Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Principal Security Engineer, Application Security & Automation

$126k - $224.4k
Full-time

Eli Lilly and Company

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world. What You'll Be Doing: As an Application Security Engineer, you will operate at the intersection of software engineering and security engineering- leading platforms, writing code, building integrations, and designing automation. You will take part in Lilly's Secure SDLC program end-to-end, including SAST, DAST, SCA, and secret scanning tooling; secrets management; and our emerging software supply chain capabilities. You will use technology and apply LLM-based approaches to secure application and architecture design, vulnerability triage and remediation, and the delivery of secure‑by‑default patterns across Lilly’s development ecosystem. How You'll Succeed: Engineering-first mentality: You bring real software development experience and treat security problems as engineering problems, automating what can be automated, integrating deeply with developer workflows, and writing production-quality code. AI fluency: You are genuinely excited about LLMs and agentic tooling and have built things with them. You understand MCP, agent harnesses, and how to wire LLMs into real workflows — and you can tell where AI meaningfully accelerates security work versus where it shouldn't be trusted. Platform management: Success requires running AppSec tooling as platforms with clear SLAs, telemetry, and continuous improvement rather than one-off scans and tickets. Secure coding credibility: You have written code in multiple languages and ecosystems and can speak the developer's language. When you flag a finding or propose a control, engineers trust that you understand the tradeoffs. Developer partnership: You build leverage through partnership—meeting development teams where they are, shipping secure-by-default patterns, and making the secure path the path of the least resistance. Build system security: You understand that CI/CD is itself a high-value target. You have opinions on GitHub Actions OIDC, pinning actions to commit SHAs, least-privilege runners, and protecting secrets and artifacts as they move through the pipeline. Key Responsibilities: Evolve one or more AppSec platforms within the Secure SDLC program. Design and build automation within Security Architecture and Engineering. Apply LLMs, agentic frameworks, MCP servers, and tool-calling patterns. Partner with development teams on secure coding practices, threat modeling, and remediation of findings from SAST, DAST, SCA, and secret scanning tools. Contribute to Lilly's Secure SDLC standards and vulnerability management policy, translating policy into enforceable pipeline and platform controls. Support the secrets management rollout and migration of applications off legacy secret stores, including code-level guidance for SDK-based and injected consumption patterns. Produce developer-facing content, reference architectures, secure patterns, short-form instructional content and reusable code samples. Harden Lilly's CI/CD environment against software supply chain attacks— pinned actions, OIDC-based cloud auth, runner isolation, workflow permissions, and protection of build-time secrets and artifacts. Partner with the Cloud Security team on Infrastructure-as-Code (IaC) security — extending secure-by-default patterns and developer guardrails from application code into the infrastructure that runs it. Your Basic Qualifications: Bachelor's Degree in Computer Science, Information Security, Software Engineering, or related fields. At least 2 years of dedicated application security experience At least 2 years of software development experience with individual contributions to production systems, At least a total of 5 years of combined experience across both rigors. Proven production coding experience in at least one of: Python, TypeScript/JavaScript, Java, Go, or C# — not solely in an advisory, review, or scripting capacity. Experience building or integrating security automation within a GitHub environment, including GitHub Actions. Familiarity with threat modeling in a professional setting Hands-on experience with large language models (LLMs) in a professional or project context, such as prompt engineering, API integration, or workflow automation. What You Should Bring: Hands-on software development experience in at least one modern language (Python, TypeScript/JavaScript, Java, Go, or C#) with a track record of shipping working code- not just reviewing others'. Strong expertise in application security fundamentals—OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability assessment. Experience operating or deeply integrating with SAST, DAST, SCA, and secret scanning tools. Genuine enthusiasm for and hands-on experience with LLMs, prompt engineering, agentic workflows, or LLM-powered tooling—bonus points for things you have actually built and shipped. Familiarity with secrets management platforms and patterns and with software supply chain / artifact management. Working knowledge of cloud environments (AWS preferred; Azure or GCP welcome) and containerized workloads (ECS, EKS, Docker). Familiarity with IaC scanning and the IaC ecosystem (Terraform, CloudFormation, Kubernetes manifests) Strong communication skills; ability to translate security requirements into actionable engineering guidance and to represent AppSec in conversations with engineering partners. Commitment to staying ahead of with emerging AppSec threats, tooling, and AI/LLM capabilities. Location & Work Flexibility This role is based at our Corporate Center in Indianapolis, IN. We offer a flexible hybrid work model, with three days onsite and two days working remotely each week, supporting both collaboration and work‑life balance. We are also open to considering fully remote candidates based on role requirements and business needs. Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form ( for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response. Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status. Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia Network, Black Employees at Lilly, Chinese Culture Network, Japanese International Leadership Network (JILN), Lilly India Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ+ Allies), Veterans Leadership Network (VLN), Women’s Initiative for Leading at Lilly (WILL), enAble (for people with disabilities). Learn more about all of our groups. Actual compensation will depend on a candidate’s education, experience, skills, and geographic location. The anticipated wage for this position is $126,000 - $224,400 Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees. #WeAreLilly At Lilly we strive to ensure our employees are part of a team that cares about them and our shared purpose of making life better for those around the world. How do we do this? We continue to look for ways to include, innovate, accelerate and deliver while maintaining integrity, excellence and respect for people. We hope that you seek to join us on our journey as we create medicine and deliver improved outcomes for patients across the globe! #WeAreLilly

Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Sr. Principal Security Engineer, Application Security & Automation in United States vacancy
  • $126k - $224.4k

     ...Application Security Engineer At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare...  ...Lilly's Secure SDLC program through engineering, automation, and applied AI. This is a critical, builder role on the... 
    Application
    Senior
    Full time
    Remote work
    Flexible hours
    2 days per week

    Eli Lilly

    Indianapolis, IN
    40 minutes ago
  •  ...senior member of the Cybersecurity Engineering team responsible for designing, implementing...  ..., and optimizing enterprise security monitoring and automation capabilities. Led the architecture...  ...from cloud, network, endpoint, and application sources. Develop and maintain... 
    Application
    Senior
    Work at office

    Red Lobster

    Orlando, FL
    4 days ago
  • $139.2k - $218.4k

     ...operational efficiency, reduce security and compliance risk, and...  ...role As a Senior Security Engineer on GitLab's Security...  ...security operations through automation and intelligent workflows....  ...knowledge, skills, abilities of the applicant, equity with other team members... 
    Application
    Senior
    Full time
    Remote work
    Flexible hours

    GitLab

    United States
    1 day ago
  • $139.2k - $218.4k

     ...operational efficiency, reduce security and compliance risk, and...  ...this role As a Senior Security Engineer on GitLab’s Security...  ...security operations through automation and intelligent workflows....  ...knowledge, skills, abilities of the applicant, equity with other team members... 
    Application
    Senior
    Full time
    Remote work
    Flexible hours

    GrabJobs

    United States
    19 hours ago
  • $195k - $240k

     ...Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary...  ...environment, and we expect our offensive engineers to build the tooling that makes...  ...complexity at scale. It brings applications, infrastructure, data, models,... 
    Application
    Senior
    Work at office

    Dormont Manufacturing Co

    New York, NY
    2 days ago
  • $164.8k - $228.4k

     ...Upstart's Information Security team is dedicated to advancing...  ...through strong collaboration, automation, and thoughtful security design...  .... As a Senior Security Engineer focused on Data Security...  ..., services, or internal web applications) Experience launching new... 
    Application
    Senior
    Summer work
    Currently hiring
    Local area
    Remote work
    Work from home

    UpStart

    United States
    3 days ago
  • $108.25k - $130k

     ...our proposed architectures, apps, and automations really do improve their work lives. If...  ...WHERE YOU’LL FIT WITHIN THE TEAM The SaaS security engineer will lead and scale our SaaS security...  ..., cloud infrastructure, and SaaS application configuration practices. The role also... 
    Application
    Senior
    Full time
    Work experience placement
    Work at office
    1 day per week

    Bain & Company

    Boston, MA
    4 days ago
  •  ...About the role: The Senior Security Engineer I - Enterprise Security is responsible...  ...others. You are passionate about building automated alerting and response capabilities and...  ...and misconfigurations in systems and applications. Mentor engineers in the Security team... 
    Application
    Senior
    Full time
    Remote work
    Relocation package
    Flexible hours

    Samsara

    Grizzly Flats, CA
    17 hours ago
  • $178.4k - $226.7k

     ...you wanted an opportunity to secure an advanced satellite based...  ...Control Requirement Due to applicable export control laws and...  ...will leverage support from automation teams that find discoverable...  ...security advocates & security engineers via 1-1 sessions & office hours... 
    Application
    Senior
    Permanent employment
    Work experience placement
    Internship
    Work at office
    Local area
    Flexible hours

    Amazon.com Inc

    Redmond, WA
    2 days ago
  • $336k - $395k

     ...The Security team ensures that our users, employees...  ...tooling that enable engineering teams to ship fast without...  ...and alerting, automation to eliminate entire classes...  ...We are seeking a Principal Security Engineer to...  ...Deep understanding of application and platform risks (e... 
    Application
    Work at office
    Local area
    Work from home
    Worldwide

    Asana

    San Francisco, CA
    2 days ago
  • $270k - $300k

     ...will lead strategic identity security initiatives across the...  ...highly collaborative technical engineer who can execute at both the...  ...~ Serve as the engineering principal on implementing secure identity...  ...standards ~ Work with application development teams to... 
    Application
    Daily paid
    Local area
    Remote work

    Jones Lang LaSalle IP, Inc.

    United States
    1 day ago
  •  ...capable of driving enterprise security initiatives and influencing...  ...a Senior Security Software Engineer, you will design, lead, and...  ...DLQs. Implement security automation (SOAR-like playbooks) that...  ...their skills and capabilities. Applicants in the recruitment process... 
    Application
    Senior
    Local area
    Work from home
    Relocation package

    General Motors

    Austin, TX
    1 day ago
  • $190.6k - $263.9k

     ...from you. The Team: Upstart's Security Engineering team is passionate about bringing...  ...teams to reduce security risk through automation, collaboration, offensive security, and...  ...engineering practices across application security, infrastructure security, offensive... 
    Application
    Senior
    Summer work
    Currently hiring
    Local area
    Remote work
    Work from home

    UpStart

    United States
    4 days ago
  •  ...Staff Security Engineer (IOT/Embedded Security) Tysons, Virginia The Staff Security Engineer...  ...ensure they remain up to date with applicable industry standards and compliance...  ...systems Use a combination of manual and automated techniques to assess risks and... 
    Application
    Casual work
    Work at office
    Immediate start
    Worldwide

    Alarm.com

    McLean, VA
    2 days ago
  • $190.6k

     ...hear from you. The Team Upstart’s Security Engineering team protects Upstart’s people,...  ...monitoring and response, secure tooling, automation, and cross-functional security programs...  ..., cloud environments, business applications, endpoints, identity platforms, and critical... 
    Application
    Senior
    Summer work
    Currently hiring
    Local area
    Remote work
    Work from home

    GrabJobs

    United States
    17 hours ago
  •  ...productivity. We’re looking for a smart, driven engineering professional to join our infrastructure team and help support a secure, scalable, and user-friendly computing...  ...for next-generation AI and machine learning applications, particularly in the domain of Confidential... 
    Application
    Senior
    Full time

    Upscaleai

    Santa Clara, CA
    4 days ago
  •  ...Network Operations Center (NOC) Engineer (Tier 3) serves as the...  ...involving routing instability, security incidents, hardware failures...  ...knowledge of security automation, API-driven provisioning, and...  ...ZPA), enabling secure user-to-application connectivity without traditional... 
    Application
    Senior
    Night shift

    Vanguard Group, Inc.

    Charlotte, NC
    3 days ago
  • $155.58k - $320.32k

     ...rules, processes, and platform for our secure development lifecycle. Deliver and review...  ...Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent...  ...years of experience in product security, application security, or security related software... 
    Application
    Senior
    Work at office
    Local area
    Relocation
    Relocation package

    Pinterest

    Chicago, IL
    4 days ago
  • $165k - $185k

     ...Role Betterment is hiring a Sr. Security Engineer, Corporate Information Security to be a principal member of the Workforce Security...  ...under growth, and lifecycle automation that reaches every downstream...  ...a few weeks to review all applications. If we’d like to spend more time... 
    Application
    Senior
    Full time
    Temporary work
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    Betterment

    New York, NY
    9 hours ago
  • $225k - $250k

     ...Data Center Security Software Principal Engineer Fleet Data Centers designs, builds and operates mega...  ...Principal Engineer leads applied AI, automation engineering, and systems...  ...experience in security engineering, AI/ML applications, or systems integration. Experience... 
    Application

    Fleet Data Centers

    Arlington, VA
    1 day ago
  •  ...capable of driving enterprise security initiatives and influencing...  ...a Staff Security Software Engineer on GM's Security Operations...  ...integrations and AI-driven automation. You'll set standards for how...  ...skills and capabilities. Applicants in the recruitment process may... 
    Application
    Contract work
    Local area
    Work from home
    Relocation package

    General Motors

    Austin, TX
    17 hours ago
  • $154k - $286k

     ...to join a dynamic and growing team of engineers developing high-speed PMA layer IP for...  ...as needed with the digital, analog and application teams. Candidate should be willing to work...  ...on. We are a global electronic design automation company, providing software, hardware,... 
    Application
    Senior
    Full time
    Work experience placement
    Work at office

    Cadence Design Systems

    San Jose, CA
    3 days ago
  • Sr Principal Engineer, NPD Quality and Reliability Job Description Onsemi is looking for a self-...  ...sustainable energy grids, industrial automation, and 5G and cloud infrastructure. With...  ...Opportunity Employer. All qualified applicants will receive consideration for employment... 
    Application
    Senior
    Full time
    Local area
    Shift work

    Onsemi

    Allen, TX
    2 days ago
  • Proofpoint is seeking a Senior Director of Security Engineering in Sunnyvale, CA. This role will lead the vision and strategy for security...  ...engineering, ensuring robust protection across infrastructure and applications. The ideal candidate will have over a decade of experience... 
    Application
    Senior

    Proofpoint

    Sunnyvale, CA
    3 days ago
  • $165k - $242k

     ...You'll Do: The Enterprise Security team at CoreWeave is responsible...  ...controls, guardrails, and automation that keep our workforce,...  ...contractors, and critical business applications protected in a modern, cloud...  ...: As a Senior Security Engineer, Enterprise Security , you'... 
    Application
    Senior
    Permanent employment
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    21 days ago
  • $190.6k - $263.9k

     ...you. The Team: Upstart's Application Security team ispassionate in bringing...  ...We approach our efforts through automation, strong collaboration with our partner...  ...for Upstarters. As the Principal Application Security Engineer at Upstart, you will be expected... 
    Application
    Summer work
    Currently hiring
    Work at office
    Local area
    Remote work
    Work from home

    UpStart

    United States
    1 day ago
  • $184.44k - $273.9k

     ...highly technical and execution‑oriented Principal - Information Security Engineering to lead the design, implementation, and...  ...to ensure high‑fidelity alerting and automated remediation. Partner with infrastructure and application teams to ensure secure deployment standards... 
    Application
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours
    3 days per week

    Seagate Technology

    Fremont, CA
    9 hours ago
  •  ...to quickly find answers and automate tasks. Powered by the world's...  ...automation with Moveworks' Reasoning Engine and natural language...  ...Description The Moveworks Security team at ServiceNow is not looking...  ...employer. All qualified applicants will receive consideration for... 
    Application
    Senior
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    United States
    3 days ago
  • $141k - $169.25k

     ...our proposed architectures, apps, and automations really do improve their work lives....  ...WHERE YOU’LL FIT WITHIN THE TEAM Staff Security Engineers are responsible for the security...  ...27001, GDPR). Embed in centralized Application security team to promote secure AI tooling... 
    Application
    Full time
    Work at office
    Local area
    1 day per week

    Bain & Company

    Boston, MA
    1 day ago
  • $196k - $220.5k

     ...games. We are looking for an experienced Senior Enterprise Security Engineer reporting to the Engineering Manager of Enterprise Security....  ..., and device trust tooling. ~ Knowledge and practical application of IT security best practices. ~ A great sense of empathy.... 
    Application
    Senior
    Full time
    Work at office
    Relocation
    Relocation package
    2 days per week
    1 day per week

    Discord

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Principal Security Engineer, Application Security & Automation. Be the first to apply!