee Assistance Program, and other specialized behavioral health services and resources for employees and family members
  • Discount on services at Lurie Children’s facilities
  • Discount purchasing program

There’s a Place for You with Us

At Ann & Robert H. Lurie Children’s Hospital of Chicago and its affiliates (collectively “Lurie Children’s”), we embrace and celebrate diversity and equity in a serious way. We are committed to building a team with a variety of backgrounds, skills, and viewpoints — recognizing that diverse identities strengthen our workplace and the care we can provide to the Chicago community and beyond. We treat everyone fairly, appreciate differences, and make meaningful connections that foster belonging and allyship. This is a place where you can be your best, so we can give our best to the patients and families who trust us with their care.  

Lurie Children’s and its affiliates are equal employment opportunity employers.  We value diversity and are committed to creating an inclusive environment for all employees.  All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin, ancestry, age, disability, marital status, pregnancy, protected veteran status, order of protection status, protected genetic information, or any other characteristic protected by law. 

For questions about how to request an accommodation please contact: employeehealth@luriechildrens.org

AI Notice 

Lurie Children’s utilizes certain AI-enabled features within our recruiting platform to support candidate engagement and assist recruiters in identifying and prioritizing applicants whose experience aligns with job requirements. All employment decisions are made by individuals.

It is a civil rights violation with respect to recruitment, hiring, promotion, or employment for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of protected classes under the Illinois Human Rights Act or to use zip codes as a proxy for protected classes.

For questions about the use of artificial intelligence in this process or any additional support, please contact: peoplequestions@luriechildrens.org