This position is no longer accepting applications
Closed on September 14, 2026.
This role is filled — get an email when new InfoSec roles open on CybersecurityJobs.io:
Principal Application Security Engineer
Get alerted when similar jobs are posted — set up a New InfoSec jobs on CybersecurityJobs.io alert.
See other roles at Motion Recruitment.
Job Description
The Principal Application Security Engineer will serve as a senior AppSec advisor on a 12-month contract for a financial services organization in Charlotte, NC (Hybrid). The role emphasizes enterprise application security strategy, AppSec modernization and automation, and AI and GenAI application security capabilities.
Location and Contract Details
- Location: Charlotte, NC (Hybrid)
- Contract duration: 12 Months
- Job type: Contract
Key Responsibilities
- Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
- Advise on the strategy and resolution of highly complex and unique challenges, applying in-depth evaluation across multiple areas to deliver long-term, large-scale solutions.
- Provide expertise to client senior leadership on innovative engineering business solutions.
- Strategically engage with client personnel to drive alignment and execution.
- Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
- Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
- Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
- Partner with Application Security Champions and engineering teams to support consistent adoption of required AppSec controls.
- Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
- Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
- Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
- Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
- Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
- Define protections for AI-specific risks, including insecure prompt construction, tool misuse, and secrets exposure.
- Drive modernization of AppSec controls through automation, rationalization, and platform integration.
- Build proofs-of-concept and pilots for new security capabilities, scaling successful solutions into production.
- Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
- Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
- Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
- Research emerging threats and technologies and translate findings into actionable AppSec strategy.
Required Qualifications
- 7+ years of Engineering experience, or equivalent demonstrated through a combination of work or consulting experience, training, military experience, and/or education.
- 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
- Deep expertise in SSDLC controls, including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
- Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
- Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
- Experience designing AI-driven security automation or decisioning capabilities.
- Strong understanding of DevSecOps and CI/CD security integration.
- Experience working in highly regulated environments, such as financial services.
- Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
Relevant Technologies
- SSDC
- SDLC
- SSAST
- SCA
- DAST
- GenAI
- LLM
- DevSecOps
- CI/CD
- Infrastructure-as-code
Role Highlight
A well-known financial services company is seeking a Principal Application Security Engineer for a long-term 12-month contract in Charlotte, NC (Hybrid).