
Principal Application Security Engineer
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in California.
β’ Oversee cross-functional projects and set innovative security development lifecycle practices.
β’ Managed security design evaluations and threat modeling for both new and existing services at iHerb.
β’ Assess, prototype, implement, and manage security-centric tools and services.
β’ Establish new secure architecture standards, frameworks, and patterns across various layers.
β’ Identify and analyze emerging security threats, assess their relevance to iHerb, and proactively institute centralized mitigations.
β’ Lead our security assessment, penetration testing, and bug bounty initiatives.
β’ Over 8 years of technical security leadership experience at a leading software company.
β’ Proven technical background (Computer Science / Engineering degree or equivalent experience).
β’ Strong comprehension of common application and infrastructure security vulnerabilities and mitigation strategies (OWASP Top 10, CWE 25, etc.).
β’ Expertise in implementing SDL processes, technologies, and automation within a DevOps framework.
β’ Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection, and encryption.
β’ Familiarity with major programming languages and frameworks (e.g., Python, C# .NET, JavaScript, Node.js, Java, etc.).
β’ Health insurance
β’ 401(k) matching
β’ Paid time off
β’ Flexible work hours
β’ Professional development opportunities
Henkel
Pepperl+Fuchs Group
Win Systems
Intel Corporation
Get handpicked remote jobs straight to your inbox weekly.