368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$129k – $258k per year (Estimated)
Location
Remote (United States)
Seniority
Principal · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is an AI-powered job platform focused on remote and flexible work. It matches candidates with relevant roles using skills and preference-based algorithms, and also offers career coaching and job-search guidance.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Application Security Engineer based in the United States.

This is a senior technical leadership role focused on embedding application security into software engineering at enterprise scale.

You will partner with development, DevOps, platform engineering, and SRE teams to reduce risk while enabling fast, secure delivery.

The role combines hands-on security engineering with strategic influence across applications, APIs, cloud environments, and CI/CD pipelines.

You will shape secure-by-design practices, scalable controls, reference architectures, automation, and engineering standards.

You will also help advance security approaches for AI-enabled applications and responsible use of AI in software development.

Success requires strong technical judgment, credibility with engineers, and the ability to turn complex security risks into practical solutions.

This is an opportunity to influence security maturity across a large, distributed engineering organization while remaining close to the technology.

Accountabilities:

    • Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
    • Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
    • Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
    • Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
    • Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
    • Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
    • Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
    • Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
    • Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
    • Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.
    • Requirements:

      • 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
      • Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
      • Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
      • Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
      • Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
      • Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
      • Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
      • Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
      • Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
      • Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
      • Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
      • Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
      • Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
      • Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
      • Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.
      • Benefits:

        • Base salary range of $172,000-$240,000, depending on experience, skills, and geographic considerations.
        • 15% annual bonus target, subject to applicable plan terms and conditions.
        • Comprehensive employee benefits package covering health and other wellness needs.
        • Remote work opportunity within the United States.
        • Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
        • Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.
        • Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$108k – $195k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • United States
Python
AI/ML
AI Agents
Amazon SageMaker
AWS Bedrock
AWS Bedrock AgentCore
LLM
DevOps
AWS
CI/CD
CloudFormation
Docker
IAM
Kubernetes
Platform Engineering
Terraform
Cybersecurity
FedRAMP
Apply
$131k – $237k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Chantilly • Columbia
Bash
Python
TypeScript
JavaScript
Databases
PostgreSQL
Frontend
Angular
DevOps
Ansible
ArgoCD
AWS
Azure
buildah
CI/CD
Docker
Docker Swarm
FluxCD
GitLab
GitLab CI
Grafana
Helm
Kubernetes
Loki
Prometheus
Terraform
Twelve-Factor App
Podman
Apply
$108k – $195k per year • In office • Full-Time • 8+ years exp • Orlando
Bash
Python
DevOps
Ansible
AWS
Azure
CI/CD
Configuration Management
Docker
Git
GitLab
Kubernetes
OpenShift
Red Hat
Apply
$70k – $126k per year • Remote • Full-Time • 3+ years exp • United States
Python
DevOps
Azure
Azure DevOps
Bitbucket
CI/CD
Docker
GitHub
GitLab
GitLab CI
Jenkins
Kubernetes
Cybersecurity
SonarQube
QA
Postman
Robot Framework
Selenium
Apply
$58k – $105k per year • Remote • Full-Time • United States
JavaScript
Python
DevOps
Bitbucket
CI/CD
GitHub
GitLab
GitLab CI
Jenkins
Cybersecurity
SonarQube
QA
Robot Framework
Apply
$152k – $229k per year • Remote • Full-Time
AI/ML
Human-in-the-Loop
Apply
$162k – $180k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
Databases
Snowflake
AI/ML
dbt
DevOps
AWS
Cybersecurity
HIPAA
Zero Trust
Analytics
ETL/ELT
Apply
$14k – $32k per year (Estimated) • Remote • Full-Time • 2+ years exp • Bachelor's Degree
DevOps
Incident Management
Management
ServiceNow
Apply
$29k – $60k per year (Estimated) • Remote • Full-Time • 8+ years exp
DevOps
Azure
Azure DevOps
Apply
$26k – $69k per year (Estimated) • Remote • Full-Time • 12+ years exp • Bachelor's Degree
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.