Jobgether
Principal Application Security Engineer
engineeringfull-timeUS
SALARY
$172k – $240k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities:
- Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
- Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
- Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
- Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
- Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
- Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
- Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
- Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
- Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
- Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.
- 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
- Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
- Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
- Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
- Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
- Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
- Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
- Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
- Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
- Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
- Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
- Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
- Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
- Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
- Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.
- Base salary range of $172,000–$240,000, depending on experience, skills, and geographic considerations.
- 15% annual bonus target, subject to applicable plan terms and conditions.
- Comprehensive employee benefits package covering health and other wellness needs.
- Remote work opportunity within the United States.
- Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
- Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.
- Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.
Requirements:
Benefits:
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply