Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Application Security Engineer

$177k - $225k
Full-time

iHerb

Summary:

Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role can be fully remote and must reside in US.

In this role, you will help us drive our Product Security strategy working with development teams globally to define new security capabilities, grow the team by hiring the best talent, and partner with senior leaders across the organization to deliver company-wide security initiatives. 

Responsibilities Include::

  • Lead cross-functional projects and establish cutting-edge security development lifecycle practices

  • Directed security design reviews and threat modeling for new and existing services at iHerb

  • Evaluate, prototype, implement, and operate security-focused tools and services

  • Create new secure architecture standards, frameworks and patterns spanning multiple layers

  • Discover and analyze emerging security threats, determining applicability to iHerb and proactively implement centralized mitigations

  • Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA...)

  • Maintain a strong knowledge of current security threats and operational best practices

  • Drive our security assessment, penetration testing and bug bounty programs

  • Participate in security incident response

In order to be successful in this role you must have: 

  • Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with an innate ability to translate technical vulnerabilities into organizational risks

  • 8+ years of technical security leadership at a top-tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and broader cloud computing technologies

  • Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…)

  • Proficiency implementing SDL process, technology, and automation in a DevOps environment

  • Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption

  • Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

  • Excellent problem solving, critical thinking, collaboration and communication skills

Bonus Qualifications:

  • Experience with Cloudflare security, AWS VPCs, EC2 instances and docker

  • Ability to drive good decisions through data with great attention to detail and deliver KPIs 

  • Experience driving application security training, security champions and awareness campaigns

  • Active contributor to the security community (research, open source, publications…) with the ability to attract and hire great talent

#LI-JC1

The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work. The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc. iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations. Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year. Eligibility requirements for these benefits will be controlled by applicable plan documents. Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies. For more information on iHerb benefits, visit us at iHerbBenefits.com .

Anticipated Pay Scale:

$177,000—$225,000 USD

Staffing Agency Submission Notice iHerb does not accept unsolicited 3rd party ('Agency') candidates. If you are an Agency, please send any requests to be considered as a supplier in our Vendor Management System to View email address on codingjobboard.com . Do not contact iHerb employees directly. If requested to work on a role, any Agency candidates would be presented through the internal recruiting organization.

About iHerb iHerb is on a mission to make health and wellness accessible to all. We offer Earth’s best-curated selection of health and wellness products, at the best possible value, delivered with the most convenient experience. We’re the world’s largest eCommerce platform dedicated to vitamins, minerals, and supplements, and other health and wellness products. For more than 25 years, we’ve been making it simple for people all over the world to purchase the highest quality products. From supplements to skincare to grocery items, we ship over 50,000 products, from over 1,800 brands direct to our customers in 180+ countries. Our vision is to become the #1 destination for health and wellness across the world. With a passion for wellness and a mind for innovative solutions, iHerb team members share a vision for a healthier world that drives them each day. Our 5 Shared Values unite our global team:

Focus on the Customer · Empower Our People · Be Entrepreneurial & Pivot Quickly · Embrace Diversity & Inclusion · Strive for Simplicity

iHerb Benefits At iHerb, we are dedicated to offering programs designed to help our employees and their families stay healthy, live well, and plan for their financial future. Built on a strong foundation, our programs provide options and upgrades with flexibility, protection, and security in mind. For the comprehensive benefits list, visit  . For our international team members, you may be eligible for benefits depending on the country where you are employed. The Talent Acquisition Partner/local HR representative will go over the benefits you are eligible for. 

iHerb is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal Application Security Engineer in Remote vacancy
  • $177k - $225k

    Role Description Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a...  ...around the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle... 
    Principal
    Full time
    Remote work

    iHerb, LLC

    Remote
    6 days ago
  • $177k - $225k

     ...Summary: Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred...  ...the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance... 
    Principal
    Full time
    Local area
    Remote work

    iHerb

    Remote
    a month ago
  • $140k - $200k

     ...offering a wide range of simple, reliable, and secure crypto products and services to...  ..., reach, and impact. The Department: Application Security Gemini operates at the intersection...  ...The Role: Senior Application Security Engineer As a Senior Application Security... 
    Suggested
    Full time
    Work at office
    Remote work
    Flexible hours

    Gemini

    New York, NY
    22 hours ago
  • $150k - $196k

    This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across... 
    Suggested
    Temporary work
    Remote work

    Jobgether

    United States
    1 day ago
  • $150k - $196k

    This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This role offers the opportunity to strengthen application security across a... 
    Suggested
    Full time
    Temporary work
    Remote work
    Worldwide

    Jobgether

    United States
    2 days ago
  • $157k - $216k

     ...join us! About the Role AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at... 
    Full time
    Contract work
    Local area
    Remote work

    AlphaSense

    United States
    5 days ago
  • $83.1k - $149.5k

     ...20. Since then, we have issued innovative bitcoin-backed securities and have been the leader in bitcoin treasury companies. This...  ...and redefine financial investment. Job Description Application Security Engineer Strategy (Nasdaq: MSTR) • Tysons Corner, VA • Full-time,... 
    Full time
    Shift work

    MicroStrategy

    Tysons, VA
    22 hours ago
  • $92k - $123.9k

     ...ll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems...  ...real difference. Job Description Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure... 
    Full time
    Contract work
    Work at office
    Remote work
    Flexible hours

    Veilant

    United States
    2 days ago
  • $100k - $140k

     ...Principal Applications Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and... 
    Principal
    Full time
    H1b
    Local area
    Immediate start
    Remote work
    Visa sponsorship

    Bright Vision Technologies

    United States
    3 days ago
  • $159.8k - $303.5k

    Role Description As a Principal Security Research Engineer on the Threat Research and Detection Engineering (TRaDE) team, you'll play a key role in...  ...hands-on experience integrating LLM APIs into production applications ~Ability to work autonomously and drive decisions... 
    Principal
    Full time
    Local area
    Flexible hours

    Elastic

    Remote
    2 days ago
  •  ...continuously evolve a suite of internal security tools and platforms — including: ~Vulnerability Management (VM) ~Web Application Security (WAS) scanning orchestration...  ...tooling The successful candidate will engineer scalable, well-tested, end-to-end web applications... 
    Principal
    Full time

    Deltek

    Remote
    5 hours ago
  • $102k - $177.1k

    Role Description Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will require up to 10% travel. As the world’s... 
    Principal
    Full time
    Immediate start
    Remote work

    Johnson & Johnson Innovative Medicine

    Remote
    6 days ago
  • $150k - $196k

    Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and... 
    Full time
    Temporary work

    OneStream Software

    Remote
    4 days ago
  • Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly... 
    Full time
    Flexible hours

    Barracuda Networks Inc.

    Remote
    1 day ago
  • Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable... 
    Full time
    Flexible hours

    Las Vegas Sands Corp.

    Remote
    3 days ago
  • Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering... 
    Full time
    Remote work

    BioRender Inc.

    Remote
    3 days ago
  • $180k - $205.5k

    Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established... 
    Full time
    Work experience placement
    Remote work
    Sleeping nights

    Spring Health

    Remote
    1 day ago
  • $192k - $240k

    Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management.... 
    Full time
    Work experience placement

    Brex

    Remote
    7 days ago
  • $120k - $145k

    Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery... 
    Full time
    Remote work

    Parallels Inc

    Remote
    19 days ago
  • Role Description As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our... 
    Full time
    Temporary work
    Immediate start
    Remote work
    Flexible hours

    Canopy

    Remote
    3 days ago
  • $180k - $200k

     ...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most...  ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop... 
    Full time
    Flexible hours

    Virtru

    Remote
    7 days ago
  • $100k - $140k

    Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security... 
    Full time
    Flexible hours

    Zocdoc

    Remote
    18 days ago
  • Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security... 
    Full time
    Remote work
    Flexible hours

    GuidePoint Security

    Remote
    6 days ago
  • $100k - $130k

    Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified... 
    Full time
    Local area
    Immediate start

    Bonterra

    Remote
    5 days ago
  • $157k - $216k

    Role Description AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity... 
    Full time
    Remote work

    AlphaSense

    Remote
    1 day ago
  • $190k - $273k

    Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends... 
    Full time
    Flexible hours

    Apollo.io

    Remote
    7 days ago
  • $180k - $215k

    Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering... 
    Full time
    Work at office
    Remote work
    Weekend work

    Monarch Money

    Remote
    5 days ago
  • $120k - $258.5k

    Role Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving...  ...of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack... 
    Full time

    Nordstrom

    Remote
    5 days ago
  • $130k - $190k

     ...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50...  ...this role now: The company is maturing its application security function from a position of strength... 
    Full time
    Home office

    Mitek Systems

    Remote
    5 hours ago
  • Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development... 
    Full time
    Remote work

    Canary Technologies Corp

    Remote
    5 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Application Security Engineer. Be the first to apply!