Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Principal Security Engineer, Application Security & Automation

$126k - $224.4k

Eli Lilly

Application Security Engineer

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We're looking for people who are determined to make life better for people around the world.

As an Application Security Engineer your role is focused on advancing Lilly's Secure SDLC program through engineering, automation, and applied AI. This is a critical, builder role on the Security Architecture & Engineering (SAE) team that will own and evolve core AppSec platforms- SAST, DAST, SCA, secret scanning, secrets management, and software supply chain controls- while building the automation and AI tooling that can scale across thousands of repositories and hundreds of applications. We're targeting candidates at R4-6. Job description is below.

What You'll Be Doing:

As an Application Security Engineer, you will operate at the intersection of software engineering and security engineering- leading platforms, writing code, building integrations, and designing automation. You will take part in Lilly's Secure SDLC program end-to-end, including SAST, DAST, SCA, and secret scanning tooling; secrets management; and our emerging software supply chain capabilities. You will use technology and apply LLM-based approaches to secure application and architecture design, vulnerability triage and remediation, and the delivery of secure-by-default patterns across Lilly's development ecosystem.

How You'll Succeed:

  • Engineering-first mentality: You bring real software development experience and treat security problems as engineering problems, automating what can be automated, integrating deeply with developer workflows, and writing production-quality code.
  • AI fluency: You are genuinely excited about LLMs and agentic tooling and have built things with them. You understand MCP, agent harnesses, and how to wire LLMs into real workflows — and you can tell where AI meaningfully accelerates security work versus where it shouldn't be trusted.
  • Platform management: Success requires running AppSec tooling as platforms with clear SLAs, telemetry, and continuous improvement rather than one-off scans and tickets.
  • Secure coding credibility: You have written code in multiple languages and ecosystems and can speak the developer's language. When you flag a finding or propose a control, engineers trust that you understand the tradeoffs.
  • Developer partnership: You build leverage through partnership—meeting development teams where they are, shipping secure-by-default patterns, and making the secure path the path of the least resistance.
  • Build system security: You understand that CI/CD is itself a high-value target. You have opinions on GitHub Actions OIDC, pinning actions to commit SHAs, least-privilege runners, and protecting secrets and artifacts as they move through the pipeline.

Key Responsibilities:

  • Evolve one or more AppSec platforms within the Secure SDLC program.
  • Design and build automation within Security Architecture and Engineering.
  • Apply LLMs, agentic frameworks, MCP servers, and tool-calling patterns.
  • Partner with development teams on secure coding practices, threat modeling, and remediation of findings from SAST, DAST, SCA, and secret scanning tools.
  • Contribute to Lilly's Secure SDLC standards and vulnerability management policy, translating policy into enforceable pipeline and platform controls.
  • Support the secrets management rollout and migration of applications off legacy secret stores, including code-level guidance for SDK-based and injected consumption patterns.
  • Produce developer-facing content, reference architectures, secure patterns, short-form instructional content and reusable code samples.
  • Harden Lilly's CI/CD environment against software supply chain attacks— pinned actions, OIDC-based cloud auth, runner isolation, workflow permissions, and protection of build-time secrets and artifacts.
  • Partner with the Cloud Security team on Infrastructure-as-Code (IaC) security — extending secure-by-default patterns and developer guardrails from application code into the infrastructure that runs it.

Your Basic Qualifications:

  • Bachelor's Degree in Computer Science, Information Security, Software Engineering, or related fields.
  • At least 2 years of dedicated application security experience
  • At least 2 years of software development experience with individual contributions to production systems,
  • At least a total of 5 years of combined experience across both rigors.
  • Demonstrated production coding experience in at least one of: Python, TypeScript/JavaScript, Java, Go, or C# — not solely in an advisory, review, or scripting capacity.
  • Experience building or integrating security automation within a GitHub environment, including GitHub Actions.
  • Familiarity with threat modeling in a professional setting
  • Hands-on experience with large language models (LLMs) in a professional or project context, such as prompt engineering, API integration, or workflow automation.

What You Should Bring:

  • Hands-on software development experience in at least one modern language (Python, TypeScript/JavaScript, Java, Go, or C#) with a track record of shipping working code- not just reviewing others'.
  • Strong expertise in application security fundamentals—OWASP Top 10, CWE, secure coding practices, threat modeling, and vulnerability assessment.
  • Experience operating or deeply integrating with SAST, DAST, SCA, and secret scanning tools.
  • Genuine enthusiasm for and hands-on experience with LLMs, prompt engineering, agentic workflows, or LLM-powered tooling—bonus points for things you have actually built and shipped.
  • Familiarity with secrets management platforms and patterns and with software supply chain / artifact management.
  • Working knowledge of cloud environments (AWS preferred; Azure or GCP welcome) and containerized workloads (ECS, EKS, Docker).
  • Familiarity with IaC scanning and the IaC ecosystem (Terraform, CloudFormation, Kubernetes manifests)
  • Strong communication skills; ability to translate security requirements into actionable engineering guidance and to represent AppSec in conversations with engineering partners.
  • Commitment to staying ahead of with emerging AppSec threats, tooling, and AI/LLM capabilities.

Location & Work Flexibility This role is based at our Corporate Center in Indianapolis, IN. We offer a flexible hybrid work model, with three days onsite and two days working remotely each week, supporting both collaboration and work‑life balance.

We are also open to considering fully remote candidates based on role requirements and business needs.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.

Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.

Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia Network, Black Employees at Lilly, Chinese Culture Network, Japanese International Leadership Network (JILN), Lilly India Network, Organization of Latinx at Lilly (OLA), PRIDE (LGBTQ+ Allies), Veterans Leadership Network (VLN), Women's Initiative for Leading at Lilly (WILL), enAble (for people with disabilities). Learn more about all of our groups.

Actual compensation will depend on a candidate's education, experience, skills, and geographic location. The anticipated wage for this position is

$126,000 - $224,400

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well

Vacancy posted 4 hours ago
Similar jobs that could be interesting for youBased on the Sr. Principal Security Engineer, Application Security & Automation in Indianapolis, IN vacancy
  • $104k - $156k

     ...Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will...  ...and mobile devices ~ Build automation and tooling to enforce secure...  ...~ Experience securing cloud-native applications / SaaS solutions and networks.... 
    Application
    Remote work

    Relativity

    Indianapolis, IN
    4 days ago
  • $66k - $171.6k

     ...make life better for people around the world. The Senior Principal Engineer - Automation Engineering will work as a member of the Automation...  ...purpose of ensuring that reliable and compliant control applications and systems are used in the manufacturing at Foundry. Additionally... 
    Application
    Senior
    Full time
    Work experience placement
    Remote work
    Flexible hours

    Eli Lilly

    Indianapolis, IN
    3 days ago
  • $71.2k - $158.2k

     ...Job Description The Senior Federal Information Systems Security Engineer (ISSE) serves as a technical integrator responsible for ensuring...  ...or client-facing roles may be required to comply with applicable requirements, such as immunization/occupational health mandates... 
    Application
    Senior
    Contract work
    Temporary work
    Work experience placement
    Relocation
    Flexible hours

    Oracle

    Indianapolis, IN
    1 day ago
  • $109.2k - $223.4k

     ...network underneath your workload. A Principal Network Engineer on our team supports the design,...  ...of a deep network understanding and automation skills to operate a production environment...  ...may be required to comply with applicable requirements, such as immunization and... 
    Application
    Temporary work
    Immediate start
    Flexible hours

    Oracle

    Indianapolis, IN
    3 days ago
  • $107.8k - $161.8k

     ...bonus-eligible. CNO’s IT Team CNO’s IT Team is hiring a Sr IT Security Engineer. The Sr IT Security Engineer will work with minimal supervision...  ...security technologies (endpoint management, cloud application security, certificate management, etc.). Strong fundamental... 
    Application
    Senior
    Remote job
    Full time
    Temporary work
    Work experience placement
    Work at office
    Work from home

    CNO Financial Group, Inc.

    Carmel, IN
    20 hours ago
  •  ...Collaborators and Doers. .We’re seeking a Principal Test Engineer - SDET I to join us. The Principal...  ..., design and execute both manual and automated functional, integration, performance...  ...microservices, APIs, cloud-based web applications, and distributed systems. Familiarity... 
    Application
    Contract work
    Work from home
    Shift work

    GoTo Meeting

    Carmel, IN
    2 days ago
  • $170.6k - $390k

     ...your career in information security! The opportunity The...  ...with infrastructure, cloud, application, and security operations teams...  ...Senior Manager in Cybersecurity Engineering, where you will play a...  ...with SASE / SSE platforms Automation and Infrastructure‑as‑Code exposure... 
    Application
    Senior
    Summer holiday
    Remote work
    Flexible hours

    EY

    Indianapolis, IN
    1 day ago
  •  ...Sr Cloud Security Engineer Seeking a Sr Cloud Security Engineer who understand security. Main focus...  ..., state file protection, and automated security scanning. Designs and implements...  ...across cloud infrastructure and applications. Responds to security incidents,... 
    Application
    Senior
    Flexible hours
    Shift work

    inSync Staffing

    Indianapolis, IN
    11 days ago
  •  ...achieve more through innovation, automation, and intelligent insights. The Role: Sr. Solutions Architect...  ...expertise in AI and automation, security, networking, digital transformation...  ...technical team develops custom applications, provides managed services, and... 
    Application
    Senior
    For contractors
    Work experience placement
    Local area

    Presidio

    Indianapolis, IN
    4 days ago
  • $114k - $198k

     ...coordinated by the Ramp Team Sr. Director. Key Objectives/Deliverables...  ...Provide Peptide API process engineering expertise to the Global...  ...facility start-up, through application of process engineering fundamentals...  ...skills with operations, automation, and other process team... 
    Application
    Senior
    Temporary work
    Local area
    Relocation
    Flexible hours
    Shift work

    Initial Therapeutics, Inc.

    Indianapolis, IN
    2 days ago
  •  ...Quality Assurance Manager Bachelor's Degree in Computer Applications, Computer Information Systems, Computer Science or related, Math, any Engineering, or Business related. 5 years as a Software Engineer, Automation Testing, QA Analyst or related. Ensure that quality... 
    Application
    Senior
    Relocation

    Pyramid Technology Solutions

    Indianapolis, IN
    1 day ago
  •  ...environments. This role ensures secure visibility into encrypted...  ...and developers Designs & engineers comprehensive network...  ...sets: 1) Access Control, 2) Application Security, 3) Business Continuity...  ...infrastructure is a plus Scripting or automation experience using Python,... 
    Application
    Temporary work
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    2 days ago
  • $117k - $209k

     ...through philanthropy and volunteerism. Responsibilities The Engineering Tech Center is responsible for providing global technical expertise...  ...& Energy Balances, Facilities (fitness for use), Root Cause applications, Equipment and Unit Operation Changes/Improvements including... 
    Application
    Senior
    Full time
    Contract work
    Temporary work
    Casual work
    H1b
    Visa sponsorship
    Work visa
    Flexible hours

    Eli Lilly and Company

    Indianapolis, IN
    2 days ago
  •  ...environments. This role ensures secure visibility into encrypted...  ...and developers Designs & engineers comprehensive network decryption...  ...sets: 1) Access Control, 2) Application Security, 3) Business...  ...infrastructure is a plus Scripting or automation experience using Python,... 
    Application
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    20 hours ago
  •  ...Network Security Engineer Group 1001 is a consumer-centric, technology-driven family of insurance...  ...and technological needs of unique application infrastructure across a diverse cloud,...  ...threats. Develop and maintain automation tools and scripts to streamline security... 
    Application
    Senior
    Temporary work
    Immediate start

    Group1001

    Zionsville, IN
    3 days ago
  •  ...Business Services, Inc. in Indianapolis is seeking a Systems Engineer responsible for designing, implementing, and supporting enterprise...  ...in virtualization and operating systems with a focus on automation and scalability. Candidates should have a minimum of 5 years experience... 
    Senior

    KSM Business Services, Inc.

    Indianapolis, IN
    1 day ago
  •  ...Looking For: We are seeking a Senior Security Engineer with experience in advanced detection...  ...hardening, and security automation. The Senior Security Engineer at OPENLANE...  ...WAF rule-writing for specialized web applications. Technical Benchmarking & PoC Execution... 
    Application
    Senior
    Temporary work
    Work at office
    Local area
    Immediate start

    Openlane

    Carmel, IN
    1 day ago
  • $184k - $230k

     ...make the world's health data secure, accessible and actionable, we...  ...We're Looking For As a Sr Product Security Architect at...  ...across Datavant's portfolio of applications, ensuring that security is embedded...  .... Partnering closely with engineering teams, product leadership,... 
    Application
    Senior
    Remote work

    Datavant

    Indianapolis, IN
    4 days ago
  •  ...PROFILES*** Job title: DevOps Engineer - IAM Automation Development Work Location:...  ...including App Registrations, Service Principals, Managed Identities, Identity...  ...Collaborate closely with cloud platform, security architecture, and application teams to deliver scalable,... 
    Application
    Senior
    Immediate start
    Remote work
    Relocation

    Spruce Infotech

    Indianapolis, IN
    4 days ago
  • $64.5k - $167.2k

     ...people around the world. Position Brand Description: The Principal Engineer - Process Automation will be a part of the IDAP (Indianapolis Device...  ...actions. Perform activities in accordance with cGMPs and applicable procedures. Proactively evaluate automation code to identify... 
    Application
    Full time
    Work experience placement
    Local area
    Flexible hours
    Weekend work

    Eli Lilly and Company

    Indianapolis, IN
    2 days ago
  • $186.07k - $218.9k

     ...Attendance is expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a...  ...offices), including expertise in IOT/IOT automation and prosumer networking gear. Conduct... 
    Application
    Senior
    Local area

    Coinbase

    Indianapolis, IN
    4 days ago
  • $87k - $110k

     ...and providing tailored solutions. The application period for the job is estimated to be 4...  ...challenges around energy, safety, security, air travel, productivity, and global urbanization...  ...the world's most complex challenges in automation, the future of aviation and energy... 
    Application
    Senior
    Permanent employment
    Temporary work
    Work experience placement
    Work at office
    Flexible hours

    Honeywell

    Indianapolis, IN
    22 hours ago
  • $78.4k - $106.1k

     ...Position Overview The DevSecOps Engineer, Junior supports the design, security, and automation of delivery pipelines and infrastructure that underpin mission-critical applications. The role contributes to CI/CD workflows that integrate build, test, and security controls... 
    Application
    Contract work
    Work experience placement
    Work at office
    Remote work

    ASM Research, An Accenture Federal Services Company

    Indianapolis, IN
    1 day ago
  • On-Site Experienced Automation Software Engineer Indianapolis, IN, USA Job Description On-Site Experienced Automation Software Engineer Kirby...  ...usage to identify effective solutions Configure and deploy applications, including installation and user training Design... 
    Application
    Senior
    For contractors
    Work at office
    Flexible hours

    Kirby Risk

    Indianapolis, IN
    2 days ago
  • Principal Automation Integration Engineer - API Network page is loaded## Principal Automation Integration Engineer...  ...on connecting our facilities (securely) and leveraging the data from those...  ...support innovation evaluation and application for Manufacturing Process... 
    Application
    Full time
    Temporary work
    H1b
    Relocation
    Visa sponsorship
    Work visa
    Monday to Friday
    Flexible hours
    Day shift

    Eli Lilly and Company

    Indianapolis, IN
    2 days ago
  •  ...Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst ) Information Security Risk Management Hybrid 1: This role...  ...support & operations or design & engineering role in any of the following...  ...areas: 1) Access Control, 2) Application Security, 3) Business... 
    Application
    Senior
    Temporary work
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    3 days ago
  • $103k - $128k

    Description As MISO's Security Architect I , you will support...  ...across enterprise systems, applications, and cloud platforms. This role...  ...places a strong emphasis on automation, scripting, configuration...  ...secure-by-design practices into engineering and operations. Develop... 
    Application
    Local area

    MISO

    Carmel, IN
    4 days ago
  • $87k - $222.2k

    Initial Therapeutics, Inc. is seeking a hands-on engineer to integrate agentic AI with laboratory automation systems in Indianapolis, Indiana. The role involves rapid prototyping and scaling AI-driven workflows to enhance molecule discovery. Candidates should hold a PhD... 
    Senior

    Initial Therapeutics, Inc.

    Indianapolis, IN
    3 days ago
  • A leading global healthcare firm in Indianapolis is looking for a Senior Principal Engineer - Automation Engineering. This role involves providing automation support for operations, mentoring team members, and overseeing the implementation of control systems. Candidates... 
    Senior
    Full time

    Eli Lilly

    Indianapolis, IN
    2 days ago
  • $250.6k - $384.6k

     ...mission is to help GM deliver trusted automated‑driving products. As the central...  ...to achieving that vision. As Sr Manager, AV Behavior Safety Engineering, you will lead the strategy and support...  ...It is based on what a successful applicant might be paid in accordance with... 
    Application
    Senior
    Odd job
    Permanent employment
    Local area
    Remote work
    Work from home
    Flexible hours

    General Motors

    Indianapolis, IN
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Principal Security Engineer, Application Security & Automation. Be the first to apply!