Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Application Security Engineer [Remote]

$172k - $240k
Full-time

jobgether

United States
  • Remote job

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Application Security Engineer based in the United States.

This is a senior technical leadership role focused on embedding application security into software engineering at enterprise scale.
You will partner with development, DevOps, platform engineering, and SRE teams to reduce risk while enabling fast, secure delivery.
The role combines hands-on security engineering with strategic influence across applications, APIs, cloud environments, and CI/CD pipelines.
You will shape secure-by-design practices, scalable controls, reference architectures, automation, and engineering standards.
You will also help advance security approaches for AI-enabled applications and responsible use of AI in software development.
Success requires strong technical judgment, credibility with engineers, and the ability to turn complex security risks into practical solutions.
This is an opportunity to influence security maturity across a large, distributed engineering organization while remaining close to the technology.

Accountabilities:

  • Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.
  • Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.
  • Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.
  • Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.
  • Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.
  • Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.
  • Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.
  • Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.
  • Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.
  • Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.

Requirements:

  • 10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.
  • Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.
  • Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.
  • Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.
  • Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.
  • Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.
  • Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.
  • Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.
  • Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.
  • Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.
  • Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.
  • Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.
  • Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.
  • Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.
  • Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.

Benefits:

  • Base salary range of $172,000–$240,000 , depending on experience, skills, and geographic considerations.
  • 15% annual bonus target , subject to applicable plan terms and conditions.
  • Comprehensive employee benefits package covering health and other wellness needs.
  • Remote work opportunity within the United States.
  • Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.
  • Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.
  • Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Principal Application Security Engineer [Remote] in United States vacancy
  •  ...Time$160k - $225kA GPU cloud computing startup, revolutionizing the computing landscape, is looking to hire a Principal Product and Application Security Engineer to join their team as a founding engineer. This startup has hit a $1B valuation, closed their Series A... 
    Principal
    Full time

    Motion Recruitment

    San Francisco, CA
    3 days ago
  • $163.63k - $211.75k

     ...dynamic work environment in one of Chicago's most iconic areas.Role OverviewCboe’s Cybersecurity team is seeking a Principal Application Security Engineer to provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across our... 
    Principal
    Full time
    Work at office

    Cboe Exchange

    Chicago, IL
    1 day ago
  •  ...profit opportunities, and increase communication of initiatives across the organization. The role will focus on enrollment and applications of new incentive programs/agreements and maximizing existing. This includes optimizing process and procedures for gross profit generating... 
    Principal
    Full time
    Work at office
    Remote work

    CDW

    Chicago, IL
    1 day ago
  •  ...Principal Application Security Engineer In this role, you will: · Drive strategic efforts and lead transformative projects in the application security program. The ideal candidate will lead the charge in identifying and developing our next generation automation and... 
    Principal
    Work experience placement

    Veracity

    Phoenix, AZ
    4 days ago
  •  ...Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Principal Application Security Engineer in Charlotte, NC (Hybrid). Work with the brightest minds at one of the largest financial institutions in the world. This... 
    Principal
    Long term contract
    Full time
    Contract work
    Temporary work
    Flexible hours

    Motion Recruitment

    Charlotte, NC
    2 days ago
  •  ...Role Overview Are you passionate about securing global‑scale e‑commerce services and applications that power millions of customers across more...  ...countries? We are looking for a hands‑on Principal Product Security Engineer to lead Secure Development Lifecycle assurance... 
    Principal
    Remote work
    Home office

    iHerb Inc.

    New York, NY
    20 hours ago
  • $172k - $240k

    Role Description Join CDW and help secure the software, platforms, and...  ...Security team, you will help shape how application security is embedded into engineering at scale—partnering across...  ...while enabling delivery. As a Principal Application Security Engineer, you... 
    Principal
    Full time

    CDW

    Remote
    3 days ago
  • $144.2k - $288.4k

     ...Summary ~Development, Standards & Secure Design: ~Lead development and enforcement of application and AI security policies,...  ...: ~Serve as the principal SME for securing AI-enabled applications...  ...Leadership & Influence: ~Influence engineering and product teams to integrate... 
    Principal
    Hourly pay
    Full time
    Temporary work
    Local area

    CVS Health

    Remote
    2 days ago
  • $177k - $225k

     ...Summary: Are you passionate about securing global-scale ecommerce services and applications that power millions of customers across over a hundred...  ...the globe? We are looking for a hands-on Principal Product Security Engineer to lead our Secure Development Lifecycle assurance... 
    Principal
    Full time
    Local area
    Remote work

    iHerb

    Remote
    27 days ago
  • $97.9k - $166.7k

     ...Data Center, Telecommunication and Industrial and Defense applications. Headquartered in Lowell, Massachusetts, MACOM has design centers...  ...customers insights into our entire portfolio.Applications Engineer - Principal Our customer applications require high speed (GHz) ICs for... 
    Principal

    MACOM

    Newport Beach, CA
    20 hours ago
  • Chicago, Illinois100% RemoteFull Time$140k - $160kA consulting company is looking to bring on a hands on a Senior Application Security Engineer to work with clients on new development. You'll perform code reviews, conduct SAST/DAST/SCA scans, identify vulnerabilities in... 
    Full time

    Motion Recruitment

    Chicago, IL
    4 days ago
  • The Application Security team is responsible for the solutions and processes that secure Vanguard applications and operations. As an Application...  ...(containers, serverless, API, AI/ML).Provide hands-on engineering support for security incidents, threat events, vulnerability... 
    Full time

    Vanguard

    Malvern, PA
    4 days ago
  •  ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web,... 
    Full time

    Tempus

    Chicago, IL
    20 hours ago
  •  ...against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR...  ...disability. Envision yourself at BarracudaAs a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll... 
    Worldwide
    Flexible hours

    Barracuda

    Ann Arbor, MI
    3 days ago
  • $170k - $235k

     ...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets and spacecraft to deploy Starlink, the world’s most... 
    Permanent employment
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours
    Weekend work

    SpaceX

    Redmond, WA
    20 hours ago
  • $165k - $225k

     ...with the talent and ambition to build the technology that secures it.OUR MISSIONTrue Anomaly delivers decisive capabilities...  ...advantage and we are better together.YOUR MISSIONAs a Senior Application Security Engineer, you will be instrumental in implementing and auditing... 
    Permanent employment
    Shift work

    True Anomaly

    Denver, CO
    1 day ago
  • Job DescriptionSenior Application Security EngineerBasic PurposeWe are seeking an experienced Senior Application Security Engineer with strong expertise in application security testing, vulnerability management, and DevSecOps advisory services. The successful candidate... 

    Infosys Technologies

    Wisconsin
    4 days ago
  • $50 per hour

     ...WorthStandard Job DescriptionWhat You Will Be DoingAs the Applications Engineer Principal - Level 6 you will be responsible for providing expert...  ...leadership on funding capture strategies and proposals to secure resources for upcoming projects.Gather and assess product... 
    Principal
    Full time
    Temporary work
    Work experience placement
    Casual work
    Flexible hours

    Lockheed Martin

    Fort Worth, TX
    2 days ago
  •  ...organization, both internally and externallyAbility to travel as required by business and on-call availabilityThe Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the... 

    CBIZ

    Independence, OH
    2 days ago
  • $135k - $150k

     ...while our focus on creativity and innovative solutions empowers our customer communities to thrive.We are seeking a Senior Application Security Engineer to lead hands-on application security testing, secure code review, and secure SDLC enablement across moder application... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    3 days per week

    Nelnet

    Lincoln, NE
    2 days ago
  •  ...or Not Required)Preferred.Role Responsibilities: (what they will be doing)Deploy and configure container scanning tools to ensure secure containerized environments.Analyze vulnerabilities identified through container scans, prioritizing remediation based on risk.Develop... 

    Mindlance

    Atlanta, GA
    2 days ago
  • $107.9k - $195.05k

    The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations...  .... Primary ResponsibilitiesLeidos is looking for an Application Security Engineer to support: Application Security Operations and... 
    Full time
    Work at office
    Local area

    Leidos

    Ashburn, VA
    1 day ago
  •  ...Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Full time
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Insurance Company

    Farmington Hills, MI
    20 hours ago
  •  ...SerDes Alliance (ASA) Motion Link multi-Gigabit connectivity for next-generation sensors and vehicle displays. As part of the Applications Engineering team, you will work with both internal engineering teams to develop collaterals to ease customer adoption of our SerDes... 
    Principal
    Full time
    Work at office
    Local area
    Remote work

    NXP Semiconductors

    Austin, TX
    3 days ago
  • $120k - $202.5k

    Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec), Application Detection and Response (ADR), and DevSecOps. The ideal candidate will have hands... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Atlanta, GA
    2 days ago
  • $99k - $225k

    Application Security EngineerThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a cloud computing infrastructure architect, you know how to take advantage of cloud capabilities. On our team of experienced professionals, you’ll use... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Huntsville, AL
    1 day ago
  • $127k - $160.55k

     ...knowledge you've gained, and the personal interests that shape who you are.Position OverviewZelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and... 
    Full time
    Work at office
    Local area
    Visa sponsorship
    Flexible hours

    Zelis

    Boston, MA
    3 days ago
  • Opportunity OverviewTeam Overview:The Application Security Engineer, Agentic Secure Code Harness Engineer is a hands-on role responsible for operating, monitoring, and improving an AI-enabled AppSec harness used to evaluate application and infrastructure source code for... 
    Temporary work
    Work at office
    Home office
    Flexible hours
    3 days per week

    Edward Jones

    Tempe, AZ
    20 hours ago
  • Job DescriptionSecurity Application EngineerSeattle (Bellevue, WA) Long Term ProjectNeed GC...  ...Suite, Kali Linux) Job Description: Security team is seeking an enthusiastic Security...  ...such as billing ops, application support, engineering ops, finance, legal, privacy, risk... 

    USM Systems

    Seattle, WA
    20 hours ago
  • $100k - $167.5k

    Who We’re Looking For:The State Street Cyber Security Architecture & Engineering team is seeking an accomplished professional with proven expertise in Application Security (AppSec) and DevSecOps. The ideal candidate will have hands-on experience in application security,... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Quincy, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Application Security Engineer [Remote]. Be the first to apply!