Principal Application Security Engineer
Core
Provide senior technical leadership and end-to-end ownership for embedding pragmatic, scalable security across a hybrid engineering ecosystem, partnering with application, platform, and infrastructure teams to define secure-by-default architecture patterns and drive implementation of security controls throughout the SDLC.
Role type
Principal Application Security Engineer (Individual Contributor)
Builds
Secure-by-default architecture patterns, security controls, and guardrails for microservices, APIs, and containerized workloads in public cloud and on-premises Kubernetes environments.
Domain
Financial markets infrastructure / Application Security / Cloud Native Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application and API security architecture, Kubernetes security primitives (RBAC, namespaces, pod security), DevSecOps tooling integration (SAST, SCA, secret scanning, IaC scanning), hybrid cloud security (EKS, AKS, GKE), secure coding guidance, threat modeling, vulnerability management strategy, AI implementation security governance.
Preferred skills
CSSLP, CKS, OSCP, AWS/Azure Security Specialty certifications, experience writing and delivering production software in modern backend languages (C++, Go, Java, C#, Python, Node.js).
Technologies
Kubernetes, EKS, AKS, GKE, CI/CD pipelines, SAST, SCA, secret scanning, IaC scanning, microservices, APIs, containerized workloads.
Responsibilities
Own secure architecture reviews and threat modeling for new systems; Define and drive adoption of application and API security standards; Provide principal-level guidance for high-risk code and design changes; Own Kubernetes workload security standards across multi-cluster environments; Establish and evolve container image security strategy; Drive the design and adoption of DevSecOps guardrails in CI/CD pipelines; Own the strategy for risk-based software vulnerability management; Lead security design support during incident response; Provide principal-level architecture and risk guidance for AI implementations.
Seniority
Principal, hands-on IC with broad technical influence and strategic direction setting.