Principal Application Security Engineer I - Remote India
Outseer
IndiaremotePosted 1 month ago
Skill Required
Application-Security-EngineerCybersecurity-and-ComplianceSecurity-ArchitectureCloud-SecurityDevSecOpsSenior-Application-Security-EngineerLead-Application-Security-EngineerPrincipal-Security-Software-EngineerApplication-Security-LeadApplication-Security-ArchitectPrincipal-Security-EngineerSecurity EngineerApplication DevelopersecurityPenetration TestingSOCCloud Securityrelated fieldOWASPEngineeringR ProgrammingJavaScriptShell ScriptingdesigningAndroidwrittenTestNGPythondesignDevOps.NETAzureCI/CDCloudJavaSIEMiOSAWSFulltime
Key highlights
- 10+ years of progressive experience in application security.
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional certifications such as CSSLP, GWAPT, CISSP are highly desirable.
- Strong knowledge of web and mobile frameworks (Java, .NET, JavaScript, Python, Android, iOS).
- Expertise in cloud security (AWS, Azure, GCP).
- Excellent verbal and written communication skills.
Role overview
As a Principal Application Security Engineer is a senior technical leader responsible for designing, implementing, and guiding the organization’s security architecture and strategy.
Responsibilities
- Design and review secure system architectures for applications, cloud platforms, and infrastructure.
- Define security standards, frameworks, and best practices across engineering teams.
- Lead threat modeling and security design reviews.
- Develop and implement security controls and automation.
- Lead initiatives in cloud security, identity & access management, Zero Trust architecture, application security, data protection, SIEM, and EDR.
- Perform advanced vulnerability analysis and remediation guidance.
- Act as the security subject matter expert for complex technical decisions.
- Mentor security engineers and developers.
- Guide secure coding practices and DevSecOps adoption.
- Conduct threat modeling and risk assessments.
- Analyze emerging threats and define mitigation strategies.
- Support incident response and post‑incident security improvements.
- Work with engineering, DevOps, product, and compliance teams.
- Translate business requirements into security solutions.
- Drive adoption of security practices across the organization.
Requirements
- Bachelor’s degree in computer science, Information Security, or related field, or equivalent work experience.
- 10+ years of progressive experience in application security, focusing on securing complex web and mobile applications.
- Extensive expertise in application security principles, secure coding practices, secure architecture design, and vulnerability assessment techniques.
- Strong knowledge of web and mobile application frameworks, languages, and technologies (Java, .NET, JavaScript, Python, Android, iOS).
- Proven experience conducting advanced application security assessments, including code reviews, architecture reviews, and penetration testing.
- Deep understanding of web application security vulnerabilities (OWASP Top Ten), advanced attack techniques, and mitigation strategies.
- Demonstrated ability to develop and implement secure software development lifecycle (SDLC) processes and integrate security into DevOps and CI/CD practices.
- Expertise in cloud security concepts and practices, with hands‑on experience in cloud‑native environments (AWS, Azure, GCP).
- Strong scripting or programming skills for automation and tooling (Python, Bash, PowerShell).
- Ability to build security automation tools and integrations.
- Excellent communication skills both verbal and written.
- Project leadership with ability to prioritize multiple assignments and/or deliverables.
- Leader that can influence, motivate, and direct a workgroup to achieve results.
Nice to have
- Professional certifications in application security (CSSLP, GWAPT, CISSP) and active participation in industry forums or associations.
- Desired behaviors such as change facilitation, execution focus, team influence, motivational mentorship, technical proficiency, effective communication, employee involvement, ethical conduct and competence, role modeling.
Additional details
- The role is focused on deep technical expertise, cross‑team influence, and security leadership rather than people management.
- Outseer is committed to the principle of equal employment opportunity for all employees and to providing a work environment free of discrimination and harassment.
- All employment decisions at Outseer are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex, age, disability, HIV status, sexual orientation, gender identity, marital status, military service, family medical history or genetic information, family or parental status, or any other status protected by applicable laws.
- Outseer encourages applicants of all ages.
- Originally posted on Himalayas.