Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Application Security Engineer

iHerb Inc.

Location and Remote Policy
United States of America – Remote / Home Office – must reside in U.S.

Role Overview
Are you passionate about securing global‑scale e‑commerce services and applications that power millions of customers across more than a hundred countries?

We are looking for a hands‑on Principal Product Security Engineer to lead Secure Development Lifecycle assurance processes, security automation technologies, the hardening strategy across our product, and respond to current and emerging security threats.

Responsibilities

Lead cross‑functional projects and establish cutting‑edge security development lifecycle practices.

Directed security design reviews and threat modeling for new and existing services at iHerb.

Evaluate, prototype, implement, and operate security‑focused tools and services.

Create new secure architecture standards, frameworks and patterns spanning multiple layers.

Discover and analyze emerging security threats, determine applicability to iHerb and proactively implement centralized mitigations.

Maintain a strong knowledge of current security threats and operational best practices.

Drive security assessment, penetration testing and bug bounty programs.

Participate in security incident response.

Qualifications

Demonstrated technical foundation (Computer Science / Engineering degree or equivalent).

10+ years of technical security leadership at a top‑tier software company including experience with security products, threat modeling, security design, security architecture, cryptography, mobile security and broader cloud computing technologies.

Solid understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE…).

Proficiency implementing SDL process, technology, and automation in a DevOps environment.

Experience with large‑scale web applications and microservices, including API design, access management, authorisation, authentication, data protection and encryption.

Excellent problem‑solving, critical thinking, collaboration and communication skills.

Bonus Qualifications

Experience with Cloudflare security, AWS VPCs, EC2 instances and Docker.

Ability to drive good decisions through data with great attention to detail and deliver KPIs.

Experience driving application security training, security champions and awareness campaigns.

Active contributor to the security community (research, open source, publications…).

Pay Scale and Benefits
The anticipated pay scale for this position can be found below; it may vary by geographic location. The final pay offered to a successful candidate will depend on experience, skill set, and other factors.

Employees and their families that meet eligibility criteria may participate in our medical, dental, vision, and basic life insurance programs, and enroll in our 401(k) plan. Employees are also eligible for time off, paid sick leave, and paid holidays. RSUs and annual bonuses may be awarded based on eligibility and performance. For more information on iHerb benefits, visit iHerbBenefits.com.

About iHerb
iHerb is on a mission to make health and wellness accessible to all. We are the world’s largest e‑commerce platform dedicated to vitamins, minerals and supplements, serving consumers in over 180 countries with more than 50,000 products from 1,800 brands.

Equal Opportunity Employer
iHerb is an equal‑opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb prohibits discrimination and harassment.

#J-18808-Ljbffr
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Principal Application Security Engineer in Richmond, VA vacancy
  •  ...and help the developers behind them get paid), you’ll fit right in. The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCats products are secure.... 
    Suggested
    Remote work

    RevenueCat

    Richmond, VA
    3 days ago
  • $180k - $190k

     ...role: Branch is seeking an experienced Security professional to join our team. This...  ...candidate will have a background in securing applications, networks, cloud environments, and...  ...security into the SDLC by partnering with Engineering to implement secure design patterns,... 
    Suggested
    Remote work
    Home office
    Flexible hours

    Branch

    Richmond, VA
    2 days ago
  • $140k - $170k

     ...and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the Stellar...  ...forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data in... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Local area
    Worldwide
    Flexible hours
    Night shift

    Energent Media

    Richmond, VA
    4 days ago
  • $320k - $405k

     ...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role: The Application Security team is at the forefront of building security into every phase... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Anthropic

    Richmond, VA
    1 day ago
  • $227.9k

     ...on people’s everyday lives. We’re looking for an experienced security engineer who’s independent, excited about getting things done, and...  ...the ground running. Youll primarily be responsible for our application security, working with our product teams to work on new systems... 
    Suggested
    Remote work
    Flexible hours

    Wave Mobile Money

    Richmond, VA
    3 days ago
  •  ...A leading privacy-focused blockchain company in the United States is seeking an experienced Application Security Engineer to ensure the security of its applications and services. The role involves threat modeling, vulnerability remediation, and collaboration with engineering... 
    Remote work
    Flexible hours

    Provable

    Richmond, VA
    3 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Richmond, VA
    1 day ago
  • $150k - $173k

     ...you want to work on systems that actually move the world—literally—you’re in the right place. Position Summary: The Application Security Engineer III will serve as a technical leader dedicated to helping us build an even more secure software ecosystem for our... 
    Work experience placement
    Work from home
    Flexible hours
    Shift work

    EasyPost

    Richmond, VA
    3 days ago
  •  ...Hampton North is partnered with an international brand to find a senior-level Application Security Engineer focusing on safeguarding the confidentiality, integrity, and accessibility of enterprise data through secure application development practices with emphasis... 
    Contract work
    Remote work

    Hampton North

    Richmond, VA
    3 days ago
  • $170k - $200k

     ...AI across their organizations. We design and deliver secure, scalable, agentic AI‑native platforms that reshape how...  ...change, this is where you belong. About the Role The Principal Application Modernization Engineer is a senior technical leader who defines the scope of... 
    Principal

    Liatrio

    Richmond, VA
    2 days ago
  • $100k - $172.5k

     ...Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture...  ...for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan...  ...Employer. All qualified applicants will receive consideration for employment... 
    Principal
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Richmond, VA
    4 days ago
  •  ...OpenAI is looking for a Principal Software Engineer to join the Infrastructure Security team. This role involves designing and implementing high-scale security systems critical to safeguarding OpenAIs technology and user data. Candidates should possess strong software... 
    Principal

    OpenAI

    Richmond, VA
    2 days ago
  • $140k - $165k

     ...money for energy customers. We are seeking a Senior Product Security Engineer to join our team and help us achieve our ambitious goals...  ...you bring to Uplight: Advanced experience in securing applications and application settings Advanced experience in app and... 
    Local area
    Flexible hours
    Shift work

    upLIGHT

    Richmond, VA
    3 days ago
  • $30 - $50 per hour

     ...Role Overview As a Product Security Engineer, you will embed security into the software lifecycle for platforms that handle AI/ML data operations...  ...infrastructure and services Requirements Experience in application security and secure software development practices Hands-on... 
    Hourly pay
    Remote work

    Rex USA

    Richmond, VA
    4 days ago
  • $119.3k - $140.4k

     ...from you! The Role Maintaining the security and privacy of our users is paramount...  ...This is a unique opportunity to use your engineering and security skills to make a direct...  ...security vulnerabilities in web and mobile applications, determine risk levels, and drive... 
    Full time
    Remote work
    Work from home
    Flexible hours

    ModernHEALTH

    Richmond, VA
    1 day ago
  • $160k - $210k

     ...Direct message the job poster from Fidelis Companies Senior Recruitment Consultant with Fidelis Companies Regional Application Engineer Fully Remote | Up to 50% Travel | Full-Time $160K–$210K+ Total Compensation (flexible for the right candidate) Are you an... 
    Permanent employment
    Full time
    Remote work
    Work from home
    Flexible hours

    Fidelis Companies

    Richmond, VA
    3 days ago
  • $90k - $120k

     ...A leading air solutions company based in Chesterfield, Missouri is seeking an Applications Engineer to support technical sales and develop HVAC product solutions. The role involves providing product expertise, creating technical training materials, and engaging with clients... 

    Cambridge Air Solutions

    Richmond, VA
    2 days ago
  •  ...Pacific is proud to represent such firms as GE, Valtek, Yokogawa, MSA, and DeZURIK, to name a few. Job Description The Application Engineer draws on technical and product knowledge to support sales, system design, troubleshooting and optimal product usage. Summary... 
    Work at office
    Remote work
    Monday to Friday

    Flow Control Group Company

    Richmond, VA
    2 days ago
  • $90k - $110k

     ...reports, and may be expected to train and mentor less experienced engineers. This position reports to: Engineering Manager This position...  ..., and current suppliers to provide extensive product and application knowledge, testing, presentations and other technical contributions... 
    Full time
    Local area
    Remote work
    Night shift

    Field-Fastener-Supply-Company

    Richmond, VA
    4 days ago
  •  ...About the job Senior Application Engineer Do you like to build SaaS and Mobile solutions in a fast-paced environment? Love collaborating with colleagues to create top-notch applications that help to solve today’s problems? Like the idea of a flexible, autonomous work... 
    Remote work
    Work from home
    Flexible hours

    Nubitz

    Richmond, VA
    1 day ago
  • $118.72k - $190.04k

     ...Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance...  ...not limited to job location, experience, applicable skills and training, external market... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Red Hat

    Richmond, VA
    4 days ago
  • $100k - $130k

     ...the job poster from Bestinfo Systems LLC Global Delivery Head BestInfo Systems LLC, Founder & CEO Best Infosystems Ltd Applications Engineer (ServiceNow) - Remote (US) Full-Time (FTE) Direct Hire Position: Applications Engineer (ServiceNow) - Remote (only open... 
    Full time
    Remote work

    Best Infosystems

    Richmond, VA
    2 days ago
  • $145k

     ...145,000.00/yr - $145,000.00/yr The Application Engineer designs, builds, and delivers repeatable...  ...Lambda; Power BI/Tableau) following security, scalability, and performance best practices...  ...Functionally Partner with Industry Principals, Product Management, and Engineering... 
    Full time
    Temporary work
    H1b
    Local area
    Remote work
    Home office
    Work visa

    Seeq Corporation

    Richmond, VA
    3 days ago
  •  ...8 Location & Notes Remote work from a U.S. based location Security Clearance Requirement Current Secret Position Type Full Time...  ...Description JTEC Consulting is hiring a mid-level Application Support Engineer/Application Test Engineer with Oracle experience to support... 
    Full time
    Local area
    Remote work

    JTEC Consulting

    Richmond, VA
    2 days ago
  •  ...related service. Our reliable, high-efficiency products are used in applications wherever fluids need to be transported or shut off, covering...  ...manufacturing our products. Position Title: Application Engineer Reports To: Project & Application Engineering Manager... 
    Apprenticeship
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    KSB SE and Co KGaA

    Richmond, VA
    3 days ago
  • $120k - $135k

     ...Located remotely from your home office, you will be working hands‑on with our engineering customers in the field and recommending products that fit into their applications for our Data Centers. The primary functions include; providing efficient and accurate pre‑sale application... 
    For contractors
    Work at office
    Remote work
    Home office

    Judge Direct Placement

    Richmond, VA
    3 days ago
  • $63k - $75k

     ...Application Engineer Our client has a new position for an Application Engineer. You will be responsible for supporting sales of their lines of Chemical Mixers & Extruder instruments and providing after-sales support to existing customers. The salary range for this... 
    Night shift

    MRINetwork

    Richmond, VA
    3 days ago
  • $90k - $110k

     ...and challenge each other in pursuit of our goals. With every step we take we learn and get better. Job Summary As an Application Engineer , you’ll work directly with customers and internal teams to translate application requirements and technical drawings into... 
    Work at office
    Local area

    USA Rare Earth

    Richmond, VA
    1 day ago
  •  ...A global supplier of precision tools is seeking a Key Accounts Sales Application Engineer to manage projects, drive sales growth, and serve as a liaison between customers and internal teams. The ideal candidate should have 5-7 years of experience in cutting tooling, a... 
    Immediate start

    MAPAL Dr. Kress KG

    Richmond, VA
    4 days ago
  •  ...USA Rare Earth LLC is seeking an Application Engineer to work closely with customers and internal teams. You will translate application requirements into material and design recommendations, while supporting the sales process and collaborating on product presentations... 

    USA Rare Earth LLC

    Richmond, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Application Security Engineer. Be the first to apply!