Principal Application Security Engineer

Motion Recruitment Partners LLC

Charlotte, Northern (NC, KY)

Hybrid

USD 140,000 - 180,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Financial Services Company in Charlotte, NC is seeking a Principal Application Security Engineer for a hybrid role on a 12-month contract. You will lead the AppSec program, drive SSDLC controls, and collaborate with engineering to implement AI-driven security and modernization.

Candidate will define security strategy, influence senior leadership, and guide cross-functional teams through complex security challenges in a regulated financial services environment.

Qualifications

  • 7+ years of Engineering experience, or equivalent demonstrated through work, training or education.
  • 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
  • Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
  • Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
  • Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
  • Experience designing AI-driven security automation or decisioning capabilities.
  • Strong understanding of DevSecOps and CI/CD security integration.
  • Experience working in highly regulated environments such as financial services.
  • Relevant security certifications (CISSP, CSSP, CISM, or equivalent).

Responsibilities

  • Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
  • Consult on the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, and advanced analytical and inductive thinking.
  • Provide expertise to client senior leadership on innovative Engineering business solutions.
  • Strategically engage with client personnel.
  • DCMS Application Security Strategy
  • Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
  • Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
  • Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
  • Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls.
  • Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
  • AI Innovation for Application Security
  • Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
  • Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
  • Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
  • Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
  • Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
  • AppSec Modernization and Automation
  • Drive modernization of AppSec controls through automation, rationalization, and platform integration.
  • Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
  • Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
  • Senior Lead Influence and Leadership
  • Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
  • Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
  • Research emerging threats and technologies and translate insights into actionable AppSec strategy.

Skills

Engineering experience
Application Security
SSDLC controls
Security strategy
GenAI security
AI-driven security
DevSecOps CI/CD
Regulated financial services
Security certifications

Job description

Outstanding long-term contract opportunity!

A well-known Financial Services Company is looking for a Principal Application Security Engineer in Charlotte, NC (Hybrid).

Work with the brightest minds at one of the largest financial institutions in the world.

This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today's digital age.

Contract Duration: 12 Months

Required Skills & Experience
  • 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.
  • 7+ years of Application Security or Information Security Engineering experience at enterprise scale.
  • Deep expertise in SSDLC controls including threat modeling, secure design, SAST, SCA, DAST, and penetration testing.
  • Proven ability to define security strategy and deliver outcomes through influence and technical leadership.
  • Experience securing GenAI and LLM-based applications, including adversarial testing and prompt-injection defenses.
  • Experience designing AI-driven security automation or decisioning capabilities.
  • Strong understanding of DevSecOps and CI/CD security integration.
  • Experience working in highly regulated environments such as financial services.
  • Relevant security certifications (CISSP, CSSP, CISM, or equivalent).
What You Will Be Doing
  • Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.
  • Consult on the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, and advanced analytical and inductive thinking.
  • Provide expertise to client senior leadership on innovative Engineering business solutions.
  • Strategically engage with client personnel.
  • DCMS Application Security Strategy
  • Define and lead the Application Security strategy for DCMS in-scope applications using tier-based control models.
  • Evaluate existing AppSec control coverage and establish baseline mappings by application tier.
  • Identify control gaps and drive remediation and onboarding plans with application teams and stakeholders.
  • Partner with Application Security Champions and engineering teams to ensure consistent adoption of required AppSec controls.
  • Ensure alignment with enterprise SDLC requirements and defect remediation expectations.
  • AI Innovation for Application Security
  • Identify and deliver AI and GenAI use cases that reduce manual AppSec effort and improve security coverage.
  • Design and implement automated threat modeling using code, infrastructure-as-code, and application metadata.
  • Develop adversarial testing capabilities for GenAI and LLM-based applications, including prompt injection and abuse scenarios.
  • Lead initiatives for AI model scanning, integrity validation, and secure onboarding of models.
  • Define protections for AI-specific risks including insecure prompt construction, tool misuse, and secrets exposure.
  • AppSec Modernization and Automation
  • Drive modernization of AppSec controls through automation, rationalization, and platform integration.
  • Build proofs-of-concept and pilot new security capabilities, scaling successful solutions into production.
  • Influence simplification of AppSec processes to improve developer experience while maintaining strong risk controls.
  • Senior Lead Influence and Leadership
  • Provide strategic guidance to senior leadership on Application Security priorities, risks, and investment decisions.
  • Influence cross-functional teams without direct authority to achieve enterprise security outcomes.
  • Research emerging threats and technologies and translate insights into actionable AppSec strategy.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer
Principal Application Security Engineer

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Senior Lead Application Security Engineer
Senior Lead Application Security Engineer

Motion Recruitment • Charlotte (NC)

Hybrid
USD 131,000 - 138,000
Senior Lead Application Security Engineer (AppSec SME)
Senior Lead Application Security Engineer (AppSec SME)

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Senior AI-Driven AppSec Architect
Senior AI-Driven AppSec Architect

Motion Recruitment • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Senior AppSec Architect for AI-Driven Security
Senior AppSec Architect for AI-Driven Security

Motion Recruitment Partners LLC • Charlotte (NC), Northern (KY)

Hybrid
USD 140,000 - 180,000
Lead Application Security Engineer with AI
Lead Application Security Engineer with AI

Brilliant Infotech Inc. • Charlotte (NC)

Hybrid
USD 140,000 - 210,000
Hybrid Senior Lead AppSec Architect for GenAI & AI Security
Hybrid Senior Lead AppSec Architect for GenAI & AI Security

Motion Recruitment • Charlotte (NC)

Hybrid
USD 131,000 - 138,000
Digital Product Manager 4
Digital Product Manager 4

Motion Recruitment Partners LLC • Charlotte (NC)

Hybrid
USD 110,000 - 140,000
Digital Product Manager 4
Digital Product Manager 4

Motion Recruitment • Columbus (OH)

Hybrid
USD 110,000 - 140,000
HTTP/S, Web App Security
HTTP/S, Web App Security

Motion Recruitment Partners LLC • Charlotte (NC), Northern (KY)

Hybrid
USD 110,000 - 150,000