Principal Application Security Engineer

Job Category: Principal Application Security Engineer
Job Type: Full Time
Job Location: Bucharest


  • Lead the product teams
  • Guide secure coding practices and processes
  • Guide secure architecture and secure product designs (Threat Modeling)
  • Incorporate cloud security architecture (AWS) secure design and best practices
  • Support teams in applying security within the CI/CD/CD process (DevSecOps)
  • Lead, perform, and guide penetration testing on products
  • Support customers, development teams and PSG in technical analysis and triage of security scan results
  • Support the management, control and upgrade of selected SDLC tool suites
  • Training R&D and Operations on security concepts and best practices

Helpful Skills to Support the Responsibilities:

  • Technical leadership skills, coupled with strong communication skills
  • Securing applications and infrastructure in cloud environments such as AWS
  • Java, JVM, JCA/JCE experience, Crypto Library JDK’s
  • C/C++ coding or analysis experience
  • Static analysis (SAST) tool experience such as Fortify, Checkmarx, Coverity
  • Attack surface tool experience such as InsightVM, Qualys, Nessus
  • Dynamic application security testing (DAST) experience with tools such as AppSpider, Zap
  • Opensource composition analysis using tools such as Dependency Check, Whitesource, Snyk
  • TLS, SSL, PKI, and certificate management experience
  • Layer 3 thru 7 network security experience
  • Vulnerability management procedures
  • Penetration Testing
  • Authentication and Authorization mechanics and protocols
  • Understanding and experience in IH/IR
  • Secure system configuration and deployment of infrastructure
  • Experience with Infrastructure as Code such as Terraform, Ansible
  • Experience with security best practices orchestration platforms such as Docker, Kubernetes, EKS
  • Ability to learn new products and technical concepts quickly
  • Successfully manage time and technical responsibilities, set accurate expectations and meet deliverable deadlines while working in a team environment
  • Comfortable working on both Linux-based and MS Windows-based system platforms with a strong technical understanding and aptitude for analytical problem-solving.
  • Strong understanding of application level security issues.
  • Understanding of enterprise computing environments, distributed applications, and a strong understanding of TCP/IP networks
  • Understanding of the system hardening processes, tools, guidelines and benchmarks.
  • Strong understanding of encryption technologies, Java/Linux and Microsoft implementations

These essential functions are representative of those that must be met by an employee to successfully perform the job. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions. Position may be required to perform other duties as required. Travel requirements may be up to 15% and include international travel destinations.


  • Bachelor’s degree in Computer Science, Information Technology or related field. Master’s preferred.
  • A minimum of 7-10 years of product development experience; at least 5 of those years focused on product security.
  • Hands-on experience in many of the following areas: HTTP, XML, REST, C/C++, Java, Web Servers (Apache/IIS), Scripting languages (Javascript, Python, node.js, etc.), Threat Modeling, Penetration testing, Dynamic and Static analysis, Fuzzing, Vulnerability remediation techniques, Knowledge of the CVE, The OWASP top ten, the SANS top 25.
  • Experience using Microsoft Office suite tools to create documents, presentations, and detailed drawings.
  • Superior technical writing, documentation, and communication skills are required.
  • Several years of hands-on experience with AWS Platform and AWS Security and nice-to-have AWS certifications
  • Has achieved an information security certification such as CSSLP, GWAPT, GPEN, OSCP, AWAE, CCSP or similar, or ability to obtain within 18 months of hire

Apply for this position

Allowed Type(s): .pdf, .doc, .docx