
Principal Application Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Lead impactful secure code evaluations, threat modeling, and secure design assessments for applications, APIs, and shared services.
• Convert technical risks into clear guidance for engineers, technical leaders, and business stakeholders.
• Propel the design, integration, and continuous enhancement of application security controls across CI/CD platforms, workflows, and environments.
• Identify gaps in controls, weaknesses in coverage, and friction in engineering throughout the software delivery lifecycle.
• Facilitate remediation through automation, platform enhancements, and secure-by-design methodologies.
• Define, promote, and establish secure coding standards, reference architectures, playbooks, tools, and automation solutions.
• Act as a senior technical collaborator with engineering teams by influencing design choices and guiding remediation strategies.
• Enhance CDW’s strategy for securing AI-enabled development and applications.
• Assess emerging AI security threats and establish practical guardrails.
• Offer subject matter expertise in API security, encompassing authentication, authorization, protective measures, monitoring, and secure integration patterns.
• Collaborate with web and platform teams to design, implement, and fine-tune WAF rules and policies.
• Mentor colleagues, elevate standards, and promote organization-wide advancements in application security.
• Over 10 years of experience in Application Security Engineering.
• In-depth, hands-on knowledge of secure application architecture and design, secure coding practices, code-level vulnerability assessment, and threat modeling.
• Experience in software engineering, application development, or architecture.
• Strong understanding of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns.
• Practical experience with modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar.
• Significant experience in integrating security into CI/CD pipelines, developer workflows, and engineering platforms.
• Capability to independently investigate complex technical issues, identify root causes, and drive practical remediation efforts.
• Excellent written and verbal communication skills.
• A robust sense of ownership and accountability.
• Experience in defining standards, playbooks, secure reference architectures, or scalable practices.
• Familiarity with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance is a plus.
• Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI or LLM-based capabilities is a plus.
• Knowledge of Zero Trust, secure platform engineering, and policy-as-code methodologies is a plus.
• Previous experience as an Application Security Champion, Security Champion, embedded security lead, principal engineer, or senior engineer responsible for driving security within product or application teams is a plus.
• Experience with runtime application protection, exploit prevention, threat detection technologies, and abuse case analysis is a plus.
• Experience influencing secure development practices within decentralized or federated engineering organizations is a plus.
• Experience in defining and utilizing application security metrics, maturity measures, or risk-based reporting is a plus.
• Experience designing security controls for cloud-native and distributed systems operating in Azure, AWS, or GCP is a plus.
• Experience designing, implementing, or fine-tuning Akamai protections is a plus.
• Experience with reviewing and securing IaC (Terraform or similar) is a plus.
• Annual bonus target of 15% subject to the terms and conditions of the plan.
• Benefits overview available at https://cdw.benefit-info.com/.
• Salary ranges may be subject to geographic differentials.
Persistent Systems, LLC
Guild Mortgage
Grow Therapy
ConnectiveRx
Get handpicked remote jobs straight to your inbox weekly.