Principal Application Security Engineer
$177k - $225kiHerb
Summary:
Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred countries around the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance processes, our security automation technologies, drive the security hardening strategy across our product and respond to current and emerging security threats. This role can be fully remote and must reside in US.
In this role, you will help us drive our Product Security strategy working with development teams globally to define new security capabilities, grow the team by hiring the best talent, and partner with senior leaders across the organization to deliver company-wide security initiatives.
Responsibilities Include::
Lead cross-functional projects and establish cutting-edge security development lifecycle practices
Directed security design reviews and threat modeling for new and existing services at iHerb
Evaluate, prototype, implement, and operate security-focused tools and services
Create new secure architecture standards, frameworks and patterns spanning multiple layers
Discover and analyze emerging security threats, determining applicability to iHerb and proactively implement centralized mitigations
Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA...)
Maintain a strong knowledge of current security threats and operational best practices
Drive our security assessment, penetration testing and bug bounty programs
Participate in security incident response
In order to be successful in this role you must have:
Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience) with an innate ability to translate technical vulnerabilities into organizational risks
8+ years of technical security leadership at a top-tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and broader cloud computing technologies
Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…)
Proficiency implementing SDL process, technology, and automation in a DevOps environment
Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection and encryption
Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)
Excellent problem solving, critical thinking, collaboration and communication skills
Bonus Qualifications:
Experience with Cloudflare security, AWS VPCs, EC2 instances and docker
Ability to drive good decisions through data with great attention to detail and deliver KPIs
Experience driving application security training, security champions and awareness campaigns
Active contributor to the security community (research, open source, publications…) with the ability to attract and hire great talent
#LI-JC1
The anticipated pay scale for this position can be found below, however the pay range applicable to you may vary by geographic location based on where the job is located or where you work. The final pay offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and years of experience within the job, the type of years and experience within the industry, education, etc. iHerb, LLC is a multi-state employer and this pay scale may not reflect positions that work in other states or locations. Employees (and their families) that meet eligibility criteria as outlined in applicable plan documents are eligible to participate in our medical, dental, vision, and basic life insurance programs and may enroll in our company’s 401(k) plan. Employees will also be eligible for Time Off and Paid Sick Leave pursuant to the company’s policies. Employees will enjoy paid holidays throughout the calendar year. Eligibility requirements for these benefits will be controlled by applicable plan documents. Hired applicant may be awarded Restrict Stock Units and receive annual bonuses pursuant to eligibility and performance criteria defined in the respective plan documents and policies. For more information on iHerb benefits, visit us at iHerbBenefits.com .
Anticipated Pay Scale:
$177,000—$225,000 USD
Staffing Agency Submission Notice iHerb does not accept unsolicited 3rd party ('Agency') candidates. If you are an Agency, please send any requests to be considered as a supplier in our Vendor Management System to View email address on codingjobboard.com . Do not contact iHerb employees directly. If requested to work on a role, any Agency candidates would be presented through the internal recruiting organization.
About iHerb iHerb is on a mission to make health and wellness accessible to all. We offer Earth’s best-curated selection of health and wellness products, at the best possible value, delivered with the most convenient experience. We’re the world’s largest eCommerce platform dedicated to vitamins, minerals, and supplements, and other health and wellness products. For more than 25 years, we’ve been making it simple for people all over the world to purchase the highest quality products. From supplements to skincare to grocery items, we ship over 50,000 products, from over 1,800 brands direct to our customers in 180+ countries. Our vision is to become the #1 destination for health and wellness across the world. With a passion for wellness and a mind for innovative solutions, iHerb team members share a vision for a healthier world that drives them each day. Our 5 Shared Values unite our global team:
Focus on the Customer · Empower Our People · Be Entrepreneurial & Pivot Quickly · Embrace Diversity & Inclusion · Strive for Simplicity
iHerb Benefits At iHerb, we are dedicated to offering programs designed to help our employees and their families stay healthy, live well, and plan for their financial future. Built on a strong foundation, our programs provide options and upgrades with flexibility, protection, and security in mind. For the comprehensive benefits list, visit . For our international team members, you may be eligible for benefits depending on the country where you are employed. The Talent Acquisition Partner/local HR representative will go over the benefits you are eligible for.
iHerb is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment.
$177k - $225k
Role Description Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a... ...around the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle...PrincipalFull timeRemote work$177k - $225k
...Summary: Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred... ...the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance...PrincipalFull timeLocal areaRemote work$140k - $200k
...offering a wide range of simple, reliable, and secure crypto products and services to... ..., reach, and impact. The Department: Application Security Gemini operates at the intersection... ...The Role: Senior Application Security Engineer As a Senior Application Security...SuggestedFull timeWork at officeRemote workFlexible hours$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SuggestedTemporary workRemote work$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in United States. This role offers the opportunity to strengthen application security across a...SuggestedFull timeTemporary workRemote workWorldwide$157k - $216k
...join us! About the Role AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at...Full timeContract workLocal areaRemote work$83.1k - $149.5k
...20. Since then, we have issued innovative bitcoin-backed securities and have been the leader in bitcoin treasury companies. This... ...and redefine financial investment. Job Description Application Security Engineer Strategy (Nasdaq: MSTR) • Tysons Corner, VA • Full-time,...Full timeShift work$92k - $123.9k
...ll work with the most talented software developers, systems engineers, and subject matter experts, building tools and systems... ...real difference. Job Description Veilant is looking for an Application Security Engineer to join our InfoSec team and help validate, secure...Full timeContract workWork at officeRemote workFlexible hours$100k - $140k
...Principal Applications Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and...PrincipalFull timeH1bLocal areaImmediate startRemote workVisa sponsorship$159.8k - $303.5k
Role Description As a Principal Security Research Engineer on the Threat Research and Detection Engineering (TRaDE) team, you'll play a key role in... ...hands-on experience integrating LLM APIs into production applications ~Ability to work autonomously and drive decisions...PrincipalFull timeLocal areaFlexible hours- ...continuously evolve a suite of internal security tools and platforms — including: ~Vulnerability Management (VM) ~Web Application Security (WAS) scanning orchestration... ...tooling The successful candidate will engineer scalable, well-tested, end-to-end web applications...PrincipalFull time
$102k - $177.1k
Role Description Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will require up to 10% travel. As the world’s...PrincipalFull timeImmediate startRemote work$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...Full timeTemporary work- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...Full timeFlexible hours
- Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable...Full timeFlexible hours
- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...Full timeRemote work
$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...Full timeWork experience placementRemote workSleeping nights$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management....Full timeWork experience placement$120k - $145k
Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery...Full timeRemote work- Role Description As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our...Full timeTemporary workImmediate startRemote workFlexible hours
$180k - $200k
...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most... ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop...Full timeFlexible hours$100k - $140k
Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security...Full timeFlexible hours- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...Full timeRemote workFlexible hours
$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...Full timeLocal areaImmediate start$157k - $216k
Role Description AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity...Full timeRemote work$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...Full timeFlexible hours$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...Full timeWork at officeRemote workWeekend work$120k - $258.5k
Role Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving... ...of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack...Full time$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...Full timeHome office- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...Full timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Application Security Engineer. Be the first to apply!
- senior director engineering Remote
- chief engineer Remote
- principal security engineer Remote
- project engineer assistant project manager Remote
- senior principal engineer Remote
- engineering director Remote
- principal application developer Remote
- senior chief engineer Remote
- director of product engineering Remote
- assistant chief engineer Remote















