Principal Application Security Engineer
Core
Lead secure development lifecycle assurance, security automation, and hardening strategy for global-scale ecommerce services serving millions of customers.
Role type
Principal Product Security Engineer
Builds
Security automation tools, secure architecture standards, and threat mitigations for iHerb's product.
Domain
Ecommerce / Application Security
Deliverable
production ML models | product features | infrastructure
Required skills
Security architecture, threat modeling, cryptography, mobile security, cloud computing, DevOps automation, API security, authentication/authorization, vulnerability assessment (OWASP/CWE), programming (Python, C#, JavaScript, Java)
Preferred skills
Cloudflare security, AWS VPC/EC2/Docker, data-driven decision making, security training/awareness, open source contributions
Technologies
Python, C# .NET, JavaScript, node.js, Java, Cloudflare, AWS, Docker, DAST, SAST, SCA
Responsibilities
Lead cross-functional security projects, conduct security design reviews and threat modeling, implement security tools and services, create secure architecture standards, analyze emerging threats, drive penetration testing and bug bounty programs, participate in incident response
Seniority
Principal, hands-on IC with strategy & mentorship