Principal Application Security Engineer
New
J
JobgetherSecurity & IT
Remote work opportunity within the United States.Full-TimePrincipal
SalaryBase salary range of $172,000–$240,000, depending on experience, skills, and geographic considerations.
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years
- Required Skills
- CI/CD
Requirements
- 10+ years of experience in Application Security Engineering with hands-on integration of security into software delivery.
- Deep expertise in secure application architecture, secure coding, vulnerability analysis, and threat modeling.
- Background in software engineering, application development, or architecture.
- Strong knowledge of authentication, authorization, session management, and secrets management.
- Expertise in OWASP Top 10, injection, deserialization, SSRF, and dependency vulnerabilities.
- Hands-on experience with C#, Java, Python, JavaScript, TypeScript, or Go.
- Strong experience integrating SAST, SCA, DAST, IaC scanning, and container security into CI/CD pipelines.
- Ability to independently investigate complex technical problems and deliver practical remediation.
- Experience creating security standards, playbooks, and scalable security practices.
- Demonstrated ownership and experience raising security standards across engineering organizations.
Responsibilities
- Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services.
- Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
- Identify security control gaps and delivery friction to drive remediation through automation and secure-by-design patterns.
- Define and promote secure coding standards, reference architectures, playbooks, and automated security capabilities.
- Act as a senior security advisor to engineering and platform teams to influence architecture and development practices.
- Advance application security for AI-enabled development by establishing guardrails and promoting responsible AI adoption.
- Provide expertise in API security, including authentication, authorization, and protection against common attack techniques.
- Strengthen software supply chain security through dependency management, pipeline hardening, and SBOM practices.
- Define application security metrics and risk-based reporting to prioritize improvements.
View Full Description & ApplyYou'll be redirected to the employer's site