Principal Application Security Engineer
iHerb Inc.
Location and Remote Policy United States of America – Remote / Home Office – must reside in U.S. Role Overview Are you passionate about securing global‑scale e‑commerce services and applications that power millions of customers across more than a hundred countries? We are looking for a hands‑on Principal Product Security Engineer to lead Secure Development Lifecycle assurance processes, security automation technologies, the hardening strategy across our product, and respond to current and emerging security threats. Responsibilities Lead cross‑functional projects and establish cutting‑edge security development lifecycle practices. Directed security design reviews and threat modeling for new and existing services at iHerb. Evaluate, prototype, implement, and operate security‑focused tools and services. Create new secure architecture standards, frameworks and patterns spanning multiple layers. Discover and analyze emerging security threats, determine applicability to iHerb and proactively implement centralized mitigations. Maintain a strong knowledge of current security threats and operational best practices. Drive security assessment, penetration testing and bug bounty programs. Participate in security incident response. Qualifications Demonstrated technical foundation (Computer Science / Engineering degree or equivalent). 10+ years of technical security leadership at a top‑tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security and broader cloud computing technologies. Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE…). Proficiency implementing SDL process, technology, and automation in a DevOps environment. Experience with large‑scale web applications and microservices, including API design, access management, authorisation, authentication, data protection and encryption. Excellent problem‑solving, critical thinking, collaboration and communication skills. Bonus Qualifications Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker. Ability to drive good decisions through data with great attention to detail and deliver KPIs. Experience driving application security training, security champions and awareness campaigns. Active contributor to the security community (research, open source, publications…). Pay Scale and Benefits The anticipated pay scale for this position can be found below; it may vary by geographic location. The final pay offered to a successful candidate will depend on experience, skill set, and other factors. Employees and their families that meet eligibility criteria may participate in our medical, dental, vision, and basic life insurance programs, and enroll in our 401(k) plan. Employees are also eligible for time off, paid sick leave, and paid holidays. RSUs and annual bonuses may be awarded based on eligibility and performance. For more information on iHerb benefits, visit iHerbBenefits.com. About iHerb iHerb is on a mission to make health and wellness accessible to all. We are the world’s largest e‑commerce platform dedicated to vitamins, minerals and supplements, serving consumers in over 180 countries with more than 50,000 products from 1,800 brands. Equal Opportunity Employer iHerb is an equal‑opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb prohibits discrimination and harassment. #J-18808-Ljbffr
$137.6k - $206.4k
101 Bloom Energy is seeking a Principal Application Engineer for a fully remote role. This position reports to the Sr Manager, Applications Engineering and involves driving complex technical sales activities while developing customer relationships and designing distributed...PrincipalRemote work$130k - $218k
...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants...SuggestedRemote work- ...A leading web platform company is seeking a Senior Application Security Engineer to enhance their secure development practices. This remote role involves collaborating with engineering teams, identifying security vulnerabilities, and leading security initiatives. Candidates...SuggestedRemote work
$215k - $230k
...A leading blockchain intelligence firm is looking for an Application Security Engineer to secure mission-critical infrastructure. The role involves leading security reviews, developing testing methodologies, and managing vulnerability assessment processes. Candidates should...Suggested- ...Leadership Drive enterprise-wide implementation of Application Security controls across CI/CD pipelines. Partner with AppSec Champions... ...goals. Enable decentralized security ownership across engineering teams. 2. Vulnerability & Threat Management...Suggested
- ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...ABOUT THE ROLE We are looking for a Senior Application Security Engineer to develop AI-enabled secure code scanning and integrate security...Flexible hours
$80 - $85 per hour
...identifying and prioritizing risks specifically related to application security. ? Develop, socialize, and implement security strategies... ...control Requirements Senior Application Security Engineer Mandatory Skills/Experience • 12 years of...Contract workFlexible hours- ...users (and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure....Remote work
$158k - $238k
...more performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies... ...power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development...Permanent employmentFull timeTemporary workFixed term contractLocal areaRemote workFlexible hours$220k - $350k
...Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors...Extra incomeLocal areaRemote workWork from homeHome office- ...Application Security Engineer - Vulnerability Operations (Mid-Level) Position: Contract Location: NJ/TX/NC Duration: 12+ months Job description: Required Qualifications & Skills: ~ Bachelor's degree in Computer Science,...Contract work
- ...catch regressions - turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted...Flexible hours
- ...Application Security Engineer We are seeking an Application Security Engineer who will support our client with ensuring security is integrated into all stages of software development. This role will be responsible for designing and building secure applications while...
$60 - $65 per hour
...Application Security Engineer Location: Phoenix, AZ 85054 (Atlanta GA, or NY, NY) (Onsite/Hybrid) Pay Rate: $60.00 – $65.00 per hour (Strict W2 Only) Duration: Through 12/31/2026 + Long-term Extension Compliance: No C2C, Third Parties, or W2 Referrals Role Overview...Hourly payWeekly payTemporary workFlexible hours- ...Application Security Engineer | Location: New York, NY or Charlotte, NC | Contract his Application Security Engineer contract role will embed security into the software development lifecycle to protect enterprise applications across web, mobile, and API ecosystems...Contract work
- ...Perform expert-level secure code reviews focusing on OWASP Top 10 and CWE vulnerability... .... Identify, triage, and remediate application-layer vulnerabilities, including broken... ...strong relevant experience in software engineering or security operations with a focus on...Remote work
$190k - $220k
...future of music is SoundCloud. We are looking for a Principal Product Security Engineer to join our Security team! As a Product Security Engineer... ...and Background: ~8+ years of product or application security experience, or other relevant software engineering...PrincipalWork at officeWork from homeFlexible hours- ...beacon of truth in global media and we need your help adding fuel to the fire. About the Role Polymarket is looking for an Application Security Engineer to embed security throughout our software development lifecycle. You'll partner directly with product and engineering...Contract workImmediate start
- **We believe talent deserves a human touch. Your application will be read by an actual person who’s excited to discover the real you.****Application Security Engineer**Location: Remote (United States) | Employment Type: Full-Time**About the Role**We are looking for an Application...Full timeRemote work
- ...providing a wide range of investment banking, securities, investment management and wealth... ...Strategy by architecting, engineering, deploying and operating technical security... ...agile delivery and adoption of Cloud and application security control implementations by development...Work experience placement
$137.6k - $206.4k
...We are looking for a Principal Application Engineer to join our team. This fully remote role reports to the Sr Manager, Applications Engineering... ...and proposal writing, addressing technical objections and securing approvals. Provide technical feedback to engineering and...PrincipalContract workLocal areaRemote work$135k - $200k
...defense, intelligence, and commercial applications. We are trusted by our customers to protect... .... The mission of the Application Security Team is to enable developers to be highly... ...important. As an Application Security Engineer, you will be hands-on and have wide-...Work experience placementWork at officeRemote workWork from homeRelocation package- ...world. Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune500 customers. In this pivotal role, you will be...Full timeFreelanceWork from home
- ...APPLY! At Scroll, we operate on the bleeding edge of a fast-moving frontier of zk technology, research and innovation. The Application Security Engineer will be responsible for improving the zkEVM-based zkRollup security, ensuring that Scroll is one of the safest Layer 2’s...Work at officeRemote workHome officeFlexible hours
- ...GuidePoint Security is looking for an Application Security Engineer to work remotely from the U.S. The role involves running security tools, integrating security practices into CI/CD pipelines, and collaborating with development teams. Ideal candidates will have at least...Remote workFlexible hours
$89.3k - $130k
...American Specialty Health Incorporated is looking for an Application Security Engineer II to enhance their Information Security team. The role focuses on protecting information assets from cybersecurity threats, ensuring compliance, and coordinating security measures across...Remote workWork from homeHome office$170k - $200k
...AI across their organizations. We design and deliver secure, scalable, agentic AI‑native platforms that reshape how... ...change, this is where you belong. About the Role The Principal Application Modernization Engineer is a senior technical leader who defines the scope of...Principal$10 per hour
...we’re excited about what’s ahead. About the Role: Our engineering organization is growing, and with that growth comes an expanding application and infrastructure footprint that requires dedicated application security ownership. This role exists to build that function...Full timeTemporary workFor contractorsWork at officeRemote workVisa sponsorshipFlexible hours- ...Bitwise Asset Management, Inc. is looking for a Staff Application Security Engineer to own the design and implementation of our application security program. This role provides the opportunity to build functions critical to the security of customer-facing products and...Remote work
$200k - $350k
...Traversal Traversal is the AI Site Reliability Engineer (SRE) for the enterprise—already... ...class engineers from industry: Citadel Securities, Cockroach Labs, Datadog, DE Shaw,... ...possible. The Role As an Infrastructure & Application Security Engineer at Traversal, you’ll...Full timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Application Security Engineer. Be the first to apply!
- principal quality engineer New York, NY
- principal cloud engineer New York, NY
- data center chief engineer New York, NY
- principal devops engineer New York, NY
- hotel chief engineer New York, NY
- principal developer New York, NY
- senior civil engineer project manager New York, NY
- chief building engineer New York, NY
- director of product engineering New York, NY
- general engineer New York, NY

