openleverjobgether
Principal Application Security Engineer
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-24T11:48:30.336000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:61d59478-a555-4a6e-9d01-7a98810722c3
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Application Security Engineer based in the United States. This is a senior technical leadership role focused on embedding application security into software engineering at enterprise scale. You will partner with development, DevOps, platform engineering, and SRE teams to reduce risk while enabling fast, secure delivery. The role combines hands-on security engineering with strategic influence across applications, APIs, cloud environments, and CI/CD pipelines. You will shape secure-by-design practices, scalable controls, reference architectures, automation, and engineering standards. You will also help advance security approaches for AI-enabled applications and responsible use of AI in software development. Success requires strong technical judgment, credibility with engineers, and the ability to turn complex security risks into practical solutions. This is an opportunity to influence security maturity across a large, distributed engineering organization while remaining close to the technology. Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance. Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments. Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns. Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams. Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices. Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption. Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques. Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules. Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance. Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact. Requirements: 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery. Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment. Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments. Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities. Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks. Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows. Proven ability to independently investigate complex technical problems, identify root causes
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.