CareerPlanSign in

Principal Application Security Engineer

USA🌐 Remote💼 Full-time💰 $177,000–$177,000🗓 2026-07-28 → 2026-09-26

Core

Lead Secure Development Lifecycle assurance, security automation, and hardening strategy for global-scale ecommerce services serving millions of customers.

Role type

Principal Product Security Engineer (hands-on IC with leadership)

Builds

Security automation tools, secure architecture standards, and centralized threat mitigations for iHerb's product.

Domain

Ecommerce / Application Security / Cloud Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Security architecture, threat modeling, cryptography, mobile security, cloud security, OWASP Top 10, CWE, SDL process, DevOps automation, API security, access management, authentication, authorization, data protection, encryption, vulnerability analysis, penetration testing, bug bounty program management, incident response, security tool implementation (DAST, SAST, SCA), hiring and team growth

Preferred skills

Cloudflare security, AWS VPCs, EC2, Docker, application security training, security champions programs, open source contributions, data-driven decision making

Technologies

Python, C# .NET, JavaScript, node.js, Java, AWS, Docker, Cloudflare

Responsibilities

Lead cross-functional projects to establish security development lifecycle practices; Conduct directed security design reviews and threat modeling; Evaluate and operate security-focused tools and services; Create secure architecture standards and patterns; Discover and analyze emerging security threats; Drive security assessment, penetration testing, and bug bounty programs; Participate in security incident response

Seniority

Principal, strategy & mentorship

Sourced via codingjobboard · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.