Principal Application Security Engineer [Remote]
$172k - $240kjobgether
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Application Security Engineer based in the United States.
This is a senior technical leadership role focused on embedding application security into software engineering at enterprise scale.
You will partner with development, DevOps, platform engineering, and SRE teams to reduce risk while enabling fast, secure delivery.
The role combines hands-on security engineering with strategic influence across applications, APIs, cloud environments, and CI/CD pipelines.
You will shape secure-by-design practices, scalable controls, reference architectures, automation, and engineering standards.
You will also help advance security approaches for AI-enabled applications and responsible use of AI in software development.
Success requires strong technical judgment, credibility with engineers, and the ability to turn complex security risks into practical solutions.
This is an opportunity to influence security maturity across a large, distributed engineering organization while remaining close to the technology.
Accountabilities:
- Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
- Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
- Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
- Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
- Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
- Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
- Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
- Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
- Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
- Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.
Requirements:
- 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
- Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
- Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
- Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
- Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
- Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
- Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
- Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
- Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
- Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
- Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
- Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
- Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
- Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
- Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.
Benefits:
- Base salary range of $172,000–$240,000 , depending on experience, skills, and geographic considerations.
- 15% annual bonus target , subject to applicable plan terms and conditions.
- Comprehensive employee benefits package covering health and other wellness needs.
- Remote work opportunity within the United States.
- Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
- Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.
- Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...Time$160k - $225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A...PrincipalFull time
$163.63k - $211.75k
...dynamic work environment in one of Chicago's most iconic areas.Role OverviewCboe’s Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our...PrincipalFull timeWork at office- ...profit opportunities, and increase communication of initiatives across the organization. The role will focus on enrollment and applications of new incentive programs/agreements and maximizing existing. This includes optimizing process and procedures for gross profit generating...PrincipalFull timeWork at officeRemote work
- ...Principal Application Security Engineer In this role, you will: · Drive strategic efforts and lead transformative projects in the application security program. The ideal candidate will lead the charge in identifying and developing our next generation automation and...PrincipalWork experience placement
- ...Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Principal Application Security Engineer in Charlotte, NC (Hybrid). Work with the brightest minds at one of the largest financial institutions in the world. This...PrincipalLong term contractFull timeContract workTemporary workFlexible hours
- ...Role Overview Are you passionate about securing global‑scale e‑commerce services and applications that power millions of customers across more... ...countries? We are looking for a hands‑on Principal Product Security Engineer to lead Secure Development Lifecycle assurance...PrincipalRemote workHome office
$172k - $240k
Role Description Join CDW and help secure the software, platforms, and... ...Security team, you will help shape how application security is embedded into engineering at scale—partnering across... ...while enabling delivery. As a Principal Application Security Engineer, you...PrincipalFull time$144.2k - $288.4k
...Summary ~Development, Standards & Secure Design: ~Lead development and enforcement of application and AI security policies,... ...: ~Serve as the principal SME for securing AI-enabled applications... ...Leadership & Influence: ~Influence engineering and product teams to integrate...PrincipalHourly payFull timeTemporary workLocal area$177k - $225k
...Summary: Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred... ...the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance...PrincipalFull timeLocal areaRemote work$97.9k - $166.7k
...Data Center, Telecommunication and Industrial and Defense applications. Headquartered in Lowell, Massachusetts, MACOM has design centers... ...customers insights into our entire portfolio.Applications Engineer - Principal Our customer applications require high speed (GHz) ICs for...Principal- Chicago, Illinois100% RemoteFull Time$140k - $160kA consulting company is looking to bring on a hands on a Senior Application Security Engineer to work with clients on new development. You'll perform code reviews, conduct SAST/DAST/SCA scans, identify vulnerabilities in...Full time
- The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application... ...(containers, serverless, API, AI/ML).Provide hands-on engineering support for security incidents, threat events, vulnerability...Full time
- ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web,...Full time
- ...against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR... ...disability. Envision yourself at BarracudaAs a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll...WorldwideFlexible hours
$170k - $235k
...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets and spacecraft to deploy Starlink, the world’s most...Permanent employmentTemporary workWork at officeWorldwideMonday to FridayFlexible hoursWeekend work$165k - $225k
...with the talent and ambition to build the technology that secures it.OUR MISSIONTrue Anomaly delivers decisive capabilities... ...advantage and we are better together.YOUR MISSIONAs a Senior Application Security Engineer, you will be instrumental in implementing and auditing...Permanent employmentShift work- Job DescriptionSenior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate...
$50 per hour
...WorthStandard Job DescriptionWhat You Will Be DoingAs the Applications Engineer Principal - Level 6 you will be responsible for providing expert... ...leadership on funding capture strategies and proposals to secure resources for upcoming projects.Gather and assess product...PrincipalFull timeTemporary workWork experience placementCasual workFlexible hours- ...organization, both internally and externallyAbility to travel as required by business and on-call availabilityThe Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the...
$135k - $150k
...while our focus on creativity and innovative solutions empowers our customer communities to thrive.We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application...Full timeTemporary workWork at officeLocal areaRemote work3 days per week- ...or Not Required)Preferred.Role Responsibilities: (what they will be doing)Deploy and configure container scanning tools to ensure secure containerized environments.Analyze vulnerabilities identified through container scans, prioritizing remediation based on risk.Develop...
$107.9k - $195.05k
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations... .... Primary ResponsibilitiesLeidos is looking for an Application Security Engineer to support: Application Security Operations and...Full timeWork at officeLocal area- ...Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to...Full timeLocal areaRemote workFlexible hoursShift work
- ...SerDes Alliance (ASA) Motion Link multi-Gigabit connectivity for next-generation sensors and vehicle displays. As part of the Applications Engineering team, you will work with both internal engineering teams to develop collaterals to ease customer adoption of our SerDes...PrincipalFull timeWork at officeLocal areaRemote work
$120k - $202.5k
Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec), Application Detection and Response (ADR), and DevSecOps. The ideal candidate will have hands...Full timeTemporary workFlexible hours$99k - $225k
Application Security EngineerThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you’ll use...Full timeContract workPart timeWork at officeLocal areaRemote work$127k - $160.55k
...knowledge you've gained, and the personal interests that shape who you are.Position OverviewZelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and...Full timeWork at officeLocal areaVisa sponsorshipFlexible hours- Opportunity OverviewTeam Overview:The Application Security Engineer, Agentic Secure Code Harness Engineer is a hands-on role responsible for operating, monitoring, and improving an AI-enabled AppSec harness used to evaluate application and infrastructure source code for...Temporary workWork at officeHome officeFlexible hours3 days per week
- Job DescriptionSecurity Application EngineerSeattle (Bellevue, WA) Long Term ProjectNeed GC... ...Suite, Kali Linux) Job Description: Security team is seeking an enthusiastic Security... ...such as billing ops, application support, engineering ops, finance, legal, privacy, risk...
$100k - $167.5k
Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec) and DevSecOps. The ideal candidate will have hands-on experience in application security,...Full timeTemporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Application Security Engineer [Remote]. Be the first to apply!
- senior principal engineer United States
- director data engineering United States
- data center chief engineer United States
- director quality engineering United States
- director of product engineering United States
- chief design engineer United States
- principal quality engineer United States
- chief engineer United States
- senior chief engineer United States
- clinical engineering director United States



