← Все вакансии/Lead/jobgether
LeadRemoteUS

Principal Application Security Engineer

J
jobgether
Зарплата
$14,300–$20,000
Уровень
Lead
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Application Security Engineer based in the United States.

Responsibilities
  • Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
  • Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
  • Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
  • Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
  • Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
  • Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
  • Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
  • Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
  • Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
  • Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.
Requirements
  • 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
  • Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
  • Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
  • Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
  • Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
  • Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
  • Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
  • Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
  • Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
  • Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
  • Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
  • Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
  • Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
  • Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
  • Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.
Conditions
  • Base salary range of $172,000–$240,000, depending on experience, skills, and geographic considerations.
  • 15% annual bonus target, subject to applicable plan terms and conditions.
  • Comprehensive employee benefits package covering health and other wellness needs.
  • Remote work opportunity within the United States.
  • Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
  • Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chain.
Стек и навыки

С чем работаем