SonicJobs Logo
Left arrow iconBack to search

Engineer - Application Cybersecurity

United Airlines
Posted 7 days ago, valid for 9 hours
Location

Chicago, IL, US

Salary

$89,965 - $117,212 per year

Contract type

Full Time

Paid Time Off
Employee Assistance

By applying, a United Airlines account will be created for you. United Airlines's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • United Airlines is seeking an Engineer- Application Cybersecurity with a minimum of 2 years of experience in a related field.
  • The role involves validating services, applications, and websites against secure development standards while supporting development teams with security integration throughout the product lifecycle.
  • Candidates should possess a Bachelor's degree, preferably in a STEM field, and have knowledge of automation, OWASP Top 10, and application testing methodologies.
  • The base salary for this position ranges from $89,965 to $117,212, with additional eligibility for bonuses and long-term incentives.
  • United Airlines offers a comprehensive benefits package, including medical, dental, vision, and flight privileges, while promoting a diverse and inclusive workplace.
Achieving our goals starts with supporting yours. Grow your career, access top-tier health and wellness benefits, build lasting connections with your team and our customers, and travel the world using our extensive route network.

Come join us to create what’s next. Let’s define tomorrow, together.

Description

Connecting People. Uniting the World. There’s never been a more exciting time to join United Airlines! As a global company that operates in hundreds of locations around the world — with millions of customers and tens of thousands of employees — we have a unique responsibility to uplift and provide opportunities in the places where we work, live and fly.

We’re on a path to becoming the best airline in aviation history. Join our Cybersecurity and Digital Risk (CDR) team to help lead the industry in cyber safety, security and resilience. United's CDR team plays a critical role in protecting our operations by enabling secure and resilient systems, managing threats and vulnerabilities, and ensuring swift response and recovery. Our mission is to seamlessly embed cybersecurity and digital risk management into every aspect of our business. We help drive progress and growth through trusted digital solutions, safeguarding assets and empowering our team, all while promoting a cyber-safe and secure environment that supports resilient airline operations.

United offers a competitive benefits package aimed at keeping you happy, healthy, and well-traveled. From employee-run "Business Resource Group" communities to world-class benefits like parental leave, 401(k), and privileges like space-available travel, United is truly a one-of-a-kind place to work. Are you ready to travel the world and help us keep our airline cyber safe? Apply today!
 

 

Job Overview and Responsibilities


The Engineer- Application Cybersecurity helps validate that our services, applications, and websites are designed and implemented in accordance with United’s secure development standards. The engineer works closely with development teams, product teams, and other teams across the organization to integrate security into the product lifecycle from design through deployment.
The engineer will support the enforcement of security requirements, performing application security assessments, and providing developers with remediation guidance and advice.

 

  • Improve the accessibility of security through automation, continuous integration pipelines, and other means including but not limited to developing and maintaining CI/CD templates
  • Perform code analysis of applications, manually and using application security testing solutions including mobile application security tests as well as conducting manual vulnerability analysis, and assisting product teams with vulnerability remediation
  • Research, define and communicate security best practices and standards and ensure products development teams understand them
  • Support security architecture design reviews and threat modelling of our products
     

Qualifications

What’s needed to succeed (Minimum Qualifications):

 

 

  • Bachelor's degree (STEM field preferred)
  • Minimum of 2 years of experience in related field
  • Ability to automate processes and boost tooling maturity through scripting (Python preferred) or coding
  • Working knowledge of OWASP Top 10 and/or CWE 25
  • Basic understanding of DevSecOps (e.g., CI/CD)
  • Working knowledge with application testing (e.g., SAST, DAST, MAST, RAST, IAST)
  • Working knowledge of programming languages and scripting
  • Basic understanding of SDLC process
  • Basic understanding of web and app security stack (e.g., API security)
  • Basic understanding of cloud technologies and security
  • Working knowledge with technical documentation / Standard Operating Procedures (SOPs) creation
  • Ability to work independently and self-motivate
  • Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills
  • Must be legally authorized to work in the United States for any employer without sponsorship
  • Successful completion of interview required to meet job qualification
  • Reliable, punctual attendance is an essential function of the position

 

What will help you propel from the pack (Preferred Qualifications):

 

  • AWS Certified Solutions Architect – Associate
  • Certified Application Security Engineer
  • Experience with AWS technologies
  • Working knowledge of C#, Java, Python, Swift, and JavaScript
  • Basic understanding of threat modeling
  • Basic understanding of compliance frameworks (e.g., NIST 800-53) and processes
  • Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security, cloud computing
  • Basic technical understanding of authentication and authorization flows in web applications
  • Basic understanding of networks and network security (e.g , WAF, Micro-segmentation)
  • Basic understanding of cryptography
  • Basic understanding of vulnerability management processes and proficiency in providing remediation guidance

 


The base pay range for this role is $89,965.00 to $117,212.00.
The base salary range/hourly rate listed is dependent on job-related, factors such as experience, education, and skills. This position is also eligible for bonus and/or long-term incentive compensation awards.

You may be eligible for the following competitive benefits: medical, dental, vision, life, accident & disability, parental leave, employee assistance program, commuter, paid holidays, paid time off, 401(k) and flight privileges.

United Airlines is an Equal Opportunity Employer. We recruit, employ, train, compensate, and promote without regard to race, color, religion, national origin, gender identity, sexual orientation, disability, age, veteran status, or any other protected category under applicable law. We provide reasonable accommodations for applicants and employees with disabilities. To request an accommodation, contact JobAccommodations@united.com



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a United Airlines account will be created for you. United Airlines's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.