Talent.com
Security Engineer
Security EngineerSupernova Technology • Chicago, IL, US
Security Engineer

Security Engineer

Supernova Technology • Chicago, IL, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Job Description

Job Description

About Us

Founded in 2014, we offer the industry’s first and only cloud-based, fully-customizable, end-to-end software solution to automate securities-based lending from origination through the life of the loan. By combining thought leadership in suitability and risk management with industry-leading education and the latest technology, Supernova enables advisors to deliver holistic, goals-based advice and to help their clients achieve financial wellness. We partner with the industry’s largest banks, most prominent insurance companies and leading online brokerages to democratize access to securities-based lending and better the entire financial ecosystem.

Why Join Supernova?

At Supernova Technology, we believe that the best results come from a team that is passionate, driven, and supported in all aspects of their professional lives. Here, you’ll work alongside talented and innovative individuals who are committed to driving the future of securities-based lending technology. We foster a culture of collaboration, continuous learning, and growth, where each person’s contributions make a real impact.

Job Overview

We are seeking a highly motivated and detail-oriented Security Engineer to help secure our securities-backed lending SaaS platform. The successful candidate will focus primarily on application security, secure SDLC, and application vulnerability management, while also assisting with the execution and implementation of broader information security initiatives. You’ll partner with engineering, SRE / DevOps, and business teams to embed security into our build and delivery processes, support risk reduction across cloud and endpoint surfaces, and drive measurable remediation outcomes in a regulated financial-services environment.

RESPONSIBILITIES

  • Perform hands-on web / API penetration tests, validate scanner findings, and provide clear PoCs, impact statements, and prioritized remediation aligned with OWASP.
  • Integrate and tune SAST, DAST, SCA, container, and secret-detection tools in CI / CD; define pass / fail gates and PR checklists.
  • Conduct lightweight threat modeling and security design reviews for new features such as authentication, session management, and secrets handling.
  • Manage the full application vulnerability lifecycle (discover → prioritize → fix → retest → close) with SLAs and metrics.
  • Assist in hardening AWS and ECS / Docker workloads (IAM roles, network segmentation, image policies, logging / monitoring) and support patch hygiene across cloud, container, and endpoints.
  • Participate in incident response, including exploit reproduction, log analysis, impact assessment, and lessons learned.
  • Provide evidence for audits (ISO 27001, SOC 2, NIST SSDF), maintain policies and developer guidance, and support vendor / security evaluations.
  • Translate findings into developer-ready tickets, publish secure-coding guidance, and partner with engineering to streamline secure delivery.
  • Prototype automation, explore AI / LLM-assisted workflows to improve triage and code review, and share improvements across teams.
  • Contribute to organization-wide cybersecurity training and awareness efforts.

QUALIFICATIONS

  • Bachelor's degree in security engineering, information assurance, or related field.
  • 2–3 years of experience in security or software engineering (internships, labs, or open-source count), preferably in regulated industries.
  • Strong knowledge of web / API security issues (auth, session management, injections, SSRF, CSRF, access control) and common cloud / web misconfigurations.
  • Experience with SDLC security tools (SAST / DAST / SCA / secret detection / container scanning), CI / CD workflows, and Git.
  • Scripting or coding skills (Python or JavaScript / TypeScript) and ability to read backend code.
  • Familiarity with AWS security basics (IAM least privilege, KMS, logging / monitoring, security groups) and Docker / ECS runtime considerations.
  • Clear communication skills with the ability to translate risk into actionable remediation.
  • Experience using AI / LLM-assisted tools for triage, documentation, or code review preferred.
  • Exposure to WAF / CDN tuning, API protection, and risk-based remediation SLAs / metrics preferred.
  • Familiarity with frameworks like OWASP ASVS / SAMM, NIST SSDF, ISO 27001, SOC 2, PCI DSS preferred.
  • Relevant security certifications preferred.
  • Our Employee Benefits

    At Supernova Technology, we provide a robust benefits package to support the health and well-being of our employees. Our offerings include :

    Medical, Dental, and Vision Insurance :   Multiple plans with coverage for employees and dependents.

    HSA and FSA Accounts :   Tax-advantaged accounts for health and dependent care expenses.

    Life and Disability Insurance :  Employer-paid basic coverage with options for additional voluntary coverage.

    Compensation :  $95,000 - $130,000

    Retirement Savings :  401(k) plan with employer contributions.

    Employee Assistance Program (EAP) :   Confidential support services, including free therapy sessions.

    Paid Time Off :   Flexible PTO policies.

    Additional Perks :  Commuter benefits, pet insurance, continuing education assistance, and more.

    Note : Actual salary at the time of hire may vary and may be above or below the range based on various factors, including but not limited to, the candidate's relevant qualifications, skills and experience, and the location where this position may be filled.

    Our Core Values

    Our core values drive everything we do. At Supernova, we...

    Form, execute, and communicate new ideas that add value to our employees and customers

    Strive through obstacles and failures

    Follow-through on promises or commitments to others, accept responsibility, and answer for actions & decisions

    Listen to, understand, and support our employees and customers

    Act with speed, positive attitude, and flexibility

    Exceed expectations and surpass ourselves every day; we embrace a sense of pride and never stop growing

    Join us and make an impact while growing your career at Supernova.

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    [job_alerts.create_a_job]

    Security Engineer • Chicago, IL, US

    [internal_linking.similar_jobs]
    Nuclear Cyber Security Engineer - REMOTE

    Nuclear Cyber Security Engineer - REMOTE

    JSG (Johnson Service Group, Inc.) • Cicero, IL, United States
    [filters.remote]
    [job_card.full_time]
    IF YOU DO NOT HAVE THE REQUIRED BACKGROND IN THE U.COMMERCAL NUCLEAR INDUSTRY, PLEASE DO NOT APPLY.Immediate opening for a Cyber Security Engineer with commercial nuclear background, to perform des...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Cyber Security Engineer

    Cyber Security Engineer

    Lucas James Talent Partners • Chicago, IL, United States
    [job_card.full_time]
    Our client Dscout is a flexible Experience Research Platform for capturing in-context insights from high-quality participants, bridging the gap between product teams and users.Leading brands like S...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Site Reliability and Security Engineer

    Site Reliability and Security Engineer

    Quality Technology Services • Ashburn, Illinois, USA
    [job_card.full_time] +1
    The Senior Site Reliability and Security Engineer is responsible for ensuring the reliability observability and security posture of the QTS OS and SDP platforms deployed on AWS.This role combines d...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Information Security Engineer

    Information Security Engineer

    Green Thumb Industries • Chicago, IL, United States
    [job_card.full_time]
    Information Security Engineer who thrives at the intersection of technical execution and security operations.The role is primarily remote but you must live within the Chicagoland area to come into ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security & Fire Systems Engineer III

    Security & Fire Systems Engineer III

    Johnson Controls • Calumet, Illinois, USA
    [job_card.full_time]
    Build your best future with the Johnson Controls team.As a global leader in smart healthy and sustainable buildings our mission is to reimagine the performance of buildings to serve people.Join a w...[show_more]
    [last_updated.last_updated_30] • [promoted]
    GTIL Application Security Engineer (Sr. Associate)

    GTIL Application Security Engineer (Sr. Associate)

    Grant Thornton • Chicago, Illinois, USA
    [job_card.full_time]
    Grant Thornton isone of the worlds leading professional services networks with member firms in over 145 countries 75000 people and global revenuesof$ firms offer audit tax and advisory services to ...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Sr. Security Engineer (Firewall) - Hybrid Opportunity (Based in West Des Moines, IA)

    Sr. Security Engineer (Firewall) - Hybrid Opportunity (Based in West Des Moines, IA)

    The Mutual Group • Chicago, IL, US
    [job_card.full_time]
    We are looking for a seasoned Senior Security Engineer (Firewall) with 5–10 years of cybersecurity experience, specializing in AWS cloud security. This role demands strong expertise in securit...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    AI Security Engineer | Application and Product Security

    AI Security Engineer | Application and Product Security

    ServiceNow • Chicago, Illinois, USA
    [job_card.full_time]
    PLEASE NOTE • • : This role requires a minimum of 2 days per week in our San Diego CA or Chicago IL ServiceNow Offices.Please do not apply if you cannot meet this requirement.The ServiceNow Secu...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    Relativity • Chicago, IL, United States
    [job_card.full_time]
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security Engineer Contract

    Security Engineer Contract

    VirtualVocations • Chicago, Illinois, United States
    [job_card.temporary]
    A company is looking for an Enterprise Security Engineer for a 6-month contract.Key Responsibilities : Provide security-focused consulting services to customers as defined by the statement of work...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    M&A Security Engineer, Contract To Hire

    M&A Security Engineer, Contract To Hire

    66degrees • Chicago, Illinois, USA
    [job_card.full_time]
    AI-focused data-led solutions leveraging the latest advancements in cloud technology.With our unmatched engineering capabilities and vast industry experience we help the worlds leading brands trans...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    AI Security Engineer

    AI Security Engineer

    TAG - The Aspen Group • Chicago, IL, United States
    [job_card.full_time]
    The Aspen Group (TAG) is one of the largest and most trusted retail healthcare business support organizations in the U.Working in partnership with independent practice owners and clinicians, the te...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Associate Principal, Security Engineering

    Associate Principal, Security Engineering

    The Options Clearing Corporation • Chicago, IL, United States
    [job_card.full_time]
    THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP • • • • •.Join our dynamic Security Engineering team as an Associate Principal and make a significant impact on our organization's cybersecurity postur...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security Engineer

    Security Engineer

    RAPP • Chicago, IL, United States
    [job_card.full_time]
    RAPP Chicago is looking for a Security Engineer to join our award-winning Technology team.We are RAPP - world leaders in activating growth with precision and empathy at scale.As a global, next-gene...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security Software Engineer

    Security Software Engineer

    Allstate Insurance • Chicago, IL, United States
    [job_card.full_time]
    At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years our innovative drive has kept us a step ...[show_more]
    [last_updated.last_updated_30] • [promoted]
    M&A Security Engineer

    M&A Security Engineer

    Hub International Insurance • Chicago, Illinois, USA
    [job_card.full_time]
    At HUB International we are a team of entrepreneurs.We believe in protecting and supporting the aspirations of individuals families and businesses. We help our clients evaluate their risks and devel...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Lead Energy Storage Cyber Security Engineer - REMOTE

    Lead Energy Storage Cyber Security Engineer - REMOTE

    ThinkBAC Consulting • Chicago, IL, US
    [filters.remote]
    [job_card.full_time]
    Lead Energy Storage Cybersecurity Engineer / Cybersecurity Architect.Location : FULLY REMOTE (Anywhere in the USA).This is an opportunity to join an industry leading renewable energy venture with st...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Cyber Security Endpoint Engineer

    Cyber Security Endpoint Engineer

    Chicago Transit Authority • Chicago, Illinois, United States
    [job_card.full_time]
    Deploy, configure, and manage endpoint protection tools (e.EDR, NGAV, encryption, host-based firewalls).Deploy, configure, and manage endpoint remote access tools. Test endpoint security software to...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]