Principal Application Security Engineer

barracuda-networks-inc

Ottawa

Hybrid

CAD 140,000 - 200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity options
Premium health benefits
Retirement match
Career growth
Flexible PTO
Volunteer programs

Job summary

Barracuda Networks is hiring a Principal Application Security Engineer to shape and lead our AppSec program. You will mentor team members and influence the direction of the security strategy across product lines.

You will drive threat modeling, perform hands-on security assessments, and own long-term initiatives in a complex, multi-stakeholder environment. Strong coding and cross-functional collaboration are essential.

Qualifications

  • 8-10+ years in product-focused AppSec with track record of proactive programs.
  • Deep practical knowledge of AppSec, ProdSec, and Cloud concepts.
  • Experience building or growing AppSec/ProdSec in a product environment.
  • Proven ability to own long-term security initiatives over year+ timelines.
  • Proficient in threat modeling and risk-based discussions.
  • Hands-on security assessments including pen tests and code reviews.
  • Programming in at least two languages (TypeScript/JavaScript, Python, Java, Go, etc.).
  • Strong, concise communication for developer-focused guidance.

Responsibilities

  • Shape, grow, and lead Barracuda’s Application Security program.
  • Mentor team members and influence the security program direction.
  • Own long-term security initiatives across a complex product landscape.
  • Facilitate threat modeling and drive risk-based discussions.
  • Perform app security assessments and code reviews; drive remediation.

Skills

AppSec leadership
Threat modeling
Penetration testing
Code review
Cross-functional collaboration
Security program ownership
Mentorship
Communication

Tools

Security tooling
Automation

Job description

Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.

We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.

Role Overview:

As a Principal Application Security Engineer, you will be tasked with shaping, growing, and leading Barracuda’s Application Security program. Additionally, as the most senior member of the AppSec team, you will have the opportunity to provide mentorship to other team members and have a say in the direction of the overarching security program and initiatives.

Candidates should have deep expertise in modern Application Security and Product Security practices, have experience defining and growing appsec/prodsec programs, be familiar with product development workflows/lifecycles, and have experience owning, planning, and executing initiatives across a complex multi-stakeholder business setting.

Core requirements:
  • 8-10+ years in product-focused AppSec: Able to move orgs from reactive pen-test/documentation-heavy to proactive guardrail-driven programs. Has a track record of embedding security across the development life cycle and reducing late-stage findings via automation and developer enablement.
  • Strong understanding of modern AppSec and ProdSec concepts: Deep practical (hands-on) knowledge of core security concepts across AppSec, ProdSec, and Cloud.
  • Experience building/growing AppSec and ProdSec programs: Hands-on experience building or growing modern AppSec/ProdSec programs in a product environment.
  • Hands-on experience owning long-term initiatives: Experience and a proven track record of owning workstreams, initiatives, or impactful project scope over an extended (year+) period.
  • Proficient in Threat Modeling: Can facilitate lightweight, feature-level threat models, drive risk-based discussions, and flag high-risk changes across a broad spectrum of tech stacks and product designs.
  • Hands-on security assessment experience: Has strong hands-on experience performing application penetration tests, conducting security-focused source code reviews, driving risk rating and vulnerability management processes.
  • Programming proficiency: Proficient in at least two programming languages (TypeScript/JavaScript, Python, Ruby, Java, Go, etc.). Able to review code and provide framework-specific remediation guidance.
  • Strong communication and presentation skills: Able to provide concise and practical developer-friendly guidance. Can partner with product, platform, and engineering leads to drive security initiatives. Comfortable leading short, outcome-focused design review discussions and security trainings.
Ideal candidate also has:
  • A strong sense of ownership and community within the team
  • Ability to build automation and successfully leverage AI to facilitate daily tasks
  • Hands-on experience building production-grade software
  • Experience working cross-functionally with technical and non-technical teams
Nice-to-have:
  • Applicable certifications such as OSCP, OSCE, OSWE, etc.
  • Previous management/leadership experience
  • Excited and passionate about application security and software development.
What you’ll get from us

A team where you can voice your opinion, make an impact, and where you and your experience are valued. Internal mobility – there are opportunities for cross training and the ability to attain your next career step within Barracuda.

  • Equity, in the form of non-qualifying options
  • High-quality health benefits
  • Retirement Plan with employer match
  • Career-growth opportunities
  • Flexible Time Off and Paid Time Off benefits
  • Volunteer opportunities

We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability. We are committed to a candidate selection process and work environment that is inclusive and barrier free. To ensure candidates are assessed in a fair and equitable manner, accommodations will be provided to prospective employees in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code. We are dedicated to building a workforce that reflects the diversity of the community in which we live in and serve. We encourage applications from all qualified individuals.

#LI-hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer
Principal Application Security Engineer

Barracuda • Ottawa

On-site
CAD 160,000 - 210,000
Equity options
High-quality health benefits
Retirement plan with employer match
+2
Software Development Engineer in Test II
Software Development Engineer in Test II

Barracuda • Ottawa

On-site
CAD 74,000 - 98,000
Equity options
Internal mobility
Career progression
Manager, Cloud Services and Site Reliability
Manager, Cloud Services and Site Reliability

Barracuda • Ottawa

Hybrid
CAD 136,000 - 182,000
Equity options
Health benefits
Retirement plan
+3
Manager, Cloud Services and Site Reliability
Manager, Cloud Services and Site Reliability

Barracuda Networks, Inc. • Ottawa

Hybrid
CAD 136,000 - 182,000
Non-qualifying options equity
High-quality health benefits
Retirement plan with employer match
+3
Senior Application Security Analyst
Senior Application Security Analyst

Purolator Inc. • Mississauga

On-site
CAD 110,000 - 140,000
Principal Application Security Architect
Principal Application Security Architect

OpenText • Southwestern Ontario

On-site
CAD 140,000 - 190,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Senior .NET Application Security Developer
Senior .NET Application Security Developer

Cognizant • Halifax

On-site
CAD 61,000 - 100,000
Medical, Dental, Vision, and Life Ins.
Paid Holidays and PTO
401(k) Plan and Company Contributions
+1
Principal Product Security Architect
Principal Product Security Architect

OpenText • Southwestern Ontario

On-site
CAD 140,000 - 190,000
Senior Application Security Engineer
Senior Application Security Engineer

Spring Financial • Vancouver

Hybrid
CAD 131,000 - 155,000
Competitive salary
Comprehensive benefits package
GRSP matching programme
+2