Principal Application Security Engineer
Core
Lead Secure Development Lifecycle assurance, security automation, and hardening strategy for global-scale ecommerce services serving millions of customers.
Role type
Principal Product Security Engineer (hands-on IC with leadership)
Builds
Security automation tools, secure architecture standards, and centralized threat mitigations for iHerb's product.
Domain
Ecommerce / Application Security / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security architecture, threat modeling, cryptography, mobile security, cloud security, OWASP Top 10, CWE, SDL process, DevOps automation, API security, access management, authentication, authorization, data protection, encryption, vulnerability analysis, penetration testing, bug bounty program management, incident response, security tool implementation (DAST, SAST, SCA), hiring and team growth
Preferred skills
Cloudflare security, AWS VPCs, EC2, Docker, application security training, security champions programs, open source contributions, data-driven decision making
Technologies
Python, C# .NET, JavaScript, node.js, Java, AWS, Docker, Cloudflare
Responsibilities
Lead cross-functional projects to establish security development lifecycle practices; Conduct directed security design reviews and threat modeling; Evaluate and operate security-focused tools and services; Create secure architecture standards and patterns; Discover and analyze emerging security threats; Drive security assessment, penetration testing, and bug bounty programs; Participate in security incident response
Seniority
Principal, strategy & mentorship
