Principal Application Security Specialist
Core
Principal Application Security Specialist leading application security testing, DevSecOps, and secure SDLC integration for enterprise software.
Role type
Principal, hands-on IC Application Security & DevSecOps
Builds
Automated security frameworks, CI/CD security controls, and novel testing methodologies for web, API, mobile, and AI/LLM applications.
Domain
Enterprise Software Security & DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Application security testing, DevSecOps leadership, Threat modeling, Vulnerability management, Secure SDLC integration, Security framework expertise (OWASP, MITRE, NIST), Scripting (Python, Java, Bash, PowerShell), CI/CD tooling (Git, Jenkins, Docker, Kubernetes), SAST/DAST/SCA tool selection and integration
Preferred skills
Penetration testing, Offensive security, AI/LLM security, Root-cause analysis, Cross-functional influence
Technologies
Python, Java, Bash, PowerShell, Git, Jenkins, Docker, Kubernetes, SAST, DAST, SCA
Responsibilities
Develop and own application security testing methodology and standards across web, API, mobile, and AI/LLM domains; Lead complex, novel, and high-risk security assessments including original research; Drive integration of security into SDLC and CI/CD pipelines with automated tooling; Serve as the organization's authority and final technical escalation point for application security; Design and deploy automated security frameworks for robust tooling and processes; Mentor and develop specialists while creating documentation and training material.
Seniority
Principal, hands-on IC
