Principal Application Security Engineer

Recruitment agencyJobgetherBrussels (Firmensitz, recherchiert)leverpublished 08/24/2026
Must-have:TypeScriptJavaScriptPythonJavaC#AWSAzureGoogle CloudCloudDevOpsCI/CDAISecuritySeniorLeadRemote
Nice-to-have:Principal

Accountabilities: Lead complex secure code reviews, threat modeling exercises, and secure design assessments across applications, APIs, and shared services, translating technical findings into actionable guidance.

Design, integrate, and continuously improve application security controls across CI/CD platforms, developer workflows, and engineering environments.

Identify security control gaps, coverage weaknesses, and delivery friction, then drive remediation through automation, platform improvements, and secure-by-design patterns.

Define and promote secure coding standards, reference architectures, playbooks, tooling, and automated security capabilities that can scale across engineering teams.

Act as a senior security advisor to engineering and platform teams, influencing architecture, design decisions, remediation strategies, and development practices.

Advance application security for AI-enabled development and applications by assessing emerging threats, establishing practical guardrails, and promoting responsible AI adoption.

Provide deep expertise in API security, including authentication, authorization, monitoring, secure integration patterns, and protection against common attack techniques.

Partner with web and platform teams to design, deploy, and optimize application-layer protections such as WAF policies and rules.

Help strengthen software supply chain security through dependency management, pipeline hardening, SBOM practices, artifact integrity, provenance, and package governance.

Define application security metrics, maturity indicators, and risk-based reporting to prioritize improvements and demonstrate measurable impact.

Requirements:

10+ years of experience in Application Security Engineering, with significant hands-on experience integrating security into software design, development, and delivery.

Deep expertise in secure application architecture, secure coding, code-level vulnerability analysis, threat modeling, and application security assessment.

Background in software engineering, application development, or architecture, with the ability to operate credibly from high-level design through code and runtime environments.

Strong knowledge of authentication, authorization, session management, secrets management, API security, and common vulnerability classes including OWASP Top 10 risks, injection, deserialization, SSRF, insecure design, access-control issues, and dependency vulnerabilities.

Hands-on experience securing modern technology stacks such as C#, Java, Python, JavaScript/TypeScript, Go, or comparable languages and frameworks.

Strong experience integrating SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain controls into CI/CD pipelines and developer workflows.

Proven ability to independently investigate complex technical problems, identify root causes, and deliver practical remediation.

Excellent written and verbal communication skills, with the ability to influence engineers, technical leaders, and senior stakeholders through expertise and collaboration.

Demonstrated ownership, accountability, mentoring ability, and experience raising application security standards across engineering organizations.

Experience creating security standards, playbooks, secure reference architectures, or scalable security practices.

Familiarity with software supply chain security, Zero Trust, secure platform engineering, policy-as-code, cloud-native security, and runtime application protection is highly valued.

Experience securing AI-enabled applications or advising teams on the secure use of AI and LLM-based capabilities is a plus.

Experience with cloud environments such as Azure, AWS, or GCP, Terraform or similar IaC technologies, and Akamai protections is advantageous.

Experience working as an Application Security Champion, embedded security lead, principal engineer, or senior engineer responsible for security within product or application teams is a plus.

Strong ability to influence decentralized or federated engineering organizations through partnership, standards, enablement, and technical leadership.

Benefits:

Base salary range of $172,000–$240,000 , depending on experience, skills, and geographic considerations.

15% annual bonus target , subject to applicable plan terms and conditions.

Comprehensive employee benefits package covering health and other wellness needs.

Remote work opportunity within the United States.

Opportunity to work in an AI-forward environment that encourages experimentation, continuous learning, and responsible adoption of emerging technologies.

Significant technical influence across enterprise application security, cloud-native environments, APIs, CI/CD, software supply chains, and AI-enabled applications.

Collaborative culture focused on professional growth, knowledge sharing, and meaningful technology impact.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1