Principal Application Security Engineer

CDW

United States

On-site

USD 180,000 - 240,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CDW is seeking a Principal Application Security Engineer to lead hands-on security across applications, APIs, and delivery pipelines. You will influence secure engineering practices at scale, building guardrails and reference architectures while collaborating with developers, SRE, and DevOps teams.

You will drive security controls across CI/CD, define secure coding standards, and guide remediation with scalable patterns.

Qualifications

  • 10+ years of experience in Application Security Engineering including hands-on security in software design, development, and delivery.
  • Deep expertise in secure application architecture, secure coding practices, code-level vulnerability analysis, and threat modeling.
  • Background in software engineering or architecture with the ability to engage at design, code, build, or runtime levels.
  • Strong knowledge of authentication, authorization, session management, API security, secrets management, and OWASP Top 10.
  • Experience with modern stacks such as C#, Java, Python, JavaScript/TypeScript, Go.
  • Experience integrating security into CI/CD pipelines and engineering platforms (SAST, SCA, DAST, IaC scanning).
  • Ability to investigate complex problems and drive remediation while balancing enterprise patterns with code details.

Responsibilities

  • Lead high-impact secure code reviews, threat models, and secure design assessments for applications, APIs, and shared services.
  • Drive secure coding standards, reference architectures, playbooks, tooling, and automations at scale.
  • Embed security into CI/CD pipelines and developer workflows with engineering teams.
  • Identify control gaps and drive remediation through automation and platform improvements.
  • Partner with engineering teams to secure AI-enabled development and applications.

Skills

Secure coding
Threat modeling
CI/CD security
API security
Security architecture
Code review
Communication
Security leadership

Tools

SAST
SCA
DAST
IaC scanning
Container security
SBOM

Job description

Job Summary

Join CDW and help secure the software, platforms, and services that support more than 250,000 customers across enterprise, government, education, and healthcare. As part of CDW's Global Information Security team, you will help shape how application security is embedded into engineering at scale-partnering across development, platform engineering, SRE, and DevOps to reduce risk while enabling delivery.As a Principal Application Security Engineer, you will serve as a senior technical leader and trusted advisor who helps influence secure engineering practices across the enterprise. You will bring deep hands-on application security expertise while enabling teams to adopt scalable patterns, controls, and guardrails across applications, APIs, and software delivery pipelines. This role is ideal for someone who can move fluidly between strategy and execution-shaping direction, building trust through influence, and diving into technical detail when needed.

What you will do
  • Lead high-impact secure code reviews, threat models, and secure design assessments for applications, APIs, and shared services-translating technical risk into clear guidance for engineers, technical leaders, and business stakeholders.
  • Drive the design, integration, and continuous improvement of application security controls across CI/CD platforms, workflows, and environments in close partnership with engineering, DevOps, and platform teams.
  • Identify control gaps, coverage weaknesses, and sources of engineering friction across the software delivery lifecycle, and drive practical remediation through automation, platform improvements, and secure-by-design patterns.
  • Define, advocate for, and build secure coding standards, reference architectures, playbooks, tooling, and automations that scale application security without slowing delivery.
  • Serve as a senior technical partner to engineering teams by influencing design decisions, guiding remediation strategy, and helping embed security into how software is built and deployed.
  • Advance CDW's approach to securing AI-enabled development and applications by evaluating emerging risks, defining practical guardrails, and promoting responsible use of AI as a force multiplier for engineering and security outcomes.
  • Provide deep subject matter expertise in API security, including authentication and authorization models, protections, monitoring, and secure integration patterns across modern application ecosystems.
  • Partner with web and platform teams to design, deploy, and tune application-layer protections such as WAF rules and policies.
What we expect of you
  • 10+ years of experience in Application Security Engineering, including hands-on work embedding security into software design, development, and delivery practices.
  • Deep, hands-on expertise in secure application architecture and design, secure coding practices, code-level vulnerability analysis, and threat modeling.
  • Background in software engineering, application development, or architecture, with the ability to engage credibly at the design, code, build, or runtime levels.
  • Strong command of authentication, authorization, session management, API security, secrets management, and common application vulnerabilities and exploit patterns, including OWASP Top 10 classes, injection, deserialization, SSRF, insecure design, access control issues, and dependency risk.
  • Hands‑on experience securing applications built in one or more modern technology stacks such as C#, Java, Python, JavaScript or TypeScript, Go, or similar.
  • Strong experience integrating security into CI/CD pipelines, developer workflows, and engineering platforms, including technologies such as SAST, SCA, DAST, IaC scanning, container security, API security testing, and software supply chain security controls.
  • Ability to independently investigate complex technical problems, identify root causes, and drive practical remediation while moving fluidly between enterprise patterns and code-level detail.
  • Strong written and verbal communication skills with the ability to influence engineers, platform teams, and senior stakeholders through technical credibility, sound judgment, and partnership.
  • Strong sense of ownership and accountability, with the ability to balance hands‑on technical execution with mentoring others, raising rever…
  • Experience defining standards, playbooks, secure reference architectures, or scalable practices that can be adopted broadly across engineering organizations.
  • Experience with software supply chain security, including dependency risk management, build pipeline hardening, SBOM, artifact integrity, provenance, and package governance, a plus.
  • Hands‑on experience with AI security, including securing AI-enabled applications or advising engineering teams on the secure use of AI or LLM‑based capabilities, a plus.
  • Familiarity with Zero Trust, secure platform engineering, and policy‑as‑code approaches, a plus.

Prior

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer
Principal Application Security Engineer

CO1000 CDW, LLC • Illinois

Hybrid
USD 172,000 - 240,000
Principal Application Security Engineer
Principal Application Security Engineer

Relha LLC • Northern (KY)

Hybrid
USD 172,000 - 240,000
Senior Application Security Engineer (Secure DevOps)
Senior Application Security Engineer (Secure DevOps)

Relha LLC • Northern (KY)

Hybrid
USD 172,000 - 240,000
Senior Application Security Architect — AI & Secure DevOps
Senior Application Security Architect — AI & Secure DevOps

CO1000 CDW, LLC • Illinois

Hybrid
USD 172,000 - 240,000
Lead Application Security Architect for Scaled Delivery
Lead Application Security Architect for Scaled Delivery

CDW • United States

On-site
USD 180,000 - 240,000
Application Security (DevSecOps) Senior Engineer
Application Security (DevSecOps) Senior Engineer

Recru • Spring (TX)

On-site
USD 180,000 - 240,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Principal Application Security Engineer
Principal Application Security Engineer

Triwill Group • United States

On-site
USD 140,000 - 180,000