Principal Application Security Engineer
iHerb Inc.
Location and Remote Policy
United States of America – Remote / Home Office – must reside in U.S.
Are you passionate about securing global‑scale e‑commerce services and applications that power millions of customers across more than a hundred countries? We are looking for a hands‑on Principal Product Security Engineer to lead Secure Development Lifecycle assurance processes, security automation technologies, the hardening strategy across our product, and respond to current and emerging security threats. Responsibilities Lead cross‑functional projects and establish cutting‑edge security development lifecycle practices. Directed security design reviews and threat modeling for new and existing services at iHerb. Evaluate, prototype, implement, and operate security‑focused tools and services. Create new secure architecture standards, frameworks and patterns spanning multiple layers. Discover and analyze emerging security threats, determine applicability to iHerb and proactively implement centralized mitigations. Maintain a strong knowledge of current security threats and operational best practices. Drive security assessment, penetration testing and bug bounty programs. Participate in security incident response. Qualifications Demonstrated technical foundation (Computer Science / Engineering degree or equivalent). 10+ years of technical security leadership at a top‑tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security and broader cloud computing technologies. Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE…). Proficiency implementing SDL process, technology, and automation in a DevOps environment. Experience with large‑scale web applications and microservices, including API design, access management, authorisation, authentication, data protection and encryption. Excellent problem‑solving, critical thinking, collaboration and communication skills. Bonus Qualifications Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker. Ability to drive good decisions through data with great attention to detail and deliver KPIs. Experience driving application security training, security champions and awareness campaigns. Active contributor to the security community (research, open source, publications…). Pay Scale and Benefits
The anticipated pay scale for this position can be found below; it may vary by geographic location. The final pay offered to a successful candidate will depend on experience, skill set, and other factors. Employees and their families that meet eligibility criteria may participate in our medical, dental, vision, and basic life insurance programs, and enroll in our 401(k) plan. Employees are also eligible for time off, paid sick leave, and paid holidays. RSUs and annual bonuses may be awarded based on eligibility and performance. For more information on iHerb benefits, visit iHerbBenefits.com. About iHerb
iHerb is on a mission to make health and wellness accessible to all. We are the world’s largest e‑commerce platform dedicated to vitamins, minerals and supplements, serving consumers in over 180 countries with more than 50,000 products from 1,800 brands. Equal Opportunity Employer
iHerb is an equal‑opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb prohibits discrimination and harassment. #J-18808-Ljbffr
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal Application Security Engineer in Richmond, VA vacancy
- ...and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCats products are secure....SuggestedRemote work
$180k - $190k
...role: Branch is seeking an experienced Security professional to join our team. This... ...candidate will have a background in securing applications, networks, cloud environments, and... ...security into the SDLC by partnering with Engineering to implement secure design patterns,...SuggestedRemote workHome officeFlexible hours$140k - $170k
...and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the Stellar... ...forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data in...SuggestedContract workTemporary workWork at officeLocal areaWorldwideFlexible hoursNight shift$320k - $405k
...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role: The Application Security team is at the forefront of building security into every phase...SuggestedContract workFor contractorsFor subcontractorWork at officeRemote workRelocationVisa sponsorshipWork visaFlexible hoursShift work$227.9k
...on people’s everyday lives. We’re looking for an experienced security engineer who’s independent, excited about getting things done, and... ...the ground running. Youll primarily be responsible for our application security, working with our product teams to work on new systems...SuggestedRemote workFlexible hours- ...A leading privacy-focused blockchain company in the United States is seeking an experienced Application Security Engineer to ensure the security of its applications and services. The role involves threat modeling, vulnerability remediation, and collaboration with engineering...Remote workFlexible hours
$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some...Hourly payFull timePart timeRemote work$150k - $173k
...you want to work on systems that actually move the world—literally—you’re in the right place. Position Summary: The Application Security Engineer III will serve as a technical leader dedicated to helping us build an even more secure software ecosystem for our...Work experience placementWork from homeFlexible hoursShift work- ...Hampton North is partnered with an international brand to find a senior-level Application Security Engineer focusing on safeguarding the confidentiality, integrity, and accessibility of enterprise data through secure application development practices with emphasis...Contract workRemote work
$170k - $200k
...AI across their organizations. We design and deliver secure, scalable, agentic AI‑native platforms that reshape how... ...change, this is where you belong. About the Role The Principal Application Modernization Engineer is a senior technical leader who defines the scope of...Principal$100k - $172.5k
...Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture... ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan... ...Employer. All qualified applicants will receive consideration for employment...PrincipalFull timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ...OpenAI is looking for a Principal Software Engineer to join the Infrastructure Security team. This role involves designing and implementing high-scale security systems critical to safeguarding OpenAIs technology and user data. Candidates should possess strong software...Principal
$140k - $165k
...money for energy customers. We are seeking a Senior Product Security Engineer to join our team and help us achieve our ambitious goals... ...you bring to Uplight: Advanced experience in securing applications and application settings Advanced experience in app and...Local areaFlexible hoursShift work$30 - $50 per hour
...Role Overview As a Product Security Engineer, you will embed security into the software lifecycle for platforms that handle AI/ML data operations... ...infrastructure and services Requirements Experience in application security and secure software development practices Hands-on...Hourly payRemote work$119.3k - $140.4k
...from you! The Role Maintaining the security and privacy of our users is paramount... ...This is a unique opportunity to use your engineering and security skills to make a direct... ...security vulnerabilities in web and mobile applications, determine risk levels, and drive...Full timeRemote workWork from homeFlexible hours$160k - $210k
...Direct message the job poster from Fidelis Companies Senior Recruitment Consultant with Fidelis Companies Regional Application Engineer Fully Remote | Up to 50% Travel | Full-Time $160K–$210K+ Total Compensation (flexible for the right candidate) Are you an...Permanent employmentFull timeRemote workWork from homeFlexible hours$90k - $120k
...A leading air solutions company based in Chesterfield, Missouri is seeking an Applications Engineer to support technical sales and develop HVAC product solutions. The role involves providing product expertise, creating technical training materials, and engaging with clients...- ...Pacific is proud to represent such firms as GE, Valtek, Yokogawa, MSA, and DeZURIK, to name a few. Job Description The Application Engineer draws on technical and product knowledge to support sales, system design, troubleshooting and optimal product usage. Summary...Work at officeRemote workMonday to Friday
$90k - $110k
...reports, and may be expected to train and mentor less experienced engineers. This position reports to: Engineering Manager This position... ..., and current suppliers to provide extensive product and application knowledge, testing, presentations and other technical contributions...Full timeLocal areaRemote workNight shift- ...About the job Senior Application Engineer Do you like to build SaaS and Mobile solutions in a fast-paced environment? Love collaborating with colleagues to create top-notch applications that help to solve today’s problems? Like the idea of a flexible, autonomous work...Remote workWork from homeFlexible hours
$118.72k - $190.04k
...Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance... ...not limited to job location, experience, applicable skills and training, external market...Permanent employmentFull timeContract workWork experience placementWork at officeRemote workWork from homeWorldwideFlexible hours$100k - $130k
...the job poster from Bestinfo Systems LLC Global Delivery Head BestInfo Systems LLC, Founder & CEO Best Infosystems Ltd Applications Engineer (ServiceNow) - Remote (US) Full-Time (FTE) Direct Hire Position: Applications Engineer (ServiceNow) - Remote (only open...Full timeRemote work$145k
...145,000.00/yr - $145,000.00/yr The Application Engineer designs, builds, and delivers repeatable... ...Lambda; Power BI/Tableau) following security, scalability, and performance best practices... ...Functionally Partner with Industry Principals, Product Management, and Engineering...Full timeTemporary workH1bLocal areaRemote workHome officeWork visa- ...8 Location & Notes Remote work from a U.S. based location Security Clearance Requirement Current Secret Position Type Full Time... ...Description JTEC Consulting is hiring a mid-level Application Support Engineer/Application Test Engineer with Oracle experience to support...Full timeLocal areaRemote work
- ...related service. Our reliable, high-efficiency products are used in applications wherever fluids need to be transported or shut off, covering... ...manufacturing our products. Position Title: Application Engineer Reports To: Project & Application Engineering Manager...ApprenticeshipWork experience placementLocal areaWorldwideFlexible hours
$120k - $135k
...Located remotely from your home office, you will be working hands‑on with our engineering customers in the field and recommending products that fit into their applications for our Data Centers. The primary functions include; providing efficient and accurate pre‑sale application...For contractorsWork at officeRemote workHome office$63k - $75k
...Application Engineer Our client has a new position for an Application Engineer. You will be responsible for supporting sales of their lines of Chemical Mixers & Extruder instruments and providing after-sales support to existing customers. The salary range for this...Night shift$90k - $110k
...and challenge each other in pursuit of our goals. With every step we take we learn and get better. Job Summary As an Application Engineer , you’ll work directly with customers and internal teams to translate application requirements and technical drawings into...Work at officeLocal area- ...A global supplier of precision tools is seeking a Key Accounts Sales Application Engineer to manage projects, drive sales growth, and serve as a liaison between customers and internal teams. The ideal candidate should have 5-7 years of experience in cutting tooling, a...Immediate start
- ...USA Rare Earth LLC is seeking an Application Engineer to work closely with customers and internal teams. You will translate application requirements into material and design recommendations, while supporting the sales process and collaborating on product presentations...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Application Security Engineer. Be the first to apply!
Related searches
- principal infrastructure engineer Richmond, VA
- civil engineer project manager Richmond, VA
- principal data engineer Richmond, VA
- chief engineer Richmond, VA
- principal developer Richmond, VA
- director data engineering Richmond, VA
- general engineer Richmond, VA
- senior chief engineer Richmond, VA
- principal network engineer Richmond, VA
- data center chief engineer Richmond, VA


