Jobgether
Jobgether

Principal Application Security Engineer

engineeringfull-timeUS
SALARY
$172k – $240k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Accountabilities:

    • Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
    • Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
    • Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
    • Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
    • Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
    • Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
    • Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
    • Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
    • Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
    • Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.
    • Requirements:

      • 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
      • Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
      • Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
      • Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
      • Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
      • Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
      • Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
      • Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
      • Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
      • Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
      • Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
      • Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
      • Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
      • Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
      • Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.
      • Benefits:

        • Base salary range of $172,000–$240,000, depending on experience, skills, and geographic considerations.
        • 15% annual bonus target, subject to applicable plan terms and conditions.
        • Comprehensive employee benefits package covering health and other wellness needs.
        • Remote work opportunity within the United States.
        • Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
        • Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.
        • Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now