Principal Application Security Engineer I - Remote India
As a Principal Application Security Engineer is a senior technical leader responsible for designing, implementing, and guiding the organization’s security architecture and strategy. The role focuses on deep technical expertise, cross-team influence, and security leadership rather than people management.
Essential Duties
1. Security Architecture & Strategy
- Design and review secure system architectures for applications, cloud platforms, and infrastructure.
- Define security standards, frameworks, and best practices across engineering teams.
- Lead threat modelling and security design reviews.
2. Advanced Security Engineering
- Develop and implement security controls and automation.
- Lead initiatives in areas such as:
-
- Cloud security
- Identity & access management
- Zero Trust architecture
- Application security
- Data protection
- SIEM
- EDR
- Perform advanced vulnerability analysis and remediation guidance.
3. Technical Leadership
- Act as the security subject matter expert (SME) for complex technical decisions.
- Mentor security engineers and developers.
- Guide secure coding practices and DevSecOps adoption.
4. Risk & Threat Management
- Conduct threat modelling and risk assessments.
- Analyze emerging threats and define mitigation strategies.
- Support incident response and post-incident security improvements.
5. Cross-Team Collaboration
- Work with engineering, DevOps, product, and compliance teams.
- Translate business requirements into security solutions.
- Drive adoption of security practices across the organization..
Desired Requirements
- Bachelor’s degree in computer science, Information Security, or a related field - or equivalent work experience.
- 10+ years of progressive experience in application security, with a focus on securing complex web and mobile applications.
- Extensive expertise in application security principles, secure coding practices, secure architecture design, and vulnerability assessment techniques.
- Strong knowledge of web and mobile application frameworks, languages, and technologies (e.g., Java, .NET, JavaScript, Python, Android, iOS).
- Proven experience conducting advanced application security assessments, including code reviews, architecture reviews, and penetration testing.
- Deep understanding of web application security vulnerabilities (OWASP Top Ten), advanced attack techniques, and mitigation strategies.
- Demonstrated ability to develop and implement secure software development lifecycle (SDLC) processes and integrate security into DevOps and CI/CD practices.
- Expertise in cloud security concepts and practices, with hands-on experience in cloud-native environments (e.g., AWS, Azure, GCP).
- Strong scripting or programming skills for automation and tooling (e.g., Python, Bash, PowerShell).
- Professional certifications in application security (e.g., CSSLP, GWAPT, CISSP) and active participation in industry forums or associations are highly desirable.
- Leader that can influence, motivate, and direct a workgroup to achieve results.
- Excellent communication skills both verbal and written.
- Project leadership with the ability to prioritize multiple assignments and / or deliverables.
- Ability to build security automation tools and integrations
Desired Behaviors
- Change Facilitation: Encourages and supports continuous improvement of work practices and processes. Facilitates change by actively seeking opportunities for innovation and sharing ideas with the team.
- Execution Focus: Drives execution by effectively cascading departmental goals into individual goals. Sets high performance standards, communicates clear expectations, resolves problems, provides task clarity, and establishes boundaries.
- Team Influence: Provides coaching and mentorship, utilizing open and honest communication. Escalates when necessary to ensure compliance. Recognizes team members for their contributions and fosters and open environment.
- Motivatio