Remotery

Principal Application Security Engineer

atCDWRemoteUS flagUnited StatesFull-timeApplication EngineerLead$172k – $240k/year

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Lead impactful secure code evaluations, threat modeling, and secure design assessments for applications, APIs, and shared services.

• Convert technical risks into clear guidance for engineers, technical leaders, and business stakeholders.

• Propel the design, integration, and continuous enhancement of application security controls across CI/CD platforms, workflows, and environments.

• Identify gaps in controls, weaknesses in coverage, and friction in engineering throughout the software delivery lifecycle.

• Facilitate remediation through automation, platform enhancements, and secure-by-design methodologies.

• Define, promote, and establish secure coding standards, reference architectures, playbooks, tools, and automation solutions.

• Act as a senior technical collaborator with engineering teams by influencing design choices and guiding remediation strategies.

• Enhance CDW’s strategy for securing AI-enabled development and applications.

• Assess emerging AI security threats and establish practical guardrails.

• Offer subject matter expertise in API security, encompassing authentication, authorization, protective measures, monitoring, and secure integration patterns.

• Collaborate with web and platform teams to design, implement, and fine-tune WAF rules and policies.

• Mentor colleagues, elevate standards, and promote organization-wide advancements in application security.


⛳️ Requirements

• Over 10 years of experience in Application Security Engineering.

• In-depth, hands-on knowledge of secure application architecture and design, secure coding practices, code-level vulnerability assessment, and threat modeling.

• Experience in software engineering, application development, or architecture.

• Strong understanding of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns.

• Practical experience with modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar.

• Significant experience in integrating security into CI/CD pipelines, developer workflows, and engineering platforms.

• Capability to independently investigate complex technical issues, identify root causes, and drive practical remediation efforts.

• Excellent written and verbal communication skills.

• A robust sense of ownership and accountability.

• Experience in defining standards, playbooks, secure reference architectures, or scalable practices.

• Familiarity with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance is a plus.

• Hands-on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI or LLM-based capabilities is a plus.

• Knowledge of Zero Trust, secure platform engineering, and policy-as-code methodologies is a plus.

• Previous experience as an Application Security Champion, Security Champion, embedded security lead, principal engineer, or senior engineer responsible for driving security within product or application teams is a plus.

• Experience with runtime application protection, exploit prevention, threat detection technologies, and abuse case analysis is a plus.

• Experience influencing secure development practices within decentralized or federated engineering organizations is a plus.

• Experience in defining and utilizing application security metrics, maturity measures, or risk-based reporting is a plus.

• Experience designing security controls for cloud-native and distributed systems operating in Azure, AWS, or GCP is a plus.

• Experience designing, implementing, or fine-tuning Akamai protections is a plus.

• Experience with reviewing and securing IaC (Terraform or similar) is a plus.


🏝️ Benefits

• Annual bonus target of 15% subject to the terms and conditions of the plan.

• Benefits overview available at https://cdw.benefit-info.com/.

• Salary ranges may be subject to geographic differentials.

People also viewed

Persistent Systems, LLC19 hours ago

Senior Field Application Engineer, International Programs

EuropeFull-timeApplication Engineer$129k – $161k/year
ApplyView job
Guild Mortgage22 hours ago

Senior Application Security Engineer

US flagUnited States OnlyFull-timeApplication Engineer$109k – $156k/year
ApplyView job
Grow Therapy23 hours ago

Senior/Staff Engineer, Application & Product Security

US flagCalifornia, +2 more statesFull-timeApplication Engineer$182k – $240k/year
ApplyView job
ConnectiveRx1 day ago

Lead Engineer, Application Development

US flagNew Jersey OnlyFull-timeApplication Engineer$107.6k – $165.5k/year
ApplyView job
Sequoia Connect1 day ago

Python Application Engineer

MX flagMexico OnlyFull-timeApplication Engineer
ApplyView job
LVT (LiveView Technologies)1 day ago

Application Engineer – Mid

US flagUnited States OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers