Principal Application Security Engineer
Application Security
Application Security Strategy
Cybersecurity Tools
Data Security
DevSecOps
Digital Marketing
Dynamic Application Security Testing
Engineer
Enterprise Risk
InfoSec
Infrastructure As Code
Project Management
Risk Governance
Risk Management
SAS
Security
Security Assessment
Security Automation
Security Testing
Software Composition Analysis
Software Security
Solution Architecture
Static Application Security Testing
Strategic Advisory
Job Description
The Principal Application Security Engineer will serve as a senior AppSec advisor on a 12-month contract for a financial services organization in Charlotte, NC (Hybrid). The role emphasizes enterprise application security strategy, AppSec modernization and automation, and AI and GenAI application security capabilities.
Location and Contract Details
- Location: Charlotte, NC (Hybrid)
- Contract duration: 12 Months
- Job type: Contract
Key Responsibilities
- Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
- Advise on the strategy and resolution of highly complex and unique challenges, applying in-depth evaluation across multiple areas to deliver long-term, large-scale solutions.
- Provide expertise to client senior leadership on innovative engineering business solutions.
- Strategically engage with client personnel to drive alignment and execution.
- Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
- Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
- Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
- Partner with Application Security Champions and engineering teams to support consistent adoption of required AppSec controls.
- Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
- Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
- Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
- Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
- Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
- Define protections for AI-specific risks, including insecure prompt construction, tool misuse, and secrets exposure.
- Drive modernization of AppSec controls through automation, rationalization, and platform integration.
- Build proofs-of-concept and pilots for new security capabilities, scaling successful solutions into production.
- Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
- Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Research emerging threats and technologies and translate findings into actionable AppSec strategy.
Required Qualifications
- 7+ years of Engineering experience, or equivalent demonstrated through a combination of work or consulting experience, training, military experience, and/or education.
- 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
- Deep expertise in SSDLC controls, including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
- Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
- Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
- Experience designing AI-driven security automation or decisioning capabilities.
- Strong understanding of DevSecOps and CI/CD security integration.
- Experience working in highly regulated environments, such as financial services.
- Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
Relevant Technologies
- SSDC
- SDLC
- SSAST
- SCA
- DAST
- GenAI
- LLM
- DevSecOps
- CI/CD
- Infrastructure-as-code
Role Highlight
A well-known financial services company is seeking a Principal Application Security Engineer for a long-term 12-month contract in Charlotte, NC (Hybrid).