Principal Engineer - Application Security (SDLC, SAST, DAST, SCA, Threat Modeling, Pen Testing, DevSecOps, AI)
Core
Provide technical leadership for the enterprise Application Security program, integrating security into the software development lifecycle and partnering with engineering teams to reduce application risk.
Role type
Principal Application Security Engineer (SDLC, SAST, DAST, SCA, Threat Modeling, Pen Testing, DevSecOps, AI)
Builds
Scalable security solutions, automation for CI/CD pipelines, custom security tooling, and AI-enhanced security processes.
Domain
Application Security, DevSecOps, Cloud-Native Security, AI/ML in Security
Deliverable
production ML models | product features | infrastructure
Required skills
SSDLC, SAST, DAST, SCA, Threat Modeling, Penetration Testing, CI/CD integration, DevSecOps, Cloud security (AWS/Azure/GCP), Kubernetes, Containers, Microservices, Custom security tooling, Supply chain security, Generative AI implementation
Preferred skills
CISSP, CSSLP, GIAC, OSCP, Cloud security certifications
Technologies
AWS, Azure, Google Cloud, Kubernetes, CI/CD pipelines, Generative AI
Responsibilities
Provide technical leadership across SSDLC, SAST, DAST, SCA, Threat Modeling, and Penetration Testing; Design and build automation integrating security into CI/CD pipelines; Develop strategies to scale security across large engineering organizations; Mentor engineers and promote security best practices; Solve complex application security challenges involving modern software architectures and cloud-native platforms.
Seniority
Principal, technical leadership & strategy
